Skip to content
live markets
S&P 5007,738.32▲ 3.41%NASDAQ26,433.60▲ 2.33%DOW54,492.86▲ 3.01%GOLD4,325.00▲ 4.09%WTI75.26▲ 9.79%BRENT79.36▲ 10.24%EUR/USD1.1559▲ 1.19%USD/JPY157.68▼ 2.34%DXY99.65▼ 1.19%BTC$64,717▲ 1.10%ETH$1,917▲ 2.30%SOL$74.55▲ 0.90%TOTAL CRYPTO$2.3T▲ 0.75%
pulseofnations.
Wed, Aug 5 2026 — 18:45 UTC telegram ↗ bluesky ↗ Join the wire

Microsoft Warns Hackers Targeting Hotel Wi-Fi Networks

Microsoft disclosed that Russian state-linked hackers are exploiting hotel Wi-Fi captive portals to deliver malware and steal credentials from traveling business users.

Microsoft issued a warning on Monday that a Russian state-sponsored hacking group is actively targeting hotel Wi-Fi networks worldwide to infect the devices of traveling business executives and government officials with malware.

The campaign, dubbed CaptiveCrunch by Microsoft’s Threat Intelligence team, involves the notorious Midnight Blizzard group (also known as APT29 or Cozy Bear) setting up rogue captive portal pages at hotels to intercept and compromise guest devices. The attackers inject malicious code into legitimate hotel Wi-Fi login pages, turning them into credential-harvesting tools.

When travelers connect to hotel Wi-Fi and attempt to access the internet, they are redirected to what appears to be a standard hotel portal page. However, the modified page silently deploys malware designed to capture login credentials, session tokens, and other sensitive data from the visitor’s device. Microsoft said the attacks specifically target Outlook email accounts and VPN credentials.

The technique is particularly effective because business travelers frequently connect to untrusted hotel networks and are less likely to notice subtle changes to captive portal pages. Once credentials are harvested, Midnight Blizzard can pivot into corporate networks, accessing email archives, sensitive documents, and internal systems.

Microsoft recommended that travelers use VPN connections before joining any hotel Wi-Fi network, enable multi-factor authentication on all accounts, and avoid entering credentials on captive portal pages when possible. The company also advised organizations to implement conditional access policies that flag logins from unusual locations.

The disclosure comes amid a broader increase in state-sponsored cyber operations targeting the hospitality sector. Security researchers have noted that hotels are attractive targets because they host high-value individuals, including executives, diplomats, and government officials, who carry sensitive information on their personal and work devices.

Midnight Blizzard has been linked to Russia’s SVR foreign intelligence service and has been responsible for several high-profile cyber espionage campaigns, including the 2020 SolarWinds supply chain attack. The group has demonstrated consistent sophistication in adapting its techniques to target Windows-based environments and cloud infrastructure.

Sources: Microsoft Security Blog, SecurityWeek, ABC News

React to this dispatch
Share this dispatch Telegram X WhatsApp Report an error

discussion

Join the discussion

Your email address will not be published. Required fields are marked *

Next dispatch Fitbit Data Now Syncs Directly to Apple Health App Read →