
CaptiveCrunch: Hotel and Conference Wi-Fi Is Now a Microsoft 365 Attack Surface
Storm-2945, a sub-cluster of the Russian state-sponsored threat actor Midnight Blizzard, has been compromising guest Wi-Fi captive portal systems at hotels and conference centers worldwide since May 2026 to steal Microsoft 365 OAuth tokens and install credential-stealing malware on travelers' devices. The campaign bypasses MFA and standard email security. Blocking Device Code Flow and enabling token binding protection via Conditional Access closes the primary exposure.
5-15 Minutes (with Overe)