Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Accounts | Sync Up

261

Hotel Wi-Fi can be convenient when you’re traveling, but a new campaign shows how it can also lead people to fake Microsoft 365 login pages. We’ll explain what’s happening and how to protect your account as we sit down and sync up with Rocket IT’s weekly technology update.

In this episode, you’ll hear more about:

  • How compromised hotel Wi-Fi can redirect users to fake Microsoft 365 login pages
  • Why the attack can be difficult to recognize without a suspicious email or link
  • How device-code prompts may give attackers access even when MFA is enabled
  • What travelers can do before connecting to hotel or public Wi-Fi
  • How businesses can better protect accounts and devices while employees travel

Video Transcript

When we think about phishing, we usually picture a suspicious email or text message asking us to click a link. But in this campaign, there may not be a message or link at all. The attack starts with the Wi-Fi network itself.

The campaign was uncovered by the ReliaQuest Threat Research team. During its investigation, the team identified compromised Wi-Fi gateways at hotels and conference centers in multiple U.S. cities, as well as locations in India and Saudi Arabia.

Researchers also saw people from organizations across several industries connecting through those affected networks. That included financial services, professional services, legal, health care, energy, and retail.

So, how does the attack actually work? When you join hotel Wi-Fi, your device relies on the network’s gateway to help direct your internet traffic. Researchers have not confirmed exactly how attackers gained access to these gateways, but they believe exposed management tools and weak or reused administrator credentials may have played a role.

Once attackers gain control, they can change the network’s DNS settings. Think of DNS as a directory for the internet. When you try to visit a website, it helps your device find the right destination. By changing that directory, attackers can quietly redirect someone who is trying to access Microsoft 365 to a fake login page instead. That person may believe they are signing in as usual, enter their email address and password, and unknowingly hand that information to the attacker.

That’s what makes this campaign different from a more familiar phishing attempt. You may not have clicked a strange email, opened an attachment, or intentionally visited an unfamiliar website. You may have simply connected to the hotel Wi-Fi and tried to check your account.

In a limited number of cases, researchers also saw attackers use Microsoft’s device-code sign-in process. The person connecting may see what looks like a normal Microsoft authorization request. But approving that request can authorize a session that the attacker started. That can give the attacker access to the account through a legitimate Microsoft token, even though multi-factor authentication is turned on.

With access to a Microsoft 365 account, an attacker could potentially reach email, documents, internal conversations, and other information connected to that account. And as more people travel for vacations, conferences, client meetings, or remote work, it’s common to check email or open a document from a hotel room or another shared network.

So, what should you do before connecting? If your organization provides a VPN, make sure it’s running whenever you use hotel Wi-Fi or another unfamiliar network. A trusted mobile hotspot can also give you another option when something about the connection or login process doesn’t look right.

Pay attention to unexpected Microsoft prompts as well. If you’re suddenly asked to enter a device code or approve a login you didn’t start, stop and contact your IT team before moving forward.

Businesses shouldn’t place all of the responsibility on the person traveling, though. An always-on VPN can be configured to protect company devices automatically when they connect to an outside network. Organizations can also review whether device-code authentication is needed, disable automatic proxy features that are not being used, and monitor Microsoft 365 for unusual sign-in activity.

These protections matter because someone using an affected network may have no obvious reason to believe anything is wrong. If your organization needs help protecting Microsoft 365 accounts and company devices while your team travels, contact Rocket IT using the link in this video’s description. And to stay up to date on trending technology news, hit that subscribe button and the bell to catch us on next week’s episode of Sync Up with Rocket IT.

Related Posts

Subscribe to Rocket IT's Newsletter

Stay up to date on trending technology news and important updates.

CTA2

Find out if Rocket IT is the right partner for your team

Claim a free consultation with a technology expert.

Fed up with IT support that falls short?

Claim a free 30-minute consultation and explore three key practices to evaluate the maturity of your help desk.