Hackers are compromising Wi-Fi gateways at hotels and conference centers and changing their internet settings so travelers are sent to fake Microsoft 365 login pages. ReliaQuest says the campaign has been active since at least June 2026 and has affected organizations across finance, legal, healthcare, energy, retail, and professional services in the U.S., India, Saudi Arabia, and elsewhere. The attackers altered DNS settings, used fake domains including m365-owa[.]com and owa-ms365[.]com, and in some cases abused Microsoft device-code sign-in flows to obtain legitimate OAuth session tokens that can bypass multi-factor authentication.
Why it matters: Traveling employees and conference attendees can have work accounts stolen just by using a compromised venue Wi-Fi network. Organizations should push always-on full-tunnel VPN use, disable device-code authentication where unnecessary, review Microsoft Entra ID logs, and treat hotel or event Wi-Fi as hostile until proven otherwise.
Bruce Schneier
2026.08.17
94% relevant
This is the same underlying campaign: attackers compromise public Wi-Fi devices at hotels and conference centers, change DNS settings, and redirect users to fake login pages to steal credentials.
Bill Toulas
2026.08.04
97% relevant
This is the same underlying Wi-Fi captive-portal attack campaign, but adds Microsoft attribution to Midnight Blizzard/APT29, the campaign name CaptiveCrunch, the Storm-2945 cluster, and new technical details on the CornFlake and ChocoShell malware plus Android targeting and the FruitStone management panel.
2026.08.03
95% relevant
This is a direct update on the same hotel and conference Wi-Fi hijacking campaign, adding Microsoft's attribution to Storm-2945/Midnight Blizzard, naming the CornFlake and ChocoShell malware families, and clarifying that captive-portal redirection and fake update pages are being used against travelers.
Ionut Arghire
2026.08.03
96% relevant
This source strongly updates the same underlying event by attributing the public Wi-Fi gateway and captive portal credential-theft campaign to Microsoft-tracked Storm-2945, a subgroup of Midnight Blizzard, and by adding details on the CaptiveCrunch operation, associated malware families (CornFlake, ChocoShell, FruitStone), broader hospitality-network compromise, and device-code phishing integrated into the same attack chain.
Bill Toulas
2026.07.24
100% relevant
This article establishes a distinct ongoing campaign centered on compromised hotel and conference Wi-Fi gateways redirecting users to fake Microsoft 365 authentication flows.
← Back to all stories