Free Wi-Fi has become an essential part of modern travel, whether staying in a hotel, waiting at an airport or attending a conference. However, Microsoft is warning that these convenient internet connections are increasingly being used by cybercriminals to target unsuspecting travelers.
According to Microsoft’s latest threat intelligence report, a cyber operation known as CaptiveCrunch is actively targeting guest Wi-Fi networks around the world. The attackers use fake login and update screens to trick users into downloading malicious software that can give hackers complete access to their devices.
Russian-Linked Cyber Group Behind the Campaign
Microsoft says the campaign is being carried out by Storm-2945, a group linked to Russia that is believed to operate under the well-known cyber espionage organization also referred to as Midnight Blizzard, APT29 or Cozy Bear.
The company believes the group has connections to Russia’s Foreign Intelligence Service and describes the attacks as widespread but carefully targeted. Microsoft first detected the activity in May but only recently made its findings public.
The Trap Appears Before You Even Get Online
Unlike many cyber attacks that directly target a user’s device, CaptiveCrunch focuses on the Wi-Fi login portals commonly used by hotels and other accommodation providers.
When guests attempt to connect to the internet, they may be presented with what appears to be a legitimate software update, security warning or verification request. These screens are designed to look authentic, encouraging users to download files before gaining internet access.
Once the malicious file is installed, attackers can begin collecting sensitive information from the device.
Microsoft notes that this technique is not limited to hotels. Similar attacks could also appear on public Wi-Fi networks in airports, conference centres and other shared internet environments.
Fake Windows and Google Messages Make the Scam Look Real
One reason the campaign is so effective is that the fake messages closely resemble genuine software notifications.
Attackers imitate Windows Update, Microsoft Defender security scans, DirectX updates, Microsoft Visual C++ installers, browser updates, disk optimisation tools and network diagnostic windows. Some victims may even receive messages appearing to come from Google, asking them to verify their identity or complete a security check before accessing online services.
These convincing pop-up windows are designed to lower users’ suspicions and persuade them to install malware voluntarily.
What Information Can Be Stolen?
If the attack succeeds, cybercriminals may gain access to a wide range of personal and business data.
According to Microsoft, attackers could steal saved passwords, browser cookies, documents stored on the device, screenshots, keystrokes, audio recordings and video files. They may also obtain remote control of the infected computer.
In some cases, victims are redirected to fake Microsoft 365 login pages. Entering account credentials on these pages could allow attackers to access emails and files stored in OneDrive.
Microsoft’s Advice for Travelers
Microsoft is encouraging travelers to be especially cautious whenever using free public Wi-Fi networks.
Whenever possible, using a personal mobile hotspot is considered the safest option. Travelers should also avoid downloading software, browser updates, security certificates or other applications that unexpectedly appear while connecting to a guest Wi-Fi network.
The company stresses that any update or verification request shown before internet access should be treated with caution unless its authenticity can be independently confirmed.
Businesses are also encouraged to remind employees about the risks of using public Wi-Fi while travelling and to review the information they share when connecting to hotel internet services.
Stay Alert When Using Public Wi-Fi
Public Wi-Fi remains convenient, but convenience should never replace caution.
As cybercriminals continue developing increasingly sophisticated techniques, even familiar login screens and trusted software messages can be used as part of a phishing attack. Microsoft’s warning serves as a timely reminder that when connecting to hotel Wi-Fi or any shared public network, taking a few extra moments to verify what appears on the screen could prevent a serious cybersecurity incident.