Russian Hackers Exploit Public WiFi to Steal Microsoft 365 Credentials
A Russian government-backed hacking group has been using compromised public WiFi networks to steal Microsoft 365 account access credentials, according to an alert from the tech giant.
The campaign, dubbed CaptiveCrunch, began in May and targeted professionals in sectors such as financial services, consulting, law firms, healthcare, energy, and retail.
The attackers compromised devices managing public WiFi networks and altered their configuration to redirect user traffic to servers under their control, intercepting Microsoft 365 access credentials from employees connecting while traveling for work reasons.