Wi-Fi DNS hijack
Cybersecurity Checklist for Remote Workers: 12 Essential Steps

Hackers are quietly changing the DNS settings on Wi-Fi routers at hotels, airports, and conference centers around the world — including in Saudi Arabia and India — to redirect traveling professionals to fake Microsoft 365 login pages and steal their corporate credentials. The campaign, disclosed on July 24, 2026 by cybersecurity firm ReliaQuest, has been active since at least June 2026 and has already affected organizations across financial services, healthcare, legal, energy, and retail sectors. For the millions of Filipino professionals who travel for work — OFWs on business trips, seafarers between contracts, digital nomads, and consultants — the hotel Wi-Fi DNS hijack represents a threat that bypasses even the most robust password protections, including multi-factor authentication.

The attack is particularly relevant to Filipino professionals because ReliaQuest identified compromised Wi-Fi gateways in Saudi Arabia — home to over 1 million OFWs — as well as in India, the United States, and other regions. The connection between hotel Wi-Fi and stolen Microsoft 365 credentials directly affects every Filipino professional who checks work email or accesses corporate systems from a hotel lobby, airport lounge, or conference venue while traveling.

## Key Takeaway

🎯 The Threat: Hackers are hijacking hotel and conference center Wi-Fi routers by exploiting weak management interfaces, then changing DNS settings to redirect users to fake Microsoft 365 login pages. The campaign has been active since June 2026 and spans multiple countries including Saudi Arabia and India.

📊 The Impact: Organizations in financial services, healthcare, legal, energy, and retail have been affected. The attack bypasses multi-factor authentication using a technique called device-code authentication flow, which tricks users into authorizing the attacker’s session without stealing passwords.

⚠️ Who Is at Risk: Any professional who connects to hotel, airport, or conference Wi-Fi and accesses Microsoft 365, Outlook, or corporate systems. Filipino OFWs, business travelers, and digital nomads are prime targets because they frequently use public Wi-Fi while traveling.

🔑 How It Works: The attacker gains administrator access to the Wi-Fi gateway, changes its DNS settings, and registers fake domains like m365-owa.com and owa-ms365.com. When users try to access Microsoft 365, they are silently redirected to a fake login page that captures their credentials.

🛡️ What You Can Do: Use an always-on VPN, enable encrypted DNS, disable WPAD on your devices, and never approve unexpected authentication prompts when using public Wi-Fi.

Wi-Fi DNS hijack

How the Hotel Wi-Fi DNS Hijack Works

To understand this attack, it helps to know what DNS does. DNS (Domain Name System) is the internet’s phone book. When you type “office.com” into your browser, DNS translates that human-readable name into the numerical IP address of Microsoft’s servers. Your device sends the request to a DNS server — usually provided by your internet connection — and the server tells your device where to go.

In this attack, hackers change the DNS settings on the hotel’s Wi-Fi router itself. This means that when you connect to the hotel Wi-Fi and try to access Microsoft 365, the compromised router intercepts your request and sends you to a fake login page instead of the real Microsoft site. The fake page looks identical to the real one — same logo, same layout, same colors. The difference is that when you type your username and password, you are handing them to the attacker, not to Microsoft.

ReliaQuest says the attackers registered at least four domains for their fake Microsoft login portals: m365-owa.com, owa-ms365.com, ms365-device.com, and ms365-live.com. These domain names are designed to look legitimate at a glance — they contain “m365” and “owa” (Outlook Web Access), which are terms that professionals associate with Microsoft 365. But they are not Microsoft domains, and the fake login pages they host are designed to capture credentials and session tokens.

The initial access to the Wi-Fi gateways is still unclear. ReliaQuest says the attackers likely exploited weakly protected management interfaces — the administrator panels that IT staff use to configure routers and access points. Many hotel Wi-Fi systems use default or weak passwords on these management interfaces, making them easy targets. Once the attacker has administrator access, they modify the DNS settings and the trap is set for every guest who connects.

