July 25, 2026

How Hackers Use Hotel Wi-Fi to Steal Microsoft 365 Accounts

A few weeks ago, an employee at one of our clients, a fast-growing Boston biomedical startup, checked into a hotel for a work trip and did the most ordinary thing in the world. They connected to the hotel Wi-Fi and signed into Microsoft 365. Correct password. MFA approved. Everything looked normal.

Within the same login session, our security monitoring saw that session suddenly authenticating from a different network in another state. That is not something a real user does. It is the signature of an attacker replaying a stolen login. We locked the account within minutes, before anyone could touch their email or files. The employee’s only symptom was getting locked out, which is exactly how it should go when the safeguards work.

Here is what was actually going on, and why it should concern anyone whose team travels.

The attack doesn’t come through your inbox

Most account takeovers start with a phishing email. This one doesn’t. Researchers at ReliaQuest uncovered a campaign, running since at least June 2026, where attackers break into the Wi-Fi gateway hardware at hotels and conference centers. They get in through weak admin interfaces on that equipment, the kind of gear nobody thinks about.

Once they control the gateway, they poison its DNS. In plain terms, they change the network’s phone book. When your laptop asks for the real Microsoft login page, the poisoned network quietly points you to a copy the attacker controls at addresses like m365-owa.com or ms365-live.com. You never clicked a bad link. You just joined the network and logged in.

Why multi-factor authentication doesn’t stop it

This is the part that surprises people. MFA is working exactly as designed, and it still isn’t enough.

MFA protects the moment you log in. Once you pass it, Microsoft hands your browser a session token, a small pass that says “this person already proved who they are, let them stay signed in.” These attackers don’t fight your MFA. They let you complete it against the real Microsoft, sit in the middle, and steal that token as it comes back. Then they replay it from their own systems. As far as Microsoft can tell, you already passed the check, so it lets them in.

To show how effective this is: a related version of the technique compromised more than 35,000 people across 13,000 organizations this past April, and every single victim had MFA enabled.

A newer twist abuses Microsoft’s “device code” login flow, tricking you into approving a sign-in that the attacker started. That hands them a fully authorized session without ever needing your password.

Who’s being targeted

This isn’t limited to one industry. ReliaQuest found compromised Wi-Fi gateways across the US and abroad, with victims in finance, legal, professional services, healthcare, energy, and retail. The tradecraft closely matches earlier campaigns linked to APT28, a well-documented Russian state-sponsored group. The common thread isn’t the industry. It’s employees logging into Microsoft 365 from untrusted public networks while they travel.

How to protect your team

For anyone who travels:

  • Don’t log into Microsoft 365 or email on hotel or conference Wi-Fi. Use your phone’s hotspot, which is far harder to tamper with.
  • If you have to use public Wi-Fi, stay connected to an always-on company VPN so the local network can’t see or steer your traffic.
  • Watch the web address on any login page. If it isn’t exactly a microsoft.com or office.com domain, don’t enter anything.
  • If a login feels off, or something seems wrong after you’ve signed in, report it immediately.

For IT and business owners, there’s more you can do at the account level:

  • Move toward phishing-resistant MFA (FIDO2 security keys or passkeys), which can’t be relayed the way a code or push can.
  • Turn off device-code authentication in Microsoft Entra unless you have a specific need for it.
  • Use Conditional Access with Continuous Access Evaluation so a session that suddenly hops to a new location or network gets challenged or cut off.
  • Have real detection and fast revocation in place. In our client’s case, that’s the difference between a locked account and a full breach.

The takeaway

The uncomfortable truth is that “I have MFA” is no longer the finish line. Attackers have moved on to stealing the session that comes after MFA, and public Wi-Fi is a perfect place to do it. The good news is that this attack is very detectable and very stoppable when someone is watching the right signals and can act in minutes.

That’s the job we do for the companies we support. If your team travels and you’re not sure how you’d catch something like this, we should talk. Contact Boston Managed IT and we’ll review where you stand.

About the Author

Your IT Partner Is Just a Click Away. Are you ready to stop thinking about IT?

We handle the infrastructure, helpdesk, and security — Boston businesses rely on us so they never have to think about IT again.