Warning: Compromised Hotel Routers Send Users to Phishing Sites

KnowBe4 Team | Aug 14, 2026

Attackers are using compromised hotel Wi-Fi routers to redirect users to Microsoft 365 phishing sites, according to researchers at ReliaQuest. The attacks were observed in multiple U.S. cities, as well as across India and Saudi Arabia. These types of DNS poisoning attacks can send users to phishing sites with very little evidence that something suspicious has taken place.

The researchers note, “We observed traffic to these compromised gateways from organizations in a range of industries, including financial services, professional services, legal, health care, energy, and retail—confirming this isn't sector-specific targeting, but a campaign that highly likely goes after traveling employees wherever they connect.”

This campaign is particularly dangerous because the victims aren’t targeted with suspicious emails; they’re simply presented with a legitimate-looking Microsoft 365 login page. The phishing sites are also designed to intercept OAuth tokens, granting the attacker access to the account after the user approves a prompt.

“From the user’s perspective, the experience may not appear overtly suspicious: they are redirected to what appears to be a Microsoft 365-related sign-in or authorization prompt without having clicked a phishing email or link,” ReliaQuest says. “What the user can't see is that approving the prompt authorizes a session initiated by the attacker. Once approved, Microsoft issues valid OAuth tokens to the attacker-controlled client that initiated the device-code flow. As a result, the attacker can obtain MFA-satisfied access to Microsoft 365 without collecting credentials on a fake page or intercepting authentication traffic in transit.”

This campaign highlights why users should always maintain a healthy sense of suspicion while using the internet, even if they haven’t encountered a suspicious message or link.

KnowBe4 empowers your workforce to make smarter security decisions every day. Over 70,000 organizations worldwide trust the KnowBe4 Platform to strengthen their security culture and reduce workforce risk.

ReliaQuest has the story: https://reliaquest.com/blog/threat-spotlight-dns-poisoning-tactics-expand-to-hospitality/

See KnowBe4 Security Awareness Training in Action

See how you can efficiently safeguard your organization from sophisticated social engineering threats.

Request a Demo

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.