Tech Translated

IT Security & Technology Blog

Practical IT insights for Australian businesses. Our team covers cybersecurity advisories, compliance updates, and plain-English explainers on the technology your business relies on, published regularly as the landscape shifts.

High angle view of guests at a hotel reception desk — WiFi and IT services for hospitality venues

Hackers Are Hijacking Hotel Wi-Fi to Steal Microsoft 365 Logins

Cybersecurity researchers at ReliaQuest have uncovered an active campaign where attackers are compromising Wi-Fi gateways at hotels and conference centres, then poisoning DNS settings to redirect guests to fake Microsoft 365 login pages. The campaign has been running since at least June 2026 and has hit venues across the US, India, and Saudi Arabia. Financial services, legal, healthcare, and hospitality organisations have all had devices connect through affected gateways.

This attack doesn’t need phishing emails or malware on your device. Once an attacker gets into a gateway — often through weak admin passwords or exposed management interfaces — every device on that network is a target. In some cases, the attackers abuse Microsoft’s device-code authentication flow to bypass MFA entirely, meaning even organisations with strong authentication policies can be caught out. We regularly see Australian hospitality clients running guest and corporate traffic on the same network with factory-default gateway credentials still in place. That’s exactly the configuration this campaign exploits, and it’s far more common on the Northern Beaches and in regional venues than most operators realise.

If you run a hotel or venue: change default admin credentials on all Wi-Fi and network equipment today. Segment guest and corporate networks so a compromised gateway can’t reach staff accounts. Disable external access to management interfaces. For staff connecting to any shared Wi-Fi, enforce an always-on VPN and encrypted DNS. Disable the Device Code authentication flow in Microsoft Entra ID if you’re not actively using it — that’s the specific mechanism attackers are abusing to sidestep MFA.

All IT manages Wi-Fi and network infrastructure for hospitality businesses across Sydney and beyond. If you’re not sure whether your guest Wi-Fi is properly segmented and secured, get in touch — we’ll tell you straight.

Related Guide

Cybersecurity for Sydney SMBs

Explore our complete guide to protecting your business from cyber threats.

Read the Full Guide →