Why This Attack Bypasses Multi-Factor Authentication

The most alarming aspect of the hotel Wi-Fi DNS hijack is that it can bypass multi-factor authentication (MFA) — the security measure that most Filipino professionals and organizations rely on to protect their accounts. MFA requires a second form of verification (a code from your phone, a biometric scan, or a security key) in addition to your password. It is the single most effective defense against account takeovers, as covered in our multi-factor authentication guide.

But the hotel Wi-Fi attack uses a technique called “device-code authentication flow” that turns MFA into a liability rather than a protection. Here is how it works: the attacker initiates a login session on their own device using Microsoft’s device-code flow — a legitimate authentication method designed for devices that cannot display a web page (like smart TVs, printers, or IoT devices). The flow generates a code and asks the user to visit a Microsoft URL and enter the code to approve the session.

In the attack, the user is redirected to a fake Microsoft page that displays this prompt. The user, believing they are simply logging into Microsoft 365 as usual, approves the prompt. What the user cannot see is that they are not authorizing their own session — they are authorizing the attacker’s session. A legitimate authentication token is then issued to the attacker, who can now access the user’s Microsoft 365 account, read their email, download their files, and move laterally through the organization’s network — all without ever needing the user’s password or MFA code.

ReliaQuest notes that using public DNS servers like Google’s 8.8.8.8 does not prevent this attack. The compromised Wi-Fi gateway intercepts the DNS request before it reaches the public resolver, so even if your device is configured to use Google DNS, the forged response arrives first.

The Filipino Professional Connection

For Filipino professionals, the hotel Wi-Fi DNS hijack is not a theoretical threat — it is a practical risk that applies to daily life. Consider the scenarios: a Filipino engineer on a project assignment in Saudi Arabia checking corporate email from a hotel in Riyadh. A Filipino nurse between contracts connecting to Wi-Fi at a Dubai airport lounge. A Filipino consultant presenting at a conference in Singapore. A Filipino seafarer accessing online banking during a port call. Each of these scenarios involves connecting to Wi-Fi that the professional does not control — and each is a potential entry point for the DNS hijack attack.

ReliaQuest’s finding that compromised gateways were identified in Saudi Arabia is particularly significant for the Filipino community. Saudi Arabia hosts over 1 million OFWs, many of whom travel frequently between cities and compounds. Hotel Wi-Fi, airport Wi-Fi, and conference center Wi-Fi are all commonly used by Filipino professionals in the Gulf region. As documented in our cybersecurity checklist for remote workers, public Wi-Fi is already the most common attack surface for traveling professionals — and DNS hijacking makes public Wi-Fi dangerous even when the user is careful about what they click.

The attack also connects to a broader pattern of threats targeting Microsoft 365 users. In 2026, BleepingComputer reported multiple phishing campaigns specifically targeting Microsoft 365 accounts, including the Forg365 phishing platform that uses AI to create convincing fake login pages, and the EvilTokens phishing-as-a-service toolkit that sells access to Microsoft 365 phishing infrastructure. The hotel Wi-Fi DNS hijack is the latest evolution — it does not even require the user to click a link in an email. The attack comes through the network connection itself.

How to Protect Yourself from Hotel Wi-Fi DNS Hijacking

ReliaQuest recommends several specific measures that every Filipino professional should implement before their next trip:

1. Use an always-on VPN. A Virtual Private Network (VPN) creates an encrypted tunnel between your device and a trusted server, preventing the compromised Wi-Fi gateway from intercepting or redirecting your traffic. The VPN must be “always-on” — meaning it connects automatically whenever you join a Wi-Fi network — not just activated when you remember. Full-tunnel VPNs are more effective than split-tunnel configurations, which may still route DNS requests through the compromised gateway.

2. Enable encrypted DNS. Traditional DNS requests are sent in plain text, meaning the compromised Wi-Fi gateway can read and forge them. Encrypted DNS (using protocols like DNS over HTTPS or DNS over TLS) encrypts the request, preventing the gateway from intercepting it. Your browser or operating system settings should have an option to enable encrypted DNS in “strict” mode.

