Public Wi‑Fi Gateways Become Cross-Tenant Phishing Points
A hotel or conference Wi‑Fi gateway can do more than provide access. If an attacker controls it, the venue network itself becomes the phishing endpoint, and the damage follows roaming employees back into their Microsoft 365 tenant instead of stopping at the lobby.
ReliaQuest says this has been happening since at least June 2026 at shared venues in the US, India, and Saudi Arabia. The attackers changed DNS on compromised captive-portal gateways and SOHO routers so Microsoft 365 logins were sent to look-alike pages, letting them capture credentials and other sensitive data from travelers across many industries.
That breaks the usual trust model for public Wi‑Fi. The user still sees the internet working, but the login destination has been swapped underneath them, so a compromise at one venue can affect unrelated organizations whose employees sign in there.