|
|
| September 8, 2026 |
|
Microsoft gives urgent warning about Wi-Fi risk in hotels
Microsoft is warning travelers to be particularly careful when connecting to hotel Wi-Fi after uncovering a cyberespionage campaign that hijacks public internet connections to steal passwords, business data and other sensitive information.
In a new report, the company said a hacking group known as Storm-2945 has been compromising Wi-Fi networks used by hotels, conference centers and other venues that rely on captive portals—the web pages people use to log in before accessing free internet. Microsoft said the Russia-linked attacks have been observed since early May 2026 and appear to be aimed primarily at corporate travelers. The company warned that people should assume public Wi-Fi networks cannot always be trusted and should avoid downloading software or entering sensitive information while connected. ‘CaptiveCrunch’ According to Microsoft, the campaign—which it has named “CaptiveCrunch”—manipulates internet traffic after a traveler joins a hotel’s Wi-Fi network. Instead of sending users to legitimate websites, attackers can redirect them to fake Microsoft login pages or bogus software update screens designed to steal credentials or infect devices with malware—a concerning possibility Newsweek has previously covered. The company said some victims are tricked into completing a legitimate Microsoft sign-in process using an attacker-controlled device code. Although the sign-in page is genuine, entering the code gives hackers access to the victim’s Microsoft account rather than logging them into a service they intended to use. Microsoft also found the hackers delivering malware disguised as browser updates, Windows updates or network repair tools. The malicious software can record keystrokes, steal saved passwords, capture screenshots, access microphones and webcams, monitor USB drives and remotely control infected computers. The company said it has also seen signs that Android users are being targeted through fake prompts encouraging them to install malicious app files. AI involvement Microsoft attributed the campaign to Storm-2945, which it believes is a sub-group of Midnight Blizzard, a hacking organization linked by U.S. and U.K. authorities to Russia’s Foreign Intelligence Service, or SVR. Midnight Blizzard has long been associated with cyberespionage operations targeting governments, diplomatic organizations, technology companies and other high-value organizations in the United States and Europe. The report also said Storm-2945 has been using artificial intelligence to support a significant portion of its operations, including phishing campaigns and malware development. Microsoft thanked Anthropic and OpenAI for assisting with the investigation. What to do To reduce the risk of attack, Microsoft recommends travelers use mobile hotspots, cellular data or other private internet connections instead of public hotel Wi-Fi whenever possible. It also advises users not to install software updates, browser updates or security tools prompted by hotel login pages or unexpected pop-up windows. The company said software updates should only be installed through trusted operating system update services. Organizations are also encouraged to use phishing-resistant authentication methods such as passkeys and multifactor authentication, restrict the use of device-code sign-ins where possible, and educate employees to recognize fake update prompts and other social engineering tactics. “Users should treat hotel, conference, airport, and other guest wireless networks as untrustworthy,” Microsoft said, adding that organizations should also avoid using corporate credentials on hotel Wi-Fi registration pages whenever possible. (Source: Newsweek) Story Date: August 10, 2026
|