// Alert

Microsoft 365 threat report

Attackers have been compromising hotel and conference-center Wi-Fi gateways since at least June 2026 to redirect users to fake Microsoft 365 login pages (m365-owa.com, ms365-live.com) and steal credentials. ReliaQuest documented the campaign across the U.S., India, and Saudi Arabia, targeting employees in finance, healthcare, energy, law, and retail. Initial access likely exploited weak or reused administrative credentials on exposed management interfaces (SSH, SNMP, web consoles).

// Get alerts for Microsoft 365