Threat actors have been compromising hotel Wi-Fi gateways since June to hijack Microsoft 365 accounts, posing a significant risk to traveling enterprise employees. By gaining control of these gateways, attackers can redirect user traffic to their own infrastructure, allowing them to steal Microsoft 365 credentials without directly interacting with the user's device. This tactic enables silent and efficient credential theft, making it a formidable threat. The ReliaQuest Threat Research team has identified this activity, which shifts the threat model from traditional criminal activity to geopolitical, state-aligned operations1. This change in threat model requires a different approach to mitigation and defense. The fact that threat actors are targeting Microsoft 365 accounts via compromised Wi-Fi gateways underscores the importance of exercising caution when using public Wi-Fi networks, especially for enterprise employees who handle sensitive information. So what matters most to practitioners is that this new threat vector demands a proactive and multi-layered approach to protecting Microsoft 365 accounts.
Hackers are compromising hotel Wi-Fi gateways to hijack Microsoft 365 accounts
⚡ High Priority
Why This Matters
State-aligned activity involving Microsoft shifts the threat model from criminal to geopolitical — different playbook required.
References
- CSO Online. (2026, July 28). Hackers are compromising hotel Wi-Fi gateways to hijack Microsoft 365 accounts. *CSO Online*. https://www.csoonline.com/article/4202067/hackers-are-compromising-hotel-wi-fi-gateways-to-hijack-microsoft-365-accounts.html
Original Source
CSO Online
Read original →