Microsoft Confirmation Turns Hotel Wi‑Fi Into Attack Surface

The important shift is attribution: this is now a confirmed Midnight Blizzard sub-campaign, not just a suspicious captive-portal abuse pattern. The trust gap is the point of entry. Travelers are being intercepted through the network’s own connectivity checks and pushed into Microsoft sign-in flows that look ordinary enough to follow. Microsoft says Storm-2945 has been behind the campaign since May, targeting hotel, conference, and other shared captive-portal networks in several countries. The activity has used captive-portal DNS and HTTP tampering, fake updates, and device-code authentication on real Microsoft sign-in pages to steal Microsoft 365 credentials and session tokens from employees in financial services, legal, healthcare, energy, retail, and technology. The real risk is that the user does not need to click a suspicious link or visit a bad site. Answering an automatic network check or entering a device code on a genuine Microsoft page is enough to hand over access, which leaves valid accounts and live sessions exposed even after the network issue is fixed.

Part of the PlainSec briefing for 2026-08-03

Editions

Sources