- Microsoft warns about hotel Wi-Fi risks.
- Hackers stealing login details.
- Campaign active through guest networks.
The warning is linked to CaptiveCrunch, a global hacking campaign tied to Storm-2945, a group connected to Russia’s Midnight Blizzard, Microsoft said in a blog post. The campaign has been active since early May, targeting business travelers through compromised hotel Wi-Fi networks to steal login details.
The attackers use hotel and hospitality networks to display fake verification pages, sign-in prompts and software updates that appear to be from legitimate Wi-Fi systems. Some victims are redirected to Microsoft’s device-code login process and tricked into entering a code provided by the attackers. Once approved, the attackers can access accounts using valid login tokens without needing to steal passwords or bypass multi-factor authentication directly.
Microsoft also found that the attacks can install malware on devices, creating a bigger risk than just stolen login details. The Windows remote-access trojan, called CornFlake, can steal account information, track keystrokes, collect files, take screenshots and monitor device audio and video.
A separate July report from ReliaQuest found attackers targeting Microsoft 365 users through compromised Wi-Fi networks. The attackers redirected guests to fake sign-in pages without sending phishing emails or gaining access to devices first. It found compromised Wi-Fi gateways in several U.S. cities and in countries including India and Saudi Arabia, mainly at hotels and hospitality organizations.
Microsoft advised travelers to use mobile data when possible and avoid using hotel Wi-Fi for important activities. Microsoft worked with Anthropic and OpenAI during the investigation and found that attackers used AI tools to support the campaign.
Microsoft warned last year of a phishing campaign targeting hospitality organizations through fake Booking.com emails to deliver malware and steal credentials.







