Microsoft-365 Accounts Compromised by Hotel Wi‑Fi DNS Attacks and AI Cloud Security Gaps
A 2026 Cloud Security Report from Check Point shows that 78% of enterprises experienced AI‑related security incidents in 2025. While three‑quarters of firms have updated their cloud security strategies to address AI, only 26% possess the architectural controls to enforce those policies, leaving a 51‑point gap between intent and capability. Attackers are already exploiting AI tools to accelerate phishing, generate malware and launch faster attacks.
Since June 2026 a separate campaign has hijacked Wi‑Fi gateways in hotels and conference centers. By compromising captive‑portal appliances through weak passwords or exposed management interfaces, attackers manipulate DNS responses so that Microsoft‑365 login attempts are redirected to counterfeit sites. The scheme bypasses multi‑factor authentication by abusing Microsoft’s Device‑Code‑Flow, allowing a valid OAuth token to be captured without stealing passwords. Four malicious domains have been identified, highlighting the risk of cloud‑based account compromise from public networks.