← SaaS News
SaaS

Hotel Wi‑Fi Phishing Campaign Hijacks Microsoft 365 Logins Across U.S. Cities

Hotel Wi‑Fi Phishing Campaign Hijacks Microsoft 365 Logins Across U.S. Cities

Cybersecurity firm ReliaQuest uncovered a coordinated attack that hijacks hotel and conference‑center Wi‑Fi routers to redirect users to counterfeit Microsoft 365 sign‑in pages. Active since at least June, the campaign has hit multiple U.S. cities and threatens credentials for enterprises in finance, legal, health care, energy, retail and professional services.

The attack highlights a critical blind spot in SaaS security: reliance on DNS integrity for authentication. As more enterprises adopt cloud‑first strategies, a single compromised Wi‑Fi gateway can jeopardize millions of dollars of ARR tied to Microsoft 365 subscriptions. For SaaS operators, the incident reinforces the need to embed network‑level protections—such as conditional access and DNS threat intelligence—into their GTM playbooks and product roadmaps. It also raises the stakes for vendors offering identity‑as‑a‑service, who must ensure their solutions can detect and block credential harvesting even when the user’s network is compromised.

From a broader market perspective, the campaign could accelerate demand for security‑focused add‑ons to core SaaS platforms, driving M&A activity in the identity‑security space and prompting investors to scrutinize the security posture of SaaS portfolios more closely.

  1. Hackers hijack hotel Wi‑Fi gateways to serve fake Microsoft 365 login pages, active since at least June 2026.
  2. At least four phishing domains mimic Microsoft branding, capturing email addresses and passwords.
  3. Victims span finance, legal, health care, energy, retail and professional services, indicating a focus on traveling employees.
  4. Attack leverages DNS manipulation on routers; entry points include exposed admin tools, weak passwords and unpatched firmware.
  5. Mitigations include zero‑trust network policies, stronger MFA, DNS security solutions and regular Wi‑Fi firmware updates.

The hotel Wi‑Fi phishing campaign is a textbook example of how low‑cost infrastructure attacks can have outsized effects on high‑value SaaS assets. Microsoft 365 accounts are the linchpin of many enterprise workflows, and credential theft at the network layer bypasses many traditional endpoint protections. This forces SaaS vendors to rethink the perimeter: authentication can no longer be treated as a purely client‑side problem. Conditional access policies that evaluate device health, location and risk signals must become default, not optional, especially for customers with a mobile workforce.

Historically, SaaS security has focused on protecting the cloud layer—encryption, IAM, and API security. The current threat shifts the focus back to the network edge, where DNS hijacking can silently redirect legitimate traffic. Vendors that can integrate DNS threat intelligence into their identity platforms will gain a competitive moat, as they can offer a more holistic defense that spans from the router to the cloud. This could spur a wave of acquisitions targeting DNS security startups, similar to the recent consolidation around zero‑trust network access (ZTNA) solutions.

For operators, the incident underscores the importance of educating traveling employees. Even the most sophisticated MFA can be undermined by a well‑crafted device‑code prompt that appears legitimate. Training that emphasizes checking URL spelling, using VPNs, and reporting suspicious login screens can reduce the attack surface. In the longer term, we may see hospitality providers adopt security certifications for their Wi‑Fi infrastructure, creating a new compliance market that SaaS security vendors can tap into.

Hotel Wi-Fi phishing attack targets Microsoft loginsfoxnews.com‘Poirot’s hotel was the place to stay in Istanbul’: the book that inspired my travelstheguardian.comThe great British switch-off: how floating retreats, mobile-free pubs and sauna book groups are freeing people from their smartphonestheguardian.com