Skip to main content Scroll Top

Traveling for work? Your hotel Wi-Fi may be spying on you

pexels-brett-sayles-2881232

A Russian state-linked hacking group is quietly hijacking hotel and conference Wi-Fi to plant malware and steal logins from business travelers.

Security Update  |  What you need to know

Since early 2026, Microsoft’s security researchers have been tracking a hacking campaign, nicknamed CaptiveCrunch, that’s targeting one of the most ordinary things a business traveler does: connecting to the Wi-Fi at a hotel, conference center, or airport.

The group behind it has quietly compromised the network equipment behind the “captive portal” pages you see when you join public Wi-Fi — the ones that ask you to click “I agree” or enter a room number before you get online. Once they control that connection point, they can secretly redirect what should be a routine internet check into a trap that either steals your Microsoft account credentials or installs spyware on your laptop, all without you realizing anything unusual happened.

Who’s behind it

Microsoft attributes this activity to Storm-2945, a group linked to Midnight Blizzard — the same Russian intelligence-linked hacking operation (tied to Russia’s SVR) that has spent years targeting governments, diplomats, and corporate travelers for espionage purposes. This isn’t random cybercrime; it’s a deliberate, well-resourced effort to spy on people who travel for work, and Microsoft has found the attackers are using AI to help scale and refine their operation.

How the attack actually works

Most people never see anything alarming. The trap is disguised as things a traveler would expect and trust:

  • A fake “update” prompt: A pop-up claiming your browser, Windows, or a security tool needs an update, with simple copy-and-paste instructions
  • A fake sign-in step: A prompt to enter a short code on Microsoft’s real login page — which secretly hands your logged-in session to the attacker instead of you
  • A fake app install: On some Android devices, an app download disguised as a required verification step

Anyone who follows these prompts can end up with malware that logs their keystrokes, steals saved passwords and browser logins, and even turns on their camera or microphone — or hands their Microsoft 365 account straight to the attacker.

Why executives should care

This campaign specifically targets corporate travelers — the people most likely to be connecting to email, cloud files, and sensitive systems from an airport lounge or hotel room. A single compromised laptop or stolen login can be a foothold into your entire organization’s email and cloud environment. And because the attack happens at the network level, it can look completely legitimate to the person experiencing it.

What to do about it

  • Skip hotel and conference Wi-Fi when you can. Use your phone’s hotspot, a company-issued travel router, or an eSIM data plan instead.
  • Never install an update, driver, or app because a Wi-Fi login page or pop-up told you to. Only update software through your device’s built-in settings.
  • Turn on multifactor authentication (MFA) and, ideally, passkeys for your work accounts — and be suspicious of any prompt asking you to type a code into a Microsoft sign-in page.
  • If you manage IT for your organization, ask your security team whether they’ve restricted the “device code” sign-in method and whether managed laptops can be blocked from joining unapproved Wi-Fi networks.

Bottom line: treat public Wi-Fi like a stranger’s laptop — useful in a pinch, but not somewhere you’d type a password or install software. For the full technical breakdown, detection guidance, and indicators of compromise, see our detailed report for IT and security teams.

0

image sources

  • pexels-brett-sayles-2881232: BRETT SAYLES | All Rights Reserved

Related Posts

Leave a comment

Privacy Preferences
When you visit our website, it may store information through your browser from specific services, usually in form of cookies. Here you can change your privacy preferences. Please note that blocking some types of cookies may impact your experience on our website and the services we offer.