The break is in the network path, not just the login page. Storm-2945 is abusing hotel captive portals to steer travelers to attacker-controlled pages and downloads, so the compromise starts before the user ever sees a real Microsoft prompt.
Microsoft says the campaign has run since early May 2026 and includes traffic manipulation, malware delivery, and device-code and OAuth phishing tied to Entra ID and Microsoft 365. The actor also used AI to support much of the operation, which helps it scale across transient traveler networks rather than a single venue.
That makes travel connectivity part of the identity threat model. A stolen device-code grant or session can survive a password change, and hospitality networks can be part of the delivery path even when the hotel operator is not the final target.