Briev
Live
Technology

Microsoft alerts travelers to hotel Wi-Fi hijacks that can spy on devices and steal credentials

Microsoft’s Threat Intelligence team warns that a campaign called CaptiveCrunch is compromising hotel guest Wi-Fi to deliver fake updates and login screens that can capture audio, video and passwords.

Microsoft’s Threat Intelligence division has identified a worldwide campaign named CaptiveCrunch that infiltrates guest Wi-Fi networks at hotels and other hospitality venues. The activity, attributed to Storm-2945—a sub-cluster of the Russian hacking outfit Midnight Blizzard (also known as APT29 or Cozy Bear)—has been observed since at least May across multiple countries. By compromising the underlying Wi-Fi infrastructure, the attackers redirect users to counterfeit captive-portal pages that mimic legitimate system updates or security checks, tricking victims into installing malware or surrendering login details.

Once installed, the malicious code can capture keystrokes, record audio and video, take screenshots, and harvest browser cookies and passwords, allowing access to corporate Microsoft 365 accounts and broader networks. ReliaQuest has confirmed the scheme’s presence not only in hotels but also in conference centers and similar shared venues, targeting corporate travelers. Microsoft recommends using personal cellular hotspots, ignoring unsolicited pop-ups, and limiting the data shared on public networks to mitigate the risk.

Why it matters

Travelers and businesses risk credential theft and device surveillance when using compromised hotel Wi-Fi.

In this story

CaptiveCrunchhotel Wi-Ficyberattackfake captive portalcredential theftdevice surveillancecellular hotspotMidnight BlizzardStorm-2945