CaptiveCrunch: Midnight Blizzard Weaponizes Hotel Wi-Fi Captive Portals to Steal Microsoft 365 Credentials

Source: Zscaler.com· Jithin Prajeev Nair (Director, Threat Research)· August 11, 2026
CaptiveCrunch: Midnight Blizzard Weaponizes Hotel Wi-Fi Captive Portals to Steal Microsoft 365 Credentials
SynaBot summary

A new cyber threat, dubbed CaptiveCrunch, is exploiting hotel Wi-Fi login pages to steal Microsoft 365 credentials. This sophisticated attack, linked to the group Midnight Blizzard, targets travelers and business users, highlighting emerging risks in public network security.

Key takeaways

  • Hotel Wi-Fi login pages are being weaponized for credential theft.
  • Microsoft 365 accounts are the primary target of this campaign.
  • The attack uses advanced techniques to evade detection.
  • Users should exercise extreme caution on public networks.

Why it matters

This campaign demonstrates a novel attack vector targeting remote workers. Users relying on public Wi-Fi for business should be aware that even seemingly legitimate login pages can be compromised, putting sensitive work data at risk.

This story was reported by Zscaler.com. Read the full original article:
Read on Zscaler.com

More in Enterprise & Adoption

View all