Microsoft warns travellers: Hotel Wi-Fi can expose passwords, audio and video
Microsoft has warned travelers about a cyberattack campaign called 'CaptiveCrunch' that targets hotel and public Wi-Fi networks. The campaign, linked to a Russian-affiliated group, uses fake captive portals to trick users into downloading malware or revealing credentials.
Why it matters
This highlights a significant security risk for corporate travelers and the general public using shared network infrastructure in hospitality settings.
Microsoft’s Threat Intelligence team has issued a warning to travelers following a series of sophisticated cyberattacks targeting guest Wi-Fi networks at hotels and hospitality venues worldwide. The internet hijacking campaign, dubbed ‘CaptiveCrunch’, has been active since at least May and is attributed to Storm-2945, a sub-cluster claimed to be of the Russian hacking group Midnight Blizzard (also known as APT29 or Cozy Bear).According to Microsoft, the hacker group is executing "widespread but targeted" traffic manipulation attacks through Public guest networks and captive portal screens – the web pages that appear when users attempt to log onto hotel Wi-Fi or those at public places like airports, tourists venues and more. "To date, Microsoft has identified widespread compromise of Wi-Fi networks at hospitality-related organizations and other networks serviced by captive portal equipment in several countries.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in