OCybercriminals have been exploiting compromised public Wi-Fi gateway appliances to harvest Microsoft 365 credentials from corporate employees while traveling. The attacks specifically target business users who connect to public wireless networks at airports, hotels, and other locations frequented by traveling professionals.
The threat actor gains control of Wi-Fi gateway devices that manage public network access, positioning themselves to intercept authentication traffic. When employees attempt to access their corporate Microsoft 365 accounts through these compromised networks, the attackers can capture login credentials in real time.
The attack method takes advantage of the trust users place in public Wi-Fi infrastructure. By compromising the gateway appliances themselves rather than simply monitoring network traffic, the attackers gain a privileged position to conduct credential harvesting operations. The specific technical methods used to compromise the gateways and intercept credentials were not detailed in available reporting.
Traveling employees represent a particularly vulnerable target population because they frequently rely on public Wi-Fi networks to maintain productivity while away from secure corporate environments. Organizations with mobile workforces face elevated risk from this attack vector, especially those in industries requiring frequent business travel.
Security teams should immediately warn employees about the risks of accessing corporate accounts over public Wi-Fi networks. Organizations must enforce multi-factor authentication across all Microsoft 365 accounts to prevent stolen credentials from providing direct access. Companies should also consider deploying virtual private network solutions for traveling staff and implementing conditional access policies that flag or block authentication attempts from suspicious network locations.
Source: https://www.securityweek.com/hacked-public-wi-fi-gateways-used-to-harvest-corporate-credentials/


