We want to put this in front of every client with staff who travel, because we just worked an incident that lines up with it exactly.
Security researchers at ReliaQuest have uncovered an active campaign (running since at least June) where attackers compromise the Wi-Fi gateway hardware at hotels and conference centers. Once they control the gateway, they poison DNS so that when you try to reach a real Microsoft page, you land on an attacker-run copy instead. No phishing email, no bad attachment, no malware on your laptop. You just connect to the hotel network and log in like you always do.
These attacks don't try to steal your password and code and reuse them later. They sit in the middle of your login in real time, let you complete MFA against the real Microsoft, and then grab the session token Microsoft hands back. That token is proof you already passed MFA, so the attacker replays it and walks straight in. A separate version of this technique hit more than 35,000 people this past April, and every one of them had MFA turned on.
We recently had a client employee log in from a hotel and, within the same session, watched the login jump to a completely different network in another state. That is the fingerprint of a stolen token being replayed. Our monitoring caught it and locked the account within minutes, before the attacker could do anything with it.
If you'd like us to review your team's travel security or turn on stronger protections against this specific attack, open a ticket or reach out to your account contact. We're happy to walk through it.
— Boston Managed IT