Hackers are compromising hotel Wi-Fi gateways to hijack Microsoft 365 accounts
Summary
Threat actors are compromising Wi-Fi gateways in hotels and conference centers to hijack Microsoft 365 accounts. Attackers use DNS poisoning to redirect users' traffic to fraudulent domains, stealing credentials without direct endpoint interaction. This tactic exploits the inherent trust users place in network gateways.
IFF Assessment
This article details a new attack vector that compromises user credentials, posing a direct threat to organizations and individuals by exploiting network infrastructure trust.
Defender Context
Defenders should be aware of the risks associated with public Wi-Fi and educate traveling employees about potential threats. Implementing strong multi-factor authentication for Microsoft 365 accounts can mitigate the impact of credential theft, even if network traffic is compromised.