State Linked Captive Portals Trap Traveling Microsoft 365 Users
The risk has shifted from a suspicious Wi‑Fi abuse pattern to a confirmed espionage campaign. Microsoft now attributes the captive-portal credential theft wave to Storm-2945, a Midnight Blizzard subgroup, which means hotel and conference Wi‑Fi can be a state-linked interception layer for traveler logins.
Microsoft says the campaign is abusing compromised public Wi‑Fi gateway and captive-portal systems to alter what users see on the network path, then capture Microsoft 365 credentials and session tokens from travelers. The activity has hit hospitality-related networks and other captive-portal environments in several countries, with targets across financial services, legal, healthcare, energy, and retail.
The practical break is that identity theft can start before the user reaches a real Microsoft prompt, so endpoint-only phishing controls miss the trust failure. For organizations with traveling users, valid accounts and live sessions are now part of the exposure, not just passwords.