Hacked Public Wi-Fi Gateways Exploited to Steal Corporate M365 Credentials
- CVE ID
- N/A
- Affected Products / Orgs
- Public Wi-Fi network gateway appliances, Microsoft 365 enterprise users
Exploitation of Hospitality and Public Wi-Fi Infrastructure
Traveling corporate personnel connecting to remote networks face increased risks as threat actors actively compromise public Wi-Fi gateways to execute adversary-in-the-middle (AiTM) attacks. Malicious actors are hijacking vulnerable gateway hardware installed at hotels, airports, and public venues to intercept network traffic and harvest corporate Microsoft 365 credentials.
Attack Mechanics and Credential Theft
Rather than relying on generic rogue access points, attackers target unpatched management interfaces and known vulnerabilities in network gateway appliances managing public guest Wi-Fi. Once control over the gateway appliance is established, the adversary manipulates network traffic passing through the device.
When an employee connects to the compromised network and attempts to log into corporate resources, the manipulated gateway redirects authentication sessions or injects malicious reverse-proxy frameworks. This setup allows the attacker to intercept plain-text credentials, multi-factor authentication (MFA) tokens, and session cookies in real time. Because authentication requests are relayed live to legitimate Microsoft 365 endpoints, attackers successfully bypass standard MFA defenses, capturing valid session tokens that grant persistent access to corporate email, OneDrive, and SharePoint environments.
Protecting Mobile Workforces
Securing corporate credentials against gateway-level network interception requires shifting reliance away from local network trust:
- Mandatory Mobile VPN Enactment: Mandate always-on, pre-logon Virtual Private Networks (VPN) or Zero Trust Network Access (ZTNA) clients on all enterprise laptops and mobile devices to encrypt all egress traffic before it hits local gateways.
- FIDO2 / Passkey Authentication: Transition Microsoft 365 authentication policies from OTP or push-based MFA to FIDO2-compliant hardware keys or device-bound passkeys, which mathematically bind authentication requests to the verified domain name, rendering proxy-based credential harvesting ineffective.
- Conditional Access Controls: Implement Microsoft Entra ID Conditional Access policies enforcing compliant device checks, user-risk monitoring, and location anomaly rules to block logins originating from untrusted network infrastructures.
Related content
Crafted SVGs in Bing Image Search Allow SYSTEM Command Execution
Security News'Certighost' Flaw in Active Directory Certificate Services Enables Domain Compromise
Security NewsCertighost PoC Released: AD CS Vulnerability Allows Full Windows Domain Hijack
Security NewsCISA Adds Four Actively Exploited Vulnerabilities, Including SonicWall and Microsoft…
Found something similar in your stack?
Let's find out before it becomes an incident.
Book an advisory call