Act
archived
Hotel Wi-Fi DNS hijacked to phish Microsoft 365 credentials
- Engineer — Plan: Review whether corporate travel policy requires VPN enforcement on untrusted Wi-Fi; audit M365 tenant for conditional access policies that would block logins from non-compliant networks or flag impossible-travel anomalies.
- SOC/IR — Act: Hunt for M365 sign-ins from hotel/conference-center IP ranges or unexpected geolocations since this campaign began; tune Conditional Access or SIEM rules to flag credential use immediately after untrusted-network logins.
- Leader — Learn: A reminder that credential phishing via rogue DNS is an ongoing risk for traveling employees; no board-level action warranted without evidence of organizational impact, but useful context for travel security awareness programs.
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.