Imagine checking into a beautiful hotel after a long flight, firing up your laptop, and connecting to the complimentary Wi-Fi — only to unknowingly hand your Microsoft login credentials straight to a group of Russian cybercriminals. That nightmare scenario is no longer hypothetical. It’s happening right now, and travelers around the world need to pay attention.
A sophisticated hacking group known as Midnight Blizzard — widely believed to have ties to Russian intelligence — has been exploiting hotel Wi-Fi networks in a clever and dangerous phishing campaign. Their target? Your Microsoft 365 account. Their method? A technique that security researchers are calling a “captive portal” attack, where users are redirected to a convincing but completely fake Microsoft login page the moment they try to connect to the hotel’s internet.
Here’s how the scam works: when you connect to what appears to be a legitimate hotel Wi-Fi network, you’re often greeted with a sign-in page — this is completely normal and is called a captive portal. But in these attacks, the page you see isn’t from the hotel at all. It’s a carefully crafted fake designed to harvest your Microsoft username and password, or even steal authentication tokens that allow hackers to bypass two-factor security protections entirely.
What makes this particularly alarming is that stealing an authentication token means attackers can access your account without ever needing your password. Even if you have strong credentials and two-factor authentication enabled, your account could still be compromised. Once inside, hackers can access sensitive emails, documents, and corporate data stored in Microsoft 365.
Microsoft has gone public with a warning urging Windows PC users — especially frequent travelers — to exercise extreme caution when using hotel or any public Wi-Fi. Security experts strongly recommend using a trusted VPN service whenever you connect to any network outside your home or office. You should also verify any login page carefully and avoid entering credentials on unfamiliar portals.
Business travelers are especially at risk, since a single compromised account could expose an entire organization’s data. IT departments are being advised to monitor for suspicious login activity and consider enforcing conditional access policies for remote connections.
The bottom line? That free hotel Wi-Fi is starting to look a lot more expensive than you thought. Stay cautious, stay protected, and always think before you connect.
