Hotel Wi-Fi DNS hijacking Microsoft 365 phishing campaign
Campaign
Summary
Hide ▲
Show ▼
Compromised Wi-Fi gateways at hotels and conference centers are redirecting travelers to fake Microsoft 365 login pages, creating a live credential-theft campaign that can expose business email, documents, and other sensitive data. The operation has been active since at least June and has reached organizations across financial services, professional services, legal, health care, energy, and retail in the U.S. and abroad. Attackers are using DNS changes, device-code authentication tricks, and in some cases WPAD abuse to push victims onto attacker-controlled login pages and bypass MFA.
Related Happenings
Microsoft 365 AitM phishing campaign using residential proxies
Campaign
H score34
First: 07.08.2026 13:38
Last: 07.08.2026 13:38
Sources 1
About this happening:
An active email-driven AitM phishing campaign is hijacking Microsoft 365 accounts and exposing payroll and HR mailboxes across multiple sectors. The operation has targeted...
Microsoft 365 AitM phishing campaign using residential proxies
CampaignAbout this happening: An active email-driven AitM phishing campaign is hijacking Microsoft 365 accounts and exposing payroll and HR mailboxes across multiple sectors. The operation has targeted...
Midnight Blizzard CaptiveCrunch hospitality Wi-Fi phishing campaign
Campaign
H score37
First: 04.08.2026 03:17
Last: 04.08.2026 03:17
Sources 1
About this happening:
Microsoft linked CaptiveCrunch to Midnight Blizzard / APT29, a global operation that abuses hospitality Wi‑Fi to steal Microsoft 365 accounts and deliver malware....
Midnight Blizzard CaptiveCrunch hospitality Wi-Fi phishing campaign
CampaignAbout this happening: Microsoft linked CaptiveCrunch to Midnight Blizzard / APT29, a global operation that abuses hospitality Wi‑Fi to steal Microsoft 365 accounts and deliver malware....
CaptiveCrunch Storm-2945 hotel Wi-Fi redirection campaign
Campaign
H score40
First: 01.08.2026 09:29
Last: 01.08.2026 09:29
Sources 1
About this happening:
Microsoft linked the CaptiveCrunch campaign to Midnight Blizzard / APT29 / Storm-2945, saying it has been active since early May and targets hospitality Wi‑Fi ne...
CaptiveCrunch Storm-2945 hotel Wi-Fi redirection campaign
CampaignAbout this happening: Microsoft linked the CaptiveCrunch campaign to Midnight Blizzard / APT29 / Storm-2945, saying it has been active since early May and targets hospitality Wi‑Fi ne...
Microsoft Teams OAuth phishing campaign targeting 120 organizations
Campaign
H score30
First: 30.07.2026 15:00
Last: 30.07.2026 15:00
Sources 1
About this happening:
A Microsoft Teams-themed phishing campaign is abusing Microsoft’s legitimate authentication infrastructure to steal OAuth access and compromise corporate accounts...
Microsoft Teams OAuth phishing campaign targeting 120 organizations
CampaignAbout this happening: A Microsoft Teams-themed phishing campaign is abusing Microsoft’s legitimate authentication infrastructure to steal OAuth access and compromise corporate accounts...
TA488 half-click Outlook Web Access espionage campaign
Campaign
H score42
First: 29.07.2026 18:10
Last: 29.07.2026 18:10
Sources 1
About this happening:
TA488 / Laundry Bear / Void Blizzard ran a half-click OWA campaign that abused CVE-2026-42897 in on-premises Microsoft Outlook Web Access on Exchange Ser...
TA488 half-click Outlook Web Access espionage campaign
CampaignAbout this happening: TA488 / Laundry Bear / Void Blizzard ran a half-click OWA campaign that abused CVE-2026-42897 in on-premises Microsoft Outlook Web Access on Exchange Ser...
Timeline
-
24.07.2026 20:50 2 articles · 13d ago
Hotel Wi-Fi DNS hijacking Microsoft 365 phishing campaign
Initial DisclosureSince June, attackers have been altering DNS settings on hotel and conference-center Wi-Fi gateways to send users to fake Microsoft 365 portals. The earliest phase centers on travel and event connectivity, turning public access points into a route for account compromise and document theft.
Show sources
- Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts — www.bleepingcomputer.com — 24.07.2026 20:50
- Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts — www.bleepingcomputer.com — 24.07.2026 20:50