3. Disable WPAD. Windows Proxy Auto-Discovery (WPAD) is a feature that automatically finds and applies proxy settings on your device. The attackers in the ReliaQuest investigation attempted to abuse WPAD in roughly one-third of cases. Disabling WPAD prevents the compromised gateway from injecting a malicious proxy configuration into your system.

4. Never approve unexpected authentication prompts. If you are using hotel or public Wi-Fi and suddenly see a Microsoft authentication prompt asking you to approve a session or enter a code, do not approve it. This is the device-code authentication flow attack in action. Legitimate Microsoft 365 logins do not typically require you to approve a session on a separate device unless you have explicitly initiated the login.

5. Disable device-code authentication flow when not needed. Organizations using Microsoft Entra ID (formerly Azure Active Directory) can disable the device-code authentication flow for users who do not need it. This blocks the specific technique used in the hotel Wi-Fi attack. Check with your IT department if you are unsure whether this applies to you.

These measures align with the broader security practices every Filipino professional should follow when working or traveling abroad. As covered in our complete cybersecurity guide for Filipinos, the combination of VPN, MFA, and situational awareness remains the strongest defense against evolving threats — even when the threat is as sophisticated as a DNS hijack that bypasses MFA itself.

Frequently Asked Questions About Hotel Wi-Fi DNS Hijacking

What is a hotel Wi-Fi DNS hijack?

A hotel Wi-Fi DNS hijack is an attack where hackers compromise the Wi-Fi router at a hotel, airport, or conference center and change its DNS settings to redirect users to fake Microsoft 365 login pages. When users try to access Microsoft 365, they are silently sent to the attacker’s fake login page instead of the real Microsoft site.

Does this attack affect all public Wi-Fi users?

The attack specifically targets Wi-Fi networks where the router has been compromised by the attacker. Not all public Wi-Fi is affected. However, the attack has been identified at hotels, airports, and conference centers in the United States, Saudi Arabia, India, and other regions. Any professional connecting to Wi-Fi they do not control should treat it as potentially compromised.

Can a VPN protect me from DNS hijacking?

Yes. An always-on, full-tunnel VPN encrypts all traffic between your device and the VPN server, including DNS requests. The compromised Wi-Fi gateway cannot intercept or redirect encrypted DNS requests. However, the VPN must be always-on and configured for full-tunnel mode to be effective against DNS hijacking.

Does multi-factor authentication protect against this attack?

In some cases, no. The attack uses a device-code authentication flow that tricks users into approving the attacker’s session. The attacker does not need to steal the user’s password or MFA code — they trick the user into authorizing a new session on the attacker’s device. Never approving unexpected authentication prompts while on public Wi-Fi is the key defense.

Which countries are affected by the hotel Wi-Fi DNS hijack campaign?

ReliaQuest identified compromised Wi-Fi gateways in multiple U.S. cities as well as in Saudi Arabia and India. The campaign has been active since at least June 2026 and affects organizations in financial services, healthcare, legal, energy, and retail sectors. Filipino professionals traveling to any of these regions should be particularly cautious.

How can I tell if I have been a victim of a DNS hijack?

Signs include unexpected Microsoft 365 login prompts, being redirected to login pages with unusual URLs (especially domains like m365-owa.com, owa-ms365.com, ms365-device.com, or ms365-live.com), and unexplained account activity or logins from unfamiliar locations. If you suspect compromise, change your password immediately, revoke active sessions in your Microsoft 365 security settings, and contact your IT department.

This article is for informational purposes only and does not constitute professional cybersecurity advice. Readers are encouraged to consult with qualified cybersecurity professionals for organization-specific security assessments.

Editorial Transparency Note:This article was researched and drafted with AI assistance, then reviewed, verified, and approved by Edmon Agron. All sources have been cross-checked against original publications as of the date of publication.

Leave a Reply