The hotel Wi-Fi works for someone else: DNS hijacked to steal Microsoft 365 accounts
Since June 2026 an active campaign has been compromising captive portals at hotels and conference centers, changing their DNS and redirecting guests to fake Microsoft 365 pages. The refined part: by abusing the device code flow they take your account without stealing your password, with MFA "satisfied". What is happening, why the padlock won't save you, and what we would do: from full-tunnel VPN to blocking the device code flow.