Cyber Resilience
← All news
Corroborated

Hacked Public Wi-Fi Gateways Used to Harvest Corporate Credentials

Our takeCompromised hotel Wi-Fi gateways are redirecting travelers to fake Microsoft 365 logins and stealing credentials plus auth tokens. On public Wi-Fi, use a VPN and phishing-resistant MFA — don't trust the captive portal.
Sources (2)
What this means for you — Security leader:Traveling staff are being hit via compromised hotel Wi-Fi gateways that present fake Microsoft 365 login pages and steal credentials and tokens. Require phishing-resistant MFA, route travel traffic through your VPN or SASE, and hunt M365 sign-ins and token use from unusual locations.
What this means for you — Lean IT orgs:If people on your team travel, tell them not to enter Microsoft 365 passwords on hotel Wi-Fi login or captive-portal pages—use the phone hotspot when they can. Turn on MFA for every account and watch for unexpected sign-in alerts after trips.
What this means for you — MSP:Warn client travelers that compromised hotel Wi-Fi gateways are phish-redirecting to fake Microsoft 365 logins to steal credentials and tokens. Push phishing-resistant MFA and Conditional Access where licensed, and monitor tenant sign-in logs for anomalous travel-location and token-replay patterns.
What this means for you — Researcher:Track the compromised public/hotel gateway models, the captive-portal redirect chain to fake M365 pages, and how stolen credentials versus OAuth/refresh tokens are reused. Compare indicators across the SecurityWeek and Hackread write-ups for shared infrastructure.