By compromising captive Wi-Fi gateways instead of user devices, attackers can silently redirect authentication traffic and steal Microsoft 365 credentials.

Hackers are changing the DNS settings on Wi-Fi devices at hotels and conference centers to redirect users to fake Microsoft 365 login pages.

By compromising captive Wi-Fi gateways instead of user devices, attackers can silently redirect authentication traffic and steal Microsoft 365 credentials.