Hackers Hijack Hotel Wi‑Fi DNS to Steal Microsoft 365 Accounts
What Happened — Attackers compromised Wi‑Fi gateways at hotels and conference centers, altered DNS settings, and served counterfeit Microsoft 365 login pages. The campaign, observed since June 2026, has harvested credentials—including MFA tokens—across multiple industries.
Why It Matters for Compliance & Audit Readiness
- Demonstrates the need for SOC 2‑aligned access‑control policies that extend to any network used by employees, not just corporate LANs.
- Highlights the importance of continuous evidence collection on third‑party device configurations as part of vendor‑risk and audit documentation.
Who Is Affected – Financial services, professional services, legal, health care, energy, retail, and any organization with traveling staff that rely on hotel Wi‑Fi.
Recommended Actions – Review and harden management interfaces on all network appliances; enforce MFA with conditional access that blocks OAuth token issuance from untrusted networks; map these steps to SOC 2 CC6.1 (Logical Access Control) and collect configuration logs as audit evidence. Source: BleepingComputer
Technical Notes — Attackers likely exploited exposed admin interfaces (SSH, SNMP, web dashboards) to change DNS, then used phishing domains (e.g., m365-owa.com) and WPAD proxy auto‑configuration to capture credentials and OAuth tokens, bypassing MFA without direct password theft. Source: BleepingComputer