>samit_hota
Back to security news
SN-2026-196HighOpen

Hacked Public Wi-Fi Gateways Exploited to Steal Corporate M365 Credentials

Samit Hota·
CVE ID
N/A
Affected Products / Orgs
Public Wi-Fi network gateway appliances, Microsoft 365 enterprise users
#news#vulnerability-disclosure#public

Exploitation of Hospitality and Public Wi-Fi Infrastructure

Traveling corporate personnel connecting to remote networks face increased risks as threat actors actively compromise public Wi-Fi gateways to execute adversary-in-the-middle (AiTM) attacks. Malicious actors are hijacking vulnerable gateway hardware installed at hotels, airports, and public venues to intercept network traffic and harvest corporate Microsoft 365 credentials.

Attack Mechanics and Credential Theft

Rather than relying on generic rogue access points, attackers target unpatched management interfaces and known vulnerabilities in network gateway appliances managing public guest Wi-Fi. Once control over the gateway appliance is established, the adversary manipulates network traffic passing through the device.

When an employee connects to the compromised network and attempts to log into corporate resources, the manipulated gateway redirects authentication sessions or injects malicious reverse-proxy frameworks. This setup allows the attacker to intercept plain-text credentials, multi-factor authentication (MFA) tokens, and session cookies in real time. Because authentication requests are relayed live to legitimate Microsoft 365 endpoints, attackers successfully bypass standard MFA defenses, capturing valid session tokens that grant persistent access to corporate email, OneDrive, and SharePoint environments.

Protecting Mobile Workforces

Securing corporate credentials against gateway-level network interception requires shifting reliance away from local network trust:

  • Mandatory Mobile VPN Enactment: Mandate always-on, pre-logon Virtual Private Networks (VPN) or Zero Trust Network Access (ZTNA) clients on all enterprise laptops and mobile devices to encrypt all egress traffic before it hits local gateways.
  • FIDO2 / Passkey Authentication: Transition Microsoft 365 authentication policies from OTP or push-based MFA to FIDO2-compliant hardware keys or device-bound passkeys, which mathematically bind authentication requests to the verified domain name, rendering proxy-based credential harvesting ineffective.
  • Conditional Access Controls: Implement Microsoft Entra ID Conditional Access policies enforcing compliant device checks, user-risk monitoring, and location anomaly rules to block logins originating from untrusted network infrastructures.

Found something similar in your stack?

Let's find out before it becomes an incident.

Book an advisory call