Midnight Blizzard Hijacks Hotel Wi‑Fi to Phish Guests

IT News Australia · High sophistication
Last updated August 4, 2026

Microsoft says a Russia-linked group compromised hotel and conference guest Wi‑Fi sign-in systems to redirect travelers to phishing pages and fake “update” prompts. The goal was to steal credentials (including Microsoft 365) and push malware when devices automatically check connectivity after joining a new network.

Key findings

  • Attackers compromised captive portal equipment used for hotel/conference guest Wi‑Fi sign-in, active since early May 2026.
  • Microsoft attributes the campaign (“CaptiveCrunch”) to Storm-2945, a sub-cluster of Russia-linked Midnight Blizzard (NOBELIUM/SVR attribution cited).
  • From compromised network gear, victims were redirected to phishing infrastructure and shown malware disguised as browser/OS updates during automated connectivity checks after joining Wi‑Fi.
  • The campaign included Microsoft 365 device code/OAuth phishing where victims are tricked into entering a code on a genuine Microsoft page, authenticating the attacker’s session.
  • ReliaQuest observed compromised captive portals across multiple US cities, plus India and Saudi Arabia; impacted traffic came from many industries, suggesting traveling employees broadly were targeted.
  • Some cases also attempted to abuse WPAD to expand redirection beyond authentication traffic.
  • Microsoft recommends blocking Entra ID device code flow where not needed and using MFA/passkeys; both Microsoft and ReliaQuest advise treating guest Wi‑Fi as untrustworthy and using full-tunnel VPN or managed travel routers/hotspots.

Who’s being targeted

  • Commonly targeted roles: All traveling employees, Executives, Sales, Consultants/Professional services staff, Finance, Legal, IT/Identity & Access Management.
  • Affected industries: Hospitality (hotels, conference centres), Financial services, Professional services, Legal, Health care, Energy, Retail.
  • Attack channels: website.
  • Impersonated: Hotel or conference guest Wi‑Fi captive portal, Browser or operating system update prompt shown during Wi‑Fi connectivity checks, Microsoft device code authentication flow (legitimate Microsoft page, abused by attackers).

Awareness takeaways

  • Treat hotel and conference guest Wi‑Fi as untrusted; avoid entering sensitive credentials when first joining a public network.
  • Be suspicious of “update required” prompts that appear right after connecting to public Wi‑Fi; only update through official OS/app channels.
  • If you see a Microsoft device-code sign-in you didn’t initiate, stop and report it, device codes can be used to sign attackers in.
  • Use safer connectivity options for travel, like a full-tunnel VPN or a managed hotspot/travel router, instead of relying on venue Wi‑Fi.

Red flags to watch for

  • Captive portal behaves unexpectedly (extra redirects or unusual pages)
  • Sign-in page requests credentials unrelated to Wi‑Fi access
  • You are prompted again after you already connected
  • Update prompts appear immediately after connecting to public Wi‑Fi
  • Updates are offered outside normal app store/OS update mechanisms
  • The prompt appears in a captive portal or web page instead of system settings
  • Unexpected request to use device code sign-in while joining Wi‑Fi
  • A code is provided by a third-party page before you reach Microsoft
  • Sign-in appears unrelated to any work device enrollment you initiated
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You connect to hotel Wi‑Fi, the splash page looks normal… but it’s actually Midnight Blizzard’s playground. Microsoft calls this campaign CaptiveCrunch. Storm‑2945 hacked hotel and conference captive portals so guest Wi‑Fi silently redirects you to phishing pages and fake browser or OS “updates.” Red flags: the portal keeps redirecting, asks for Microsoft 365 or other account logins, or you see a random Microsoft device‑code box you never started. Then a browser “update required” pops up the moment you join Wi‑Fi. When you travel, treat guest Wi‑Fi as hostile: if any sign‑in or update looks off, stop using that Wi‑Fi and switch to your corporate VPN hotspot or managed travel router.

Similar attacks

Russian Hackers Hijack Hotel Wi‑Fi Login Pages

Russian Hackers Hijack Hotel Wi‑Fi Login Pages

Microsoft says a Russia-linked group compromised hotel and venue Wi‑Fi captive portals to show convincing fake prompts during the normal “connect to Wi‑Fi” flow. The prompts try to trick travelers into installing malware, running commands, or approving a Microsoft sign-in that grants the attacker…

August 4, 2026
Hackers Hijack Hotel Wi‑Fi to Steal M365 Logins

Hackers Hijack Hotel Wi‑Fi to Steal M365 Logins

Microsoft reports a Russian state-backed operation that compromises hotel and conference Wi‑Fi “captive portals” to redirect travelers to fake Microsoft 365 sign-in pages or fake update prompts that install malware. One method abuses Microsoft’s device-code login flow so victims unknowingly approve…

August 4, 2026
Hackers Hijack Hotel Wi‑Fi to Push Fake Updates

Hackers Hijack Hotel Wi‑Fi to Push Fake Updates

Microsoft says attackers hijacked captive portals on hotel and conference Wi‑Fi to redirect travelers through attacker infrastructure. Victims were shown fake browser/OS update prompts (and sometimes “paste-and-run” instructions) to install malware, and later were pushed into Microsoft device-code…

August 3, 2026
Hackers Hijack Hotel Wi‑Fi to Steal M365 Logins

Hackers Hijack Hotel Wi‑Fi to Steal M365 Logins

Microsoft and ReliaQuest report a real campaign where Russian-linked hackers compromised hotel Wi‑Fi networks and redirected travelers to fake Microsoft login pages or fake update screens. The goal was to steal Microsoft 365 credentials and/or trick victims into installing espionage malware,…

August 3, 2026
Hijacked Hotel Wi‑Fi Serves Fake Updates

Hijacked Hotel Wi‑Fi Serves Fake Updates

Attackers hijacked hotel/captive-portal Wi‑Fi infrastructure to redirect travelers to fake browser or operating system update pages and trick them into installing spyware. The operation (tracked as CaptiveCrunch) used DNS manipulation and user prompts (including “ClickFix” instructions) to get…

August 1, 2026
Hotel Wi‑Fi Lures Steal M365 Logins, Drop Malware

Hotel Wi‑Fi Lures Steal M365 Logins, Drop Malware

Microsoft says Russian-linked threat actors compromised hotel and conference guest Wi‑Fi “captive portal” networks to redirect travelers to fake Microsoft 365 sign-in pages, device-code phishing, or fake update pages. The goal was to steal cloud credentials (including Entra ID device codes) and…

August 4, 2026