Midnight Blizzard, the Russian state-aligned advanced persistent threat (APT) group, has been stealing Microsoft account credentials via compromised Wi-Fi networks at hospitality organizations, SecurityWeek reported on August 3. The campaign targets hotel and conference venue Wi-Fi gateways and uses stolen credentials for follow-on espionage.
How the Attack Works
The attackers compromise the management interfaces of public Wi-Fi gateways - often poorly secured - and redirect users to lookalike captive portals that capture credentials. Once they have Microsoft account credentials, the attackers pivot to internal email and document systems, focusing on foreign-policy, defense, and NGO targets. The campaign has been active since at least early 2026 and is ongoing.
"Midnight Blizzard has been stealing Microsoft account credentials via compromised Wi-Fi networks at hospitality organizations," SecurityWeek reported.
Who Is Affected
Targets identified so far include government officials, defense industry employees, and NGO staff who have used public Wi-Fi at hotels in Europe, the Middle East, and Asia. Microsoft has been notifying affected organizations. Several governments have issued formal advisories, including the UK's National Cyber Security Centre and Germany's BSI.
What to Do
SecurityWeek and Microsoft recommend that organizations enforce MFA on all Microsoft accounts, especially for users who travel. Travelers should avoid logging into sensitive accounts from public Wi-Fi networks and should use mobile hotspots or trusted VPNs. The Wi-Fi gateway compromise is a reminder that physical access points remain one of the most overlooked attack surfaces.
Comments (0)
Log in or sign up to leave a comment.
No comments yet. Be the first to share your thoughts.