Hackers are changing DNS settings on hotel and conference-center Wi-Fi gateways to send travelers to fake Microsoft 365 login pages — without emailing a single phishing lure. ReliaQuest documented the campaign (active since at least June 2026); BleepingComputer covered it on July 24, 2026. Below: how the attack works, what travelers and IT teams should do, and an independent ranking of the top 10 U.S. hotel chains by public domain security score (100% = ideal).

Snapshot
| Field | Detail |
|---|---|
| What | DNS poisoning on captive-portal Wi-Fi gateways |
| Where | Hotels, conference centers; U.S. cities + India, Saudi Arabia |
| Since | At least June 2026 |
| Target | Traveling employees’ Microsoft 365 accounts |
| Sectors hit in traffic | Financial, professional services, legal, health care, energy, retail |
| Similar tradecraft | Overlaps FrostArmada / APT28-style gateway DNS abuse (ReliaQuest stops short of firm attribution) |
| Fake portals (reported) | m365-owa.com, owa-ms365.com, ms365-device.com, ms365-live.com |
How the attack works
| Step | What happens |
|---|---|
| 1. Gateway access | Attackers reach admin on the Wi-Fi appliance (exposed SSH / SNMP / web admin, weak credentials, or vulns) |
| 2. Poison DNS | Gateway forges DNS so “Microsoft” destinations resolve to attacker infrastructure |
| 3. Fake login | User on hotel Wi-Fi lands on a Microsoft-themed page and may enter credentials |
| 4. Device-code path | In some cases, a prompt leads the user to approve a session the attacker started — issuing a real OAuth token and bypassing MFA without stealing the password |
| 5. Optional WPAD | ~1/3 of cases also tried malicious PAC via WPAD (success not confirmed) |
Important: Setting your laptop DNS to Google 8.8.8.8 does not stop this — ReliaQuest says the gateway can forge plain-text DNS before the query leaves the network.

What travelers and Texas firms should do
| Do | Don’t |
|---|---|
| Use an always-on, full-tunnel VPN before any cloud login on hotel Wi-Fi | Trust a Microsoft-looking page just because you’re “already on the hotel portal” |
| Prefer encrypted DNS in strict mode (DoH/DoT) where policy allows | Assume changing DNS to 8.8.8.8 is enough |
| Disable WPAD on managed Windows devices | Approve unexpected device-code prompts |
| Disable or Conditional-Access-block device-code auth in Entra ID if unused | Bypass certificate / URL warnings |
| Verify the real Microsoft URL and cert before typing anything | Check email over open lobby Wi-Fi without a VPN |

Why a full-tunnel VPN matters on hotel Wi-Fi
ReliaQuest’s primary mitigation is an always-on, full-tunnel VPN (plus encrypted DNS in strict mode). That routes Microsoft 365 and other traffic through your tunnel before the poisoned gateway can answer DNS for login.microsoftonline.com or serve a fake portal.
| Requirement | Why |
|---|---|
| Connect VPN first | Before opening Outlook, Teams, browser M365, or approving any device-code prompt |
| Full tunnel (not split tunnel to M365) | Split tunnel can still leave Microsoft destinations on the hotel DNS path |
| Encrypted DNS (DoH/DoT) in strict mode | Reduces plaintext DNS the gateway can forge — VPN alone is still the priority on captive portals |
| Kill switch / block LAN | Stops apps from leaking off-tunnel if the VPN drops mid-login |
Captive portals sometimes block VPN until you “accept Wi-Fi terms.” Connect to the portal, complete the splash page, then start the VPN, then open Microsoft 365.
VPN options — consumer, SMB, and corporate
Pick the lightest control that still gives a full tunnel before cloud login. Audits below are public domain scores (100% = ideal), not a product review of VPN privacy or speed.
