// Blog / News

Hotel Wi-Fi is stealing Microsoft 365 logins: what CaptiveCrunch means for you

Share

Microsoft's threat researchers have detailed a campaign, nicknamed CaptiveCrunch, that turns the Wi-Fi at hotels and conference venues into a trap for Microsoft 365 accounts. The clever and unsettling part: it does not crack passwords or defeat multi-factor authentication head-on. It tricks travelers into handing over an already-authenticated session, MFA and all. For any small business whose people travel and log into Microsoft 365, it is worth understanding, because the technique behind it is spreading well beyond the group that pioneered it.

What is happening

Microsoft attributes the campaign to Midnight Blizzard, the Russia-linked group also known as APT29 or Cozy Bear. On compromised hotel and conference networks, the attackers control the captive portal (the "sign in to Wi-Fi" page) and the DNS behind it, which lets them redirect guests to fake pages that push malware disguised as "updates," and, more importantly, into a Microsoft 365 login trap. The standout trick is device-code phishing: the attacker starts a real Microsoft sign-in, shows the traveler a short code, and asks them to enter it at Microsoft's genuine sign-in page. When they do, they authenticate the attacker's session, not their own, and because the person completed their normal MFA, the stolen session is fully trusted.

Why MFA did not save them

This is the important lesson. The victim's password and MFA both worked perfectly, they just approved the wrong session. Device-code sign-in is a legitimate Microsoft feature (meant for devices like smart TVs that cannot show a login form), and the attack abuses it rather than breaking it. That is why "we have MFA" is no longer the end of the security conversation, and it is the subject of our companion guide on the sign-in scams that get past MFA.

Are you actually a target?

Honesty matters here: Midnight Blizzard is a nation-state group that mostly chases high-value travelers, diplomats, executives, and the like, not the average small business. You are probably not on APT29's list. But the techniques on display, malicious public Wi-Fi and device-code phishing, are exactly the kind that ordinary criminals copy once they are proven, and device-code phishing in particular is already showing up in everyday attacks. The right response is not panic; it is a few simple habits.

What to do

  • Never enter a code or approve a sign-in you did not personally start. If a page or prompt asks you to authorise a login you did not initiate, stop. This single habit defeats device-code phishing.
  • Treat public Wi-Fi as hostile. Be wary of "update required" prompts on hotel and conference networks, and use a VPN so your traffic is not at the mercy of the local network.
  • Move to phishing-resistant sign-in (passkeys or hardware keys) and tighten Microsoft 365 with Conditional Access, which can restrict the device-code flow entirely.

Sources:The Hacker NewsMalwarebytes

Want your Microsoft 365 locked down so a stolen session cannot happen?

Talk to us

Related