Microsoft has disclosed that Russian state-linked hackers hijacked hotel Wi-Fi portals to distribute malware and steal Microsoft 365 authentication tokens from unsuspecting travelers. The campaign turns a routine part of business travel, connecting to hotel internet, into a launchpad for credential theft, putting corporate accounts and sensitive data at risk.

How the Hotel Wi-Fi Attack Works

According to Microsoft, the attackers targeted the infrastructure behind hotel and conference center Wi-Fi networks rather than individual devices. By compromising the gateways that manage guest internet access, the hackers were able to redirect travelers to fake Microsoft 365 login pages that closely mimicked the real sign-in experience. Anyone who entered credentials or approved a login prompt on one of these spoofed pages risked handing over active authentication tokens, the digital keys that let attackers into email, files, and other Microsoft 365 services without needing a password at all.

This approach is notable because it doesn't rely on tricking a single victim into clicking a phishing link. Instead, it exploits trust in a shared network. When a hotel's Wi-Fi portal itself is compromised, every guest who connects becomes a potential target, regardless of how careful they normally are with email attachments or suspicious links.

Why Business Travelers Are Prime Targets

Hotels and conference centers are natural hunting grounds for this kind of operation. Business travelers and executives frequently connect to unfamiliar networks while away from the office, often under time pressure and without the same layered security protections available on a corporate network. A stolen Microsoft 365 token can give an attacker access to internal communications, financial documents, contact lists, and calendar details, information that's valuable both for espionage and for follow-on attacks against an organization.

This fits a broader pattern of Russian state-linked groups targeting officials, executives, and organizations through everyday communication and connectivity tools. In a separate case, Germany formally attributed a phishing campaign targeting federal ministers and Bundestag members to Russian state-sponsored actors, underscoring how these groups consistently go after high-value targets through channels people use daily and tend to trust.

Protecting Your Microsoft 365 Account on Hotel Wi-Fi

The good news is that travelers and IT teams can meaningfully reduce this risk with a few practical habits.

Use a VPN before doing anything else on hotel or public Wi-Fi. Connecting through a reputable VPN encrypts your traffic and routes it away from a potentially compromised local network, making it much harder for a hijacked Wi-Fi gateway to intercept or redirect your login attempts.

Enable multi-factor authentication (MFA) on every Microsoft 365 account, and pay close attention to unexpected authentication prompts. Stolen passwords are far less useful to attackers if a second factor is required, though travelers should still be cautious about approving MFA requests they didn't initiate.

Verify the login page before entering credentials. Fake Microsoft 365 sign-in pages are designed to look nearly identical to the real thing, so check the URL carefully and be suspicious of any sign-in screen that appears immediately after joining a new Wi-Fi network.

Avoid entering corporate credentials directly through a hotel's captive portal or any prompt that appears before you've intentionally opened a browser and navigated to a known site. Legitimate Wi-Fi portals typically only ask for a room number or a simple acceptance of terms, not a full Microsoft account login.

For organizations, this is also a reminder to remind traveling employees about safe Wi-Fi practices ahead of trips and to make VPN use a standard part of travel policy rather than an optional recommendation.

What This Means For You

If you travel for work and regularly connect to hotel Wi-Fi, this campaign is a direct reminder that the network you're joining may not be as trustworthy as it appears, even when it looks like an official hotel portal. The attack doesn't require you to click a malicious link in an email; simply connecting to a compromised network and logging into what looks like a normal Microsoft 365 prompt is enough to lose your token. Treating hotel Wi-Fi as inherently untrusted, and layering protections like a VPN and MFA on top of it, closes off the easiest path attackers have to your account.

Key Takeaways

Before your next trip, take a few minutes to prepare: install and test a VPN so it's ready to use the moment you connect to hotel Wi-Fi, confirm MFA is active on your Microsoft 365 account, and get in the habit of scrutinizing any login page that appears right after joining a new network. These small steps directly counter the tactics behind this campaign and go a long way toward keeping your Microsoft 365 tokens, and everything they protect, out of the wrong hands.