Consumer / individual travelers
| Option | Best for | Notes |
|---|---|---|
| Proton VPN | Privacy-focused travelers and solo consultants | Easy apps on Windows / Mac / mobile; use full tunnel before M365. Sign-up: pr.tn/ref/Z80JCX6Z |
| Cloudflare WARP (1.1.1.1 with WARP) | Free / low-friction DNS + tunnel on personal devices | Good complement for encrypted DNS; confirm it covers the apps you use and is allowed by your employer |
| NordVPN / ExpressVPN / similar | Travelers who already subscribe | Enable kill switch + full tunnel; treat as personal VPN unless IT approves |
SMB (5–200 seats)
| Option | Best for | Notes |
|---|---|---|
| Cloudflare Zero Trust / WARP | SMBs already on Cloudflare | Device posture + gateway policies; steer Microsoft 365 through the tunnel on unmanaged hotel Wi-Fi |
| Tailscale / WireGuard mesh | Small teams with light IT | Fast to deploy; pair with conditional access so M365 only works from healthy devices |
| Microsoft 365 + always-on VPN (Windows) | Firms standardized on Microsoft | Use Always On VPN or a supported client MDM-enforced before Outlook/Teams |
| Proton VPN business / team plans | Privacy-minded SMBs | Useful when staff travel constantly and you need a simple mandated client — Proton VPN |
Corporate / enterprise
| Option | Best for | Notes |
|---|---|---|
| Zscaler / Netskope / similar SSE | Regulated industries | Full SSL inspection + private access; enforce before hotel networks |
| Cloudflare Zero Trust Gateway | Global hybrid workforce | Combine WARP + Gateway + Access policies for M365 |
| GlobalProtect / AnyConnect / corporate VPN | Existing Palo Alto / Cisco estates | Mandate full tunnel on travel profiles; block split-tunnel to Microsoft |
| Entra Conditional Access | Any M365 tenant | Require compliant device + compliant network / VPN signal where possible; block device-code flow |
Quick chooser
| You are… | Start here |
|---|---|
| Solo traveler / consultant | Proton VPN or Cloudflare WARP — connect before any M365 login |
| Texas SMB without a VPN yet | Cloudflare Zero Trust or Tailscale + CA policies; optional Proton VPN for staff BYOD |
| Enterprise with SSE | Keep SSE; add travel profile that forbids M365 off-tunnel on guest Wi-Fi |
We may earn a commission if you sign up for Proton VPN through the link above.
VPN-related domain audits (July 26, 2026)
| Provider | Domain | Overall | Identity | Transport | Website | vs 100% ideal |
|---|---|---|---|---|---|---|
| Cloudflare | cloudflare.com | 88% | 90% | 45% | 100% | −12 |
| NordVPN | nordvpn.com | 86% | 95% | 15% | 92% | −14 |
| Tailscale | tailscale.com | 77% | 70% | 15% | 95% | −23 |
| Zscaler | zscaler.com | 75% | 65% | 15% | 95% | −25 |
| Proton | proton.me | 74% | 50% | 100% | 98% | −26 |
| Proton VPN | protonvpn.com | 55% | 50% | 45% | 43% | −45 |
| ExpressVPN | expressvpn.com | 44% | 25% | 15% | 43% | −56 |
These scores measure public email / transport / website posture, not whether a VPN product defeats hotel DNS poisoning. For that job, the configuration that matters is full tunnel before Microsoft login.
Audit links: cloudflare.com · nordvpn.com · tailscale.com · zscaler.com · proton.me · protonvpn.com · expressvpn.com
Hospitality brands are not accused of running the phishing pages — the risk is shared guest gateways. Still, chains with soft public mail-transport posture make spoofed “hotel Wi-Fi / loyalty / booking” follow-up email easier after a traveler is compromised.
