State Linked Captive Portals Trap Traveling Microsoft 365 Users

The risk has shifted from a suspicious Wi‑Fi abuse pattern to a confirmed espionage campaign. Microsoft now attributes the captive-portal credential theft wave to Storm-2945, a Midnight Blizzard subgroup, which means hotel and conference Wi‑Fi can be a state-linked interception layer for traveler logins. Microsoft says the campaign is abusing compromised public Wi‑Fi gateway and captive-portal systems to alter what users see on the network path, then capture Microsoft 365 credentials and session tokens from travelers. The activity has hit hospitality-related networks and other captive-portal environments in several countries, with targets across financial services, legal, healthcare, energy, and retail. The practical break is that identity theft can start before the user reaches a real Microsoft prompt, so endpoint-only phishing controls miss the trust failure. For organizations with traveling users, valid accounts and live sessions are now part of the exposure, not just passwords.

Part of the PlainSec briefing for 2026-08-03

Every edition of this story: State Linked Captive Portals Trap Traveling Microsoft 365 Users

Sources