Security Alert: Hijacked Hotel Wi-Fi Is Stealing Microsoft 365 Logins — What Traveling Dental Teams Need to Know - Compudent Systems
Information Technology Solutions for Dentists and the Dental Industry. Serving the GTA and Southern Ontario.
Dental I/T, Dental Information Technology, Network Security, Toronto, GTA, Dental, Network, I/T, Information Technology, Computer, Data, Abeldent, Dentrix, LiveDDM, Patterson Dental, Henry Schein, K-Dental, Sinclair Dental, Schick CDR, Dexis, Carestream, Carestream Dental, Digital Radiography, X-ray, Dental X-ray, Dental Software Support, Software
17426
bp-nouveau,wp-singular,post-template-default,single,single-post,postid-17426,single-format-standard,wp-theme-bridge,wp-child-theme-bridge-child,theme-bridge,woocommerce-no-js,ajax_fade,page_not_loaded,,columns-4,qode-child-theme-ver-1.0.0,qode-theme-ver-10.0,wpb-js-composer js-comp-ver-4.12,vc_responsive

Security Alert: Hijacked Hotel Wi-Fi Is Stealing Microsoft 365 Logins — What Traveling Dental Teams Need to Know

A traveler using a laptop on hotel Wi-Fi with glowing network signals shifting from blue to warning grey

Security Alert: Hijacked Hotel Wi-Fi Is Stealing Microsoft 365 Logins — What Traveling Dental Teams Need to Know

Imagine a hygienist or associate dentist at a continuing-education weekend, catching up on email from the hotel lobby between sessions. They open the laptop, join the hotel Wi-Fi, and sign in to Microsoft 365 exactly as they do every day. Nothing looks wrong. Yet in a campaign uncovered by security researchers at ReliaQuest and reported by BleepingComputer, that single routine action can quietly surrender the entire practice account — email, files, Teams and SharePoint — to an attacker who never sent a phishing message at all.

What’s Actually Happening

Researchers are tracking a campaign, active since at least June 2026, in which threat actors compromise the captive-portal Wi-Fi gateway appliances used at hotels, conference centers and other public venues. Investigators found poisoned gateways across multiple U.S. cities as well as India and Saudi Arabia, and have tied the activity to techniques resembling those of the Russian espionage group APT28 (Fancy Bear). Once inside the gateway, the attackers change its DNS settings — the internet’s address book — so that every device on that network is silently pointed at attacker-controlled infrastructure.

From there, when a guest tries to reach a legitimate Microsoft 365 sign-in page, they are invisibly rerouted to a convincing fake instead. Type in a username and password, and those credentials are captured and replayed against the real corporate account. There is no suspicious email, no malicious attachment, no link to hover over. Simply connecting to the poisoned network and logging in as normal is enough.

A traveler using a laptop on hotel Wi-Fi with glowing network signals shifting from blue to warning grey
Connecting to public hotel Wi-Fi can be enough to hand an attacker your Microsoft 365 login — no phishing email required.

Why This Attack Is So Dangerous

Most of the security training dental teams receive focuses on spotting bad emails: don’t click strange links, don’t open unexpected attachments. This campaign sidesteps all of it. It also bypasses endpoint malware protection, because nothing is installed on the device — the theft happens at the network level, upstream of the laptop entirely.

Worse, one variant researchers observed does not even need your password. Victims are funneled into a fake “device-code” sign-in prompt and asked to approve it. What the user cannot see is that approving that prompt authorizes a session the attacker started — handing over a legitimate access token and quietly stepping around multi-factor authentication without ever capturing a credential. The victim believes they are on a trusted network looking at the real Microsoft login; the only differences are subtle, like the exact domain in the address bar or a certificate warning a rushed traveler is all too likely to dismiss.

Abstract isometric illustration of network traffic being rerouted by a compromised gateway to a malicious server
By altering DNS settings on the Wi-Fi gateway, attackers silently steer every request to their own infrastructure.

What a Stolen Microsoft 365 Account Exposes

For a dental practice, a compromised M365 account is not a minor inconvenience — it is a direct line into the information you are legally obligated to protect. A single stolen login can expose:

  • Email threads containing patient names, appointment details and referral correspondence
  • SharePoint and OneDrive files, potentially including treatment documentation and administrative records
  • Teams chats and shared channels used by clinical and front-desk staff
  • A trusted identity the attacker can use to send convincing internal messages to colleagues, vendors or patients

Under PHIPA in Ontario — and HIPAA for practices with cross-border obligations — unauthorized access to patient information can trigger mandatory breach reporting, regulatory scrutiny and a serious loss of patient trust. The account that felt like a convenience is also the account that touches your most sensitive data.

Two nearly identical blank login cards, one glowing safe blue and one cracked with a warning glow
The fake portal is a pixel-perfect clone — the only reliable tell is the exact login domain and certificate warnings.

Why Dentists Are Squarely in the Crosshairs

ReliaQuest reports that the campaign is not sector-specific but instead targets traveling employees wherever they connect — and health care is explicitly among the industries seen in the compromised traffic. Dental professionals travel more than most people realize. CE courses, provincial and national dental conventions, study clubs, vendor training and hardware demonstrations all put staff in hotels and conference centers — precisely the venues being compromised. A practice owner reviewing charts from a conference hotel, or an office manager approving invoices over breakfast Wi-Fi, is exactly the kind of high-value, on-the-road target these attackers are counting on.

How to Protect Your Practice on the Road

The good news is that this attack, for all its cleverness, is defeated by a handful of disciplined habits and modern account controls. Recommend the following to everyone on your team before their next trip:

  • Avoid open hotel Wi-Fi for anything sensitive. A cellular hotspot or a known, trusted network is far safer than a shared captive portal.
  • Use a reputable VPN. An encrypted, full-tunnel connection prevents the local network from tampering with or redirecting your traffic.
  • Adopt phishing-resistant MFA and passkeys. A fake login page cannot replay a passkey or a hardware security key, even if the password is captured.
  • Block or tightly restrict device-code sign-in in Microsoft 365. This closes the variant that tricks users into approving an attacker’s session and slips past ordinary MFA.
  • Enable Conditional Access and impossible-travel rules. These can automatically block or challenge logins that appear from unexpected locations or unmanaged devices.
  • Never dismiss a certificate or security warning — treat it as a stop sign — and check the exact login domain before entering credentials.
A dental office workstation protected by a glowing shield and a passkey security token within a secured network boundary
Phishing-resistant MFA and passkeys defeat fake login pages — and blocking device-code sign-in closes the MFA-bypass variant.

Lock Down What a Single Account Can Reach

Individual vigilance matters, but resilient practices assume that one account will eventually be compromised and limit the blast radius in advance. That means enforcing multi-factor authentication across every M365 account, applying least-privilege access so no single login can reach everything, segmenting patient data from general file storage, and monitoring for the anomalous sign-ins that signal a stolen credential or hijacked session in use. Configured correctly, these controls turn a potential breach into a contained, recoverable event.

A close-up of a Wi-Fi gateway appliance with a warning status light and distorted signal ripples
The venue’s own gateway hardware is the weak point — once it is compromised, every guest is exposed.

The Bottom Line for Dental Practices

Attackers no longer need to trick your team into clicking anything — they only need your staff to connect to the wrong network at the wrong time. As dental professionals head to summer and fall CE events and conventions, the risk to Microsoft 365 accounts and the patient data behind them is real and active right now.

Compudent Systems helps dental practices across Ontario secure their Microsoft 365 environments, deploy phishing-resistant MFA and Conditional Access, and build imaging and IT infrastructure that keeps patient data protected on-site and on the road. If you are unsure how your practice would hold up against an attack like this, contact Compudent Systems for a security assessment — we will help you close the gaps before they are found for you.


Sources & further reading:

Related Reading



Contact us today - How can we help you?