Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts
Criminals are tampering with internet settings on some hotel and conference center Wi-Fi networks to send people to fake Microsoft sign-in pages and steal their email and work account passwords. Someone may think they are logging in normally, but the page is actually a trap designed to capture their information.
Who is at risk
Travelers, conference attendees, and anyone using hotel or event Wi-Fi to sign in to Microsoft email, work apps, or cloud accounts are most at risk.
What to watch for
Be alert for unexpected Microsoft sign-in screens after joining public Wi-Fi, especially if the page appears suddenly, looks unusual, or asks you to log in again.
What to do
Avoid signing in to Microsoft accounts while on hotel or event Wi-Fi unless you are certain the page is legitimate, and use your mobile data or a trusted personal connection instead if possible.
