New Delhi, Aug. 4 -- WASHINGTON - Sometime between February and May of this year, while business travelers were checking into hotels and clicking through the usual captive portal login screens, Storm-2945 was waiting. The group, a subdivision of Midnight Blizzard that Microsoft links to Russia's Foreign Intelligence Service, had compromised the guest Wi-Fi networks of hotels, conference centers, and other hospitality venues. Every user who connected was a potential target.

Microsoft disclosed the operation on Monday, naming it CaptiveCrunch. The company described the threat as "widespread" but offered no count of affected users, and declined to explain when contacted by ABC News why it waited three months after detecting the campaign in ...