Security Advisory: Hotel and Conference Wi-Fi Is Being Used to Hijack Microsoft 365 Accounts

Security Advisory: Hotel and Conference Wi-Fi Is Being Used to Hijack Microsoft 365 Accounts

We want to put this in front of every client with staff who travel, because we just worked an incident that lines up with it exactly.

What's happening

Security researchers at ReliaQuest have uncovered an active campaign (running since at least June) where attackers compromise the Wi-Fi gateway hardware at hotels and conference centers. Once they control the gateway, they poison DNS so that when you try to reach a real Microsoft page, you land on an attacker-run copy instead. No phishing email, no bad attachment, no malware on your laptop. You just connect to the hotel network and log in like you always do.

Why your MFA doesn't save you here

These attacks don't try to steal your password and code and reuse them later. They sit in the middle of your login in real time, let you complete MFA against the real Microsoft, and then grab the session token Microsoft hands back. That token is proof you already passed MFA, so the attacker replays it and walks straight in. A separate version of this technique hit more than 35,000 people this past April, and every one of them had MFA turned on.

What we saw

We recently had a client employee log in from a hotel and, within the same session, watched the login jump to a completely different network in another state. That is the fingerprint of a stolen token being replayed. Our monitoring caught it and locked the account within minutes, before the attacker could do anything with it.

What to do when you travel

  • Avoid logging into email or Microsoft 365 on hotel or conference Wi-Fi. Use your phone's hotspot instead.
  • If you must use public Wi-Fi, stay on an always-on company VPN so your traffic isn't exposed to the local network.
  • If a Microsoft login page looks even slightly off, or the web address isn't exactly microsoft.com or office.com, stop and don't enter anything.
  • If something feels wrong after you've logged in, contact us right away. Fast reporting is what limits the damage.

If you'd like us to review your team's travel security or turn on stronger protections against this specific attack, open a ticket or reach out to your account contact. We're happy to walk through it.

— Boston Managed IT