Understanding the Modus Operandi of the Attack
Cybercriminals are surreptitiously seizing control of hotel Wi-Fi gateways to divert business travelers to counterfeit Microsoft 365 login pages, illicitly obtaining corporate credentials without leaving any digital footprints. To execute DNS poisoning assaults on corporate travelers, assailants are infiltrating Wi-Fi gateway devices and captive portal equipment at hotels and conference venues. Vulnerable internet-facing management interfaces with default or weak passwords have facilitated unauthorized access for attackers. Subsequently, they manipulate the gateway’s DNS settings so that when a visitor connects to the public Wi-Fi and attempts to access Microsoft 365 services, the gateway provides a malicious IP address instead of the authentic one. This redirection leads victims to deceptive phishing websites established on deceptive domains like m365-owa[.]com. The alteration occurring at the network level rather than on the user’s device may elude traditional email security solutions and specific endpoint defenses.
Significance of the Strategic Impact and Defensive Measures
Given that a single compromised gateway can target numerous individuals across various sectors such as finance, law, and healthcare without necessitating the dissemination of malicious files or software downloads, this approach proves highly effective. According to ReliaQuest, the tactics employed bear striking similarities to techniques previously associated with the Russian state-sponsored threat group APT28, also known as Fancy Bear. When unsuspecting victims input their login credentials on the fraudulent site, they inadvertently disclose their usernames, passwords, and authenticated session tokens, which can be exploited by attackers to bypass multi-factor authentication through adversary-in-the-middle attacks. Organizations can significantly mitigate this risk by enforcing the use of always-on, full-tunnel VPNs on staff devices, ensuring that DNS queries and web traffic are routed through secure corporate infrastructure rather than relying on potentially compromised public Wi-Fi networks.
Insights from the Author
The ReliaQuest Threat Research Team recently published a report titled “DNS Poisoning Tactics Expand to Hospitality Wi-Fi” in the ReliaQuest Threat Spotlight on July 23, 2026.
Carmen Estela, a Cybersecurity Research Analyst at Cyber Defense Magazine and a nominee for the Women in Cybersecurity Award, holds a Master of Science degree from the University of Central Florida and a Bachelor’s degree in Criminology from the University of Florida, with certifications in Data Analytics and AI Fundamentals. She actively participates in industry events like BSides Orlando and BSides Jax, offering insights on emerging cyber trends. Carmen is dedicated to enhancing governance, risk, and compliance standards within the cybersecurity realm, drawing from her diverse experience as an adult protective investigator, police dispatcher, and legal intern across law enforcement, academic, and public service sectors.
Contact Carmen via email at [email protected]

