Microsoft has formally attributed a global campaign of hotel Wi-Fi attacks to Midnight Blizzard, the Russian state-linked threat actor also known as APT29. The attribution confirms what security researchers had suspected for weeks: hospitality networks used by business travelers, diplomats, and executives have become a deliberate entry point for attackers seeking access to Microsoft 365 accounts.

The campaign has already been documented in Microsoft's own advisories and covered in earlier reporting on how Russian hackers hijack hotel Wi-Fi to steal M365 tokens. What's new here is the formal link to Midnight Blizzard, a group with a long track record of espionage-driven intrusions against government agencies, think tanks, and corporate targets. Tying the activity to a known, well-resourced actor changes how seriously organizations should treat the risk, and it raises fresh questions about how much trust anyone can place in a public network.

How the Hotel Wi-Fi Attacks Work

At the center of this campaign is a straightforward but effective idea: instead of attacking a target's home or office network, compromise the shared Wi-Fi infrastructure that travelers connect to without a second thought. Hotel and conference networks are typically managed by third parties, rarely monitored closely, and used by exactly the kind of high-value targets, executives, officials, journalists, that a state-linked group like Midnight Blizzard wants to reach.

According to Microsoft's findings, the attackers used custom-built malware to intercept sessions and push travelers toward fraudulent Microsoft 365 login flows, ultimately harvesting authentication tokens and credentials. Because Microsoft 365 sits at the center of email, file storage, and single sign-on for so many organizations, a single compromised account can open the door to a much wider set of internal systems. This is the same core mechanic described in reporting on how Microsoft warns of Russian hackers on hotel Wi-Fi networks, and it underscores why the hospitality sector has become such an attractive staging ground for credential theft.

Why Attribution to APT29 Matters

Security teams often distinguish between opportunistic cybercrime and targeted, state-sponsored espionage, and the distinction shapes how a defense is built. Midnight Blizzard, also tracked as APT29 and widely believed to operate with backing from Russian intelligence, is not a smash-and-grab operation. Historically, this group prioritizes long-term access, quiet persistence, and intelligence value over quick financial payouts.

That context matters for anyone weighing whether hotel Wi-Fi attacks are relevant to them. If your organization handles sensitive communications, works with government contracts, operates in defense, policy, energy, or journalism, or simply has executives who travel internationally, this campaign is a direct reminder that public and semi-public networks are an active battleground, not a passive convenience. The broader pattern of attacks targeting travelers alongside other current threats was also flagged in a recent roundup covering hotel Wi-Fi attacks and a Zimbra zero-day, which noted how frequently travel-related infrastructure now shows up alongside other major vulnerabilities in weekly threat summaries.

What This Means For You

If you travel for work and connect to hotel or conference Wi-Fi, this campaign is a signal to change habits now rather than after an incident. The risk isn't limited to obviously suspicious networks; the entire premise of this attack is that ordinary, expected hotel Wi-Fi can be quietly compromised without visible warning signs. Microsoft's own guidance, echoed across multiple reports on this campaign, is to treat hotel and conference Wi-Fi as untrusted by default and to favor private cellular data or managed, organization-approved connections when handling anything tied to work accounts.

For IT and security teams, this is also a good moment to review how Microsoft 365 authentication is protected. Multi-factor authentication helps, but token theft techniques can sometimes bypass MFA if session tokens themselves are captured. Conditional access policies, device compliance checks, and monitoring for logins from unexpected locations or devices add meaningful friction against this kind of attack. The same lesson, that credential and portal-based attacks scale quickly across large user populations, has shown up in other recent incidents, including the exposure detailed in reporting on the Hartford HUSKY Medicaid breach, where portal access itself became the point of failure.

Actionable Takeaways

Treat hotel, airport, and conference Wi-Fi as untrusted networks, regardless of how official the login portal looks. When possible, use a personal or company-issued mobile hotspot instead of shared Wi-Fi for anything involving work accounts. Make sure multi-factor authentication is enabled on all Microsoft 365 accounts, and ask your IT team whether conditional access policies are in place to flag logins from unfamiliar devices or locations. Finally, if you or your organization has reason to believe you're a higher-value target, whether due to your industry, role, or access to sensitive data, build travel security awareness into routine training rather than treating it as an afterthought. The Midnight Blizzard hotel Wi-Fi campaign is a clear demonstration that the weakest link in a security chain isn't always inside the office network; sometimes it's the Wi-Fi password printed on a hotel room key card.