Microsoft warns travelers of attacks reaching Microsoft 365 data

Microsoft has described CaptiveCrunch, an ongoing campaign that uses compromised captive portals to redirect travellers to phishing infrastructure and malware. Microsoft says the activity has included device-code and OAuth phishing that leads to Entra device registration and subsequent Microsoft 365 data collection.
SharePoint and Teams administrators spend much of their time making collaboration easy to reach. That access can become a liability when a compromised device or token reaches the same Microsoft 365 tenant through a convincing travel-network prompt. The source does not make every SharePoint or Teams admin the incident owner. It does give them a current reason to coordinate with security and Entra owners on the practical controls and user guidance around travel, device registration and suspicious sign-in prompts.
Analysis
Send this advisory to the team that owns Entra and travel-security communications. Confirm that staff know not to approve unexpected device-code or sign-in prompts on hotel and airport networks, and that the incident route is clear.
Source note
Pulse published by Collab365 Spaces, reviewed by Helen Jones on . Cite as "Microsoft warns travelers of attacks that reach Microsoft 365 data", Collab365 Spaces.