Hotel and conference Wi-Fi is being hijacked to steal Microsoft 365 logins, and MFA does not stop it

By Ubuntu Guard Cyber | 2 August 2026

ReliaQuest has traced an active campaign that hijacks the Wi-Fi gateways inside hotels and conference centres, quietly rewriting DNS settings so that anyone who tries to reach a Microsoft 365 login page lands on a fake one instead. The campaign has been running since at least June 2026, and it does not need your password. It only needs you to approve a prompt that looks like a routine sign-in step, and it walks away with a working session token that Microsoft's own multi-factor authentication (MFA) will honour without complaint. If your staff travel for conferences, client meetings, or site visits and connect a laptop to the venue's Wi-Fi, this is now part of your threat model.

How the hijack works

The attack starts with the Wi-Fi gateway itself, not a phishing email in your inbox. ReliaQuest found that attackers gained access to poorly secured management interfaces on the Wi-Fi appliances used by hotels and conference venues, then changed the gateway's Domain Name System (DNS) settings so it answers every request for Microsoft's login domains with the address of a server the attacker controls. Anyone who joins that network and tries to sign into Microsoft 365 through Outlook, Teams, or a browser tab gets quietly redirected to a lookalike domain such as m365-owa[.]com or owa-ms365[.]com before a login box ever appears.

The second stage is what makes this campaign hard to catch. Rather than asking for a password on a fake page, something most trained staff would at least hesitate over, some of these pages trigger Microsoft's device code flow, a legitimate feature built for signing into devices without a keyboard, such as a smart TV or a conference room screen. The victim is shown a short code and told to enter it on a genuine Microsoft page to approve the sign-in. Doing so authorises a session the attacker already started on their own device, and Microsoft issues a valid OAuth access token straight to that attacker. The password never changes hands and no MFA prompt gets denied, because from Microsoft's perspective, the account owner just approved the login themselves.

Switching your device to a public DNS resolver such as 8.8.8.8 will not save you here, because the compromised gateway forges the plain-text DNS request before it ever leaves the building, well before it would reach a resolver you trust. ReliaQuest reports the campaign has hit financial services, legal, healthcare, energy, and retail organisations across the United States, India, Saudi Arabia and beyond, with no single sector spared, which points to opportunistic targeting of anyone who connects rather than a campaign built around one industry.

Why this matters in South Africa

South African businesses do not get to sit this one out just because the confirmed victims so far are overseas. Email remains the entry point for 85% of cyberattacks against South African organisations, according to a 2026 analysis by Techtron, and phishing alone accounts for more than 60% of email-related incidents inside the country's financial sector. A device code phishing page delivered through a hijacked hotel network is still a phishing attack at its core, and it lands squarely on the population most likely to be connecting from unfamiliar networks: executives, consultants, and sales teams travelling to conferences, client sites, and industry events in Johannesburg, Cape Town, Durban, and further afield.

Corporate Traveller South Africa has spent much of 2026 warning business travellers that hotel and conference Wi-Fi, even the password-protected kind, deserves the same suspicion as open public Wi-Fi, precisely because the network itself, not just the user, can be the compromised party. That warning reads differently once you know a compromised gateway can redirect Microsoft 365 traffic without a single spelling mistake or suspicious link for a trained employee to spot.

There is a Protection of Personal Information Act (POPIA) angle here that is easy to miss. A stolen OAuth token for a Microsoft 365 account usually means access to email, files, and often client personal information sitting inside that mailbox. The Information Regulator's guidance on security compromises is direct on this point: responsible parties must notify the Regulator and affected data subjects as soon as they are reasonably sure a compromise has occurred, and there is no threshold below which a business gets to decide a breach was too small to report. An account takeover that happened while an employee was at a conference in another city is still your company's compromise to report, not the venue's.

What to do this week

  1. Put every travelling staff member on a full-tunnel VPN before they connect to any hotel or conference network, so DNS and login traffic never touches the venue's gateway in the first place.
  2. Turn off Microsoft's Device Code authentication flow in Entra ID for any account or role that does not need it. Most staff accounts never need it enabled, and switching it off closes the exact mechanism this campaign relies on to bypass MFA.
  3. Enable encrypted DNS (DNS over HTTPS) in strict mode and disable WPAD, the Web Proxy Auto-Discovery Protocol most businesses have left switched on with no real use for it.
  4. Brief anyone travelling to a conference this month on the four lookalike domains confirmed so far: m365-owa[.]com, owa-ms365[.]com, ms365-device[.]com, and ms365-live[.]com. An unexpected device code prompt is a red flag, not a normal part of signing in.
  5. Review Microsoft 365 sign-in logs for unfamiliar device registrations or session approvals from locations that do not match a travelling employee's itinerary, particularly in the days after a conference.

Where Ubuntu Guard fits

If your staff travel for conferences, site visits, or client meetings and you are not certain whether Device Code authentication is still switched on in your Microsoft 365 tenant, or whether your laptops are configured to tunnel through a VPN before they ever touch a hotel network, our cybersecurity assessment covers exactly this ground. We check what your travelling accounts can do, which authentication methods are open to abuse, and where a single approved prompt could hand over far more than anyone expected.

A phishing page that never has to ask for a password is exactly the kind of thing standard staff training doesn't prepare anyone to catch. Think your business email could be faked the same way? WhatsApp us. We'll check it free: wa.me/27791595040

Cybersecurity Made Simple


© 2026 Ubuntu Guard Cybersecurity | Durban, South Africa
ubuntuguard.co.za

Sources

Not sure what your travelling accounts can reach?

Ubuntu Guard's cybersecurity assessment checks your Microsoft 365 authentication setup, travel exposure, and POPIA controls.

Book a Cybersecurity Assessment

Questions? Reach us at [email protected]