Threat actors compromised captive Wi-Fi gateways at hotels to silently redirect business travelers to fake Microsoft 365 login pages.