What the Tech: Microsoft Warning
Microsoft said hackers compromised hotel networks and used fake Google checks and Windows updates to steal passwords and other credentials.
- Microsoft reports that attackers compromised hotel networks in a campaign detected in early May, redirecting travelers to fake websites and deceptive pop-up messages linked to a Russian hacking group.
- Attackers display false Windows updates and Google-branded security checks to trick guests into clicking malicious messages. This allows hackers to access computers, collect files, record keystrokes, and potentially activate microphone or camera functions.
- Microsoft advises travelers to avoid software updates and unexpected pop-ups while on public Wi-Fi. If a suspicious message appears, users should close the browser immediately and not click any buttons inside warnings.
- Travelers should disconnect from the network if a pop-up appears and "Select Forget this network" in their device settings. Forgetting the network prevents automatic reconnection to the compromised connection.
- Consider using a portable travel router to create a private network separating devices from hotel internet. Personal cellular hotspots offer another option, with prices starting at around $50.
14 Articles
14 Articles
Microsoft warns of major Russian hacking campaign targeting public hotel Wi-Fi networks worldwide
Microsoft announced it had identified a large-scale campaign by Russian hackers targeting the public Wi-Fi infrastructure of hotels, conference centers, and other venues worldwide.
Microsoft is warning travelers about new cyberattacks that hotel guests may face when connecting to free Wi-Fi, ABC News reports.
Microsoft alerts a Russian campaign that manipulates hotel Wi-Fi access portals to steal sessions and install malware
Russian-backed hackers have taken control of public Wi-Fi networks in hotels and conference centres around the world, using artificial intelligence (AI) to support a large part of the operation.
Midnight Blizzard targets hotel Wi-Fi in CaptiveCrunch
Microsoft Threat Intelligence has disclosed a campaign called CaptiveCrunch, attributing it to a cluster it tracks as Storm-2945. Since early May 2026, the group has manipulated DNS and HTTP traffic on the Wi-Fi networks that hotels and conference venues offer guests through captive portal sign-in pages, redirecting travelers to phishing pages and malware. Microsoft says it identified "widespread compromise of Wi-Fi networks at hospitality-relat…
Jim Rossman: Hotspot mode vs. public Wi-Fi
We’ve all been there. You’re out at the mall or shopping at the grocery store or at a hotel and your phone offers to join an open Wi-Fi network. Should you do it? Is public Wi-Fi safe to use? Yes…and no. Public Wi-Fi is safe enough for tasks...
Coverage Details
Bias Distribution
- 57% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium











