
Microsoft 365
Microsoft's cloud productivity and email suite.
Microsoft 365 sign-in pages were the credential target of a hotel WiFi DNS-poisoning campaign that ReliaQuest reported on 23 July 2026; the login flow was spoofed, not Microsoft 365 itself.
Last refreshed: 3 August 2026 · Appears in 1 active topic
How are attackers spoofing Microsoft 365 logins via hotel WiFi?
Timeline for Microsoft 365
Hotel WiFi steers guests to fake logins
Cybersecurity: Threats and DefencesBackground
Microsoft 365 is Microsoft's cloud productivity and email suite, used widely across corporate environments. It featured in reporting as the credential target of a hotel WiFi campaign: compromised routers used DNS poisoning to redirect guests to counterfeit Microsoft 365 sign-in pages, harvesting corporate credentials from travellers across several American cities plus India and Saudi Arabia.
The counterfeit pages harvested corporate credentials from hotel guests, not any data from Microsoft's own servers; ReliaQuest's 23 July report found no compromise of the Microsoft 365 service itself.