Find notable cyber news and cases, enriched with sources, timelines, and signals.

Hotel Wi-Fi DNS hijacking Microsoft 365 phishing campaign

Campaign
First reported
Last updated
Happening score
H score 34
1 unique sources, 1 articles

Summary

Hide ▲

Compromised Wi-Fi gateways at hotels and conference centers are redirecting travelers to fake Microsoft 365 login pages, creating a live credential-theft campaign that can expose business email, documents, and other sensitive data. The operation has been active since at least June and has reached organizations across financial services, professional services, legal, health care, energy, and retail in the U.S. and abroad. Attackers are using DNS changes, device-code authentication tricks, and in some cases WPAD abuse to push victims onto attacker-controlled login pages and bypass MFA.

Related Happenings

Microsoft 365 AitM phishing campaign using residential proxies

Campaign
H score34 First: 07.08.2026 13:38 Last: 07.08.2026 13:38 Sources 1

About this happening: An active email-driven AitM phishing campaign is hijacking Microsoft 365 accounts and exposing payroll and HR mailboxes across multiple sectors. The operation has targeted...

Midnight Blizzard CaptiveCrunch hospitality Wi-Fi phishing campaign

Campaign
H score37 First: 04.08.2026 03:17 Last: 04.08.2026 03:17 Sources 1

About this happening: Microsoft linked CaptiveCrunch to Midnight Blizzard / APT29, a global operation that abuses hospitality Wi‑Fi to steal Microsoft 365 accounts and deliver malware....

CaptiveCrunch Storm-2945 hotel Wi-Fi redirection campaign

Campaign
H score40 First: 01.08.2026 09:29 Last: 01.08.2026 09:29 Sources 1

About this happening: Microsoft linked the CaptiveCrunch campaign to Midnight Blizzard / APT29 / Storm-2945, saying it has been active since early May and targets hospitality Wi‑Fi ne...

Microsoft Teams OAuth phishing campaign targeting 120 organizations

Campaign
H score30 First: 30.07.2026 15:00 Last: 30.07.2026 15:00 Sources 1

About this happening: A Microsoft Teams-themed phishing campaign is abusing Microsoft’s legitimate authentication infrastructure to steal OAuth access and compromise corporate accounts...

TA488 half-click Outlook Web Access espionage campaign

Campaign
H score42 First: 29.07.2026 18:10 Last: 29.07.2026 18:10 Sources 1

About this happening: TA488 / Laundry Bear / Void Blizzard ran a half-click OWA campaign that abused CVE-2026-42897 in on-premises Microsoft Outlook Web Access on Exchange Ser...

Timeline

  1. 24.07.2026 20:50 2 articles · 13d ago

    Hotel Wi-Fi DNS hijacking Microsoft 365 phishing campaign

    Initial Disclosure

    Since June, attackers have been altering DNS settings on hotel and conference-center Wi-Fi gateways to send users to fake Microsoft 365 portals. The earliest phase centers on travel and event connectivity, turning public access points into a route for account compromise and document theft.

    Show sources