Threat actors have been compromising captive Wi-Fi gateways at hotels and conference centers since at least June, using DNS poisoning to silently redirect business travelers to fake Microsoft 365 login pages, according to ReliaQuest.
The attack works at the network perimeter: once attackers gain admin access to a venue’s gateway appliance through weak or reused credentials, they intercept DNS queries for every guest connecting to the Wi-Fi. Instead of routing traffic to legitimate Microsoft servers, the compromised gateway sends victims to attacker-controlled domains impersonating Microsoft 365 authentication pages.
ReliaQuest identified four domains used in the campaign: m365-owa[.]com, owa-ms365[.]com, ms365-device[.]com, and ms365-live[.]com. The compromised gateways were found in multiple US cities as well as India and Saudi Arabia, affecting users across professional services, financial services, legal, retail, healthcare, and energy sectors.
The technique exploits a fundamental trust assumption — devices inherently trust DNS responses from the network they join. Specifying a trusted DNS server like Cloudflare’s 1.1.1.1 does not help because the gateway sits directly in the traffic path and can intercept queries before they reach any resolver.
ReliaQuest warned that a single credential compromise can cascade into significant data loss through SharePoint and email access. Hotel and conference networks should treat guest Wi-Fi gateways as high-value targets and enforce strong admin credentials, disable exposed management interfaces, and monitor for DNS anomalies.
