Articles /Trends & Hacks / Health, Insurance, Security

Microsoft Warning: Russian Hackers Are Targeting Travelers Using Hotel Wi-Fi

Travelers "should treat hotel, conference, airport, and other guest wireless networks as untrustworthy," Microsoft warns.

  Published: Aug 05, 2026

  Updated: Aug 05, 2026

Free Wi-Fi sign
dms.spb / Shutterstock

Russian hackers are targeting travelers around the world via hotel Wi-Fi systems, according to a security warning issued by Microsoft.

The threat, dubbed "CaptiveCrunch," uses fraudulent sign-in pages, software updates, and verification prompts, reports Forbes, to steal credentials and install malware on PCs using Microsoft 365.

Microsoft warns that the hackers rely on Wi-Fi networks at "hospitality-related organizations"—i.e., hotels, conference centers, and the like—to "access the accounts of corporate travelers" in particular.

The global campaign appears to have launched in early May, per Microsoft, whose security experts have traced the operation to Storm-2945, part of the Russian espionage network Midnight Blizzard.

The compromised Wi-Fi systems reportedly take users to phony Microsoft 365 log-in pages that look identical to the genuine article, making the scam nearly impossible to spot.

Hacked users can then unwittingly supply the bad guys with access to their accounts through Microsoft's authorization process or even agree to software updates that actually download malware called CornFlake and ChocoShell.

Their adorable names notwithstanding, these programs can, according to Forbes, "record keystrokes, collect files, and capture screenshots," not to mention "hijack a device’s audio and video capabilities for surveillance, and give attackers persistent access" to PCs.

Perhaps you can ask the shady spy listening to you through your computer what's Russian for yikes.

How to protect yourself from hotel Wi-Fi hackers

Microsoft's warning is blunt: "When traveling, users should treat hotel, conference, airport, and other guest wireless networks as untrustworthy."

The company advises travelers to forsake public Wi-Fi whenever possible, and to rely on private connectivity options such as a mobile hotspot or cellular data instead.

At the very least, avoid all updates while on public Wi-Fi—software updates, browser updates, network troubleshooting tools, and so on.

Additionally, Microsoft recommends enabling phishing-resistant authentication and turning off that thing where you can bypass passwords by authenticating an account by device code. (Instructions for doing that for Microsoft software can be found here.)

Although this scheme targets business travelers with PCs, the advice about remaining wary of public Wi-Fi and public charging ports while on the road applies to all of us. If hackers can find a way in, they'll definitely take it.