Rather than targeting individual devices, attackers are compromising hospitality Wi-Fi gateways to steal corporate credentials at far greater scale.

By compromising captive Wi-Fi gateways instead of user devices, attackers can silently redirect authentication traffic and steal Microsoft 365 credentials.

A threat actor has been hacking public Wi-Fi gateways within captive Wi-Fi services to steal corporate Microsoft 365 credentials.