Skip to content

Comment on Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accountsparent

Comments

It's in the article.. they hijacked the DNS to send the users to an alt phishing website.. looked identical to the Entra (M365) flow.. but the victims were sending their data/secrets/TOTP to hackers on slightly different URLs.

Most people are so used to the login flow, they don't inspect the URLS if the page looks right. Some popups even obscure the URL (almost impossible to detect).

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.