Reports say criminals compromise hotel Wi‑Fi networks by gaining control of Wi‑Fi gateways used by business travelers. Once a victim connects, the attacker redirects traffic to counterfeit Microsoft 365 login pages designed to collect Microsoft account credentials. Some accounts are reportedly accessed even when multifactor authentication is enabled, according to coverage describing how the phishing pages and related workflows can interfere with typical MFA protections. The campaign is described as focusing on Microsoft logins rather than malware downloads, relying primarily on deception and credential harvesting. The reports emphasize that travelers may be especially exposed when using Wi‑Fi in hotels, where network security practices and gateway integrity are not always under the traveler’s control. Companies and security researchers cited in the coverage advise users to treat unexpected login prompts and redirected Microsoft sign-in pages with caution, and to consider additional safeguards such as monitoring account activity. The details vary by account, but all coverage describes the same core pattern: hijacked hotel Wi‑Fi, redirected connections, and fraudulent Microsoft 365 sign-in attempts aimed at obtaining login information.