Top 10 U.S. hotel chains — domain security ranking
We audited the corporate / consumer domains of the largest U.S. hotel groups (by brand footprint) on July 26, 2026. Ranked by overall score. 100% is the ideal — none reach it.
| Rank | Chain | Domain | Overall | Identity | Transport | Website | Level | vs 100% |
|---|---|---|---|---|---|---|---|---|
| 1 | Marriott International | marriott.com | 70% | 95% | 15% | 37% | Good | −30 |
| 2 | Hyatt Hotels | hyatt.com | 68% | 90% | 15% | 37% | Above Average | −32 |
| 3 | IHG Hotels & Resorts | ihg.com | 67% | 50% | 15% | 87% | Above Average | −33 |
| 4 | Best Western | bestwestern.com | 66% | 85% | 15% | 37% | Above Average | −34 |
| 5 | G6 Hospitality (Motel 6) | motel6.com | 63% | 75% | 15% | 40% | Above Average | −37 |
| 6 | Hilton | hilton.com | 62% | 75% | 15% | 37% | Above Average | −38 |
| 7 | Wyndham Hotels | wyndhamhotels.com | 54% | 65% | 15% | 37% | Average | −46 |
| 8 | Extended Stay America | extendedstayamerica.com | 54% | 65% | 15% | 37% | Average | −46 |
| 9 | Red Roof | redroof.com | 50% | 45% | 15% | 37% | Average | −50 |
| 10 | Choice Hotels | choicehotels.com | 43% | 25% | 15% | 40% | Below Average | −57 |
Pattern across all 10
Every chain in this set scores transport 15% — the same soft public mail-transport signal we see after many Texas BEC and spoofing incidents. Identity is the separator: Marriott (95%) and Hyatt (90%) lead; Choice (25%) and Red Roof (45%) lag. A high identity score does not secure the lobby gateway; it does reduce how easy it is to spoof “marriott.com / hilton.com” booking or loyalty mail after an M365 takeover.
Story / publisher domains
| Organization | Domain | Overall | Identity | Transport | Website | vs 100% |
|---|---|---|---|---|---|---|
| ReliaQuest | reliaquest.com | 73% | 65% | 15% | 87% | −27 |
| Microsoft | microsoft.com | 68% | 90% | 70% | 45% | −32 |
| BleepingComputer | bleepingcomputer.com | 63% | 75% | 15% | 40% | −37 |
Audit links (hotels): marriott.com · hyatt.com · ihg.com · bestwestern.com · motel6.com · hilton.com · wyndhamhotels.com · extendedstayamerica.com · redroof.com · choicehotels.com
Also: reliaquest.com · microsoft.com · bleepingcomputer.com
Website stack note
Passive website-tech probes on July 26, 2026 completed for 13 of 13 domains (0 notable):
| Domain | Stack signal |
|---|---|
| All 10 hotel chains + reliaquest.com + bleepingcomputer.com + microsoft.com | No notable public CMS / PHP / short-horizon TLS flags |
A clean corporate website fingerprint does not mean guest Wi-Fi gateways are patched or locked down — ReliaQuest’s findings were on captive-portal appliances, not marriott.com marketing pages. Point-in-time only; not proof of exploitability.
Priority actions for IT teams
- Mandate full-tunnel VPN for any Microsoft 365 / Entra access off corp network — especially hotels and conferences (Proton VPN for individuals/BYOD; Cloudflare Zero Trust / corporate VPN / SSE for managed fleets).
- Block device-code flow in Entra Conditional Access unless a documented exception exists.
- Disable WPAD on managed Windows endpoints; prefer encrypted DNS in strict mode where policy allows.
- Hunt for logins from anomalous locations right after travel; revoke sessions on suspicious OAuth grants.
- Train staff: hotel Wi-Fi can lie about DNS; VPN on first, then verify URLs; never approve mystery device-code prompts.
- Hospitality operators: lock down gateway admin (no internet-exposed SSH/SNMP/admin), unique passwords, firmware updates, and monitor DNS config changes.
Related
- Delta Flight 591 in-flight Wi-Fi phishing
- ISP customer-router public Wi-Fi hotspot risk
- You’re Invited phishing alert
- FaceTime bank scam
- Surfside Beach BEC + lookalike domains
Run a free Instant Cybersecurity Audit at audit.emailmenow.com or contact EmailMeNow IT Consulting for travel VPN policy, Entra hardening, and DMARC / MTA-STS work aimed at the 100% ideal.
Sources: BleepingComputer — Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts · ReliaQuest — DNS poisoning tactics expand to hospitality Wi-Fi · Infosecurity Magazine — Hotel Wi-Fi routers compromised