A hotel Wi-Fi login may look routine, but a new cyber threat can turn that simple step into a serious security risk. Microsoft warns hotel Wi-Fi users could face cyberattack as hackers target guest networks to steal data, spread malware and spy on infected devices.
The threat behind the Wi-Fi connections
Microsoft’s Threat Intelligence calls the campaign CaptiveCrunch. It says the activity has been seen since early May 2026 and is linked to Storm-2945, a sub-cluster of the Russia-based group Midnight Blizzard. The US and UK governments have linked the operation Midnight Blizzard to Russiaโs Foreign Intelligence Service.
Attackers focus on hospitality networks that depend on captive portals. These are pages guests see before getting internet access. Microsoft says the attackers can manipulate DNS and web traffic on affected networks. This lets them send users to systems controlled by the attackers. As reported by CNVC TV-18, the campaign has affected hotels and other hospitality venues worldwide. These webpages may look like normal Windows, browser or security tools, making the attack harder to spot.
They might use fake updates to hide the attack
The danger begins when a user trusts a false prompt. The company says attackers have used fake Windows Update, browser update, Windows Security and other screens. Some pages can also show false Google-style verification checks. Clicking these prompts can install malware on a Windows device. Microsoft has identified CornFlake as the responsible software. It is a remote access trojan that can collect keystrokes, screenshots, files, browser data and session tokens. It can also be used to capture audio and video and give the attacker remote control.
ChocoShell is another tool that targets browser cookies, stored passwords, Microsoft 365 tokens, and Wi-Fi credentials. Microsoft also says there are signs that Android users may be targeted through similar pages that ask them to install an APK file. As reported by Forbes, the campaign is aimed at travelers and can affect corporate users on guest networks. Microsoft has also warned that hospitality network infrastructure should not automatically be treated as trusted.

Microsoft suggests safer ways to connect
Microsoft’s advice is to use private connections, like your phone hotspot, whenever possible. When connecting to hotel Wi-Fi, watch out for warning signs like pop-ups asking you to install browser updates, security patches, certificates, or network tools. The users should avoid public networks when you can, and use cellular data instead. Companies must also carefully review the data shared with hospitality partners on guest networks.
This warning does not mean every hotel network is dangerous. Instead, the risk is that cybercriminals can exploit the login process itself to launch attacks. Seeing a familiar hotel network name does not guarantee that the pages that follow are secure. Because many people use the same device for work, banking, and personal tasks, a single compromise can lead to serious security breaches.
Authorโs Opinion
Hotel Wi-Fi remains useful, but convenience should not replace caution. Travelers do not need to panic. They need better habits. Using mobile data, rejecting surprise downloads and checking prompts carefully can reduce exposure without