// Microsoft 365HIGH
Attackers have been compromising hotel and conference-center Wi-Fi gateways since at least June 2026 to redirect users to fake Microsoft 365 login pages (m365-owa.com, ms365-live.com) and steal credentials. ReliaQuest documented the campaign across the U.S., India, and Saudi Arabia, targeting employees in finance, healthcare, energy, law, and retail. Initial access likely exploited weak or reused administrative credentials on exposed management interfaces (SSH, SNMP, web consoles).
- Hacked Public Wi-Fi Gateways Used to Harvest Corporate Credentia(opens in a new tab)
- CaptiveCrunch: Midnight Blizzard targets travelers worldwide for(opens in a new tab)
// Get alerts for Microsoft 365