Threats · 56 days ago
The important shift is attribution: this is now a confirmed Midnight Blizzard sub-campaign, not just a suspicious captive-portal abuse pattern. The trust gap is the point of entry. Travelers are being intercepted through the network’s own connectivity checks and pushed into Microsoft sign-in flows that look ordinary enough to follow.
Microsoft says Storm-2945 has been behind the campaign since May, targeting hotel, conference, and other shared captive-portal networks in several countries. The activity has used captive-portal DNS and HTTP tampering, fake updates, and device-code authentication on real Microsoft sign-in pages to steal Microsoft 365 credentials and session tokens from employees in financial services, legal, healthcare, energy, retail, and technology.
The real risk is that the user does not need to click a suspicious link or visit a bad site. Answering an automatic network check or entering a device code on a genuine Microsoft page is enough to hand over access, which leaves valid accounts and live sessions exposed even after the network issue is fixed.
3 sources covering this story
Midnight Blizzard Targets Travelers via Captive Portals
Russian actor Storm-2945 hijacked hotel captive portals to push fake updates and steal tokens
Russian State APT Linked to Recent Public Wi-Fi Gateway Hacking
Midnight Blizzard has been stealing Microsoft account credentials via compromised Wi-Fi networks at hospitality organizations.
Storm-2945, a sub-cluster of the Russian threat actor Midnight Blizzard, has been observed compromising the sign-in portals of hospitality-related organizations such as hotels since May 2026 in order to deliver malware to travelers and steal credentials in an operation we call CaptiveCrunch.
Part of the PlainSec briefing for 2026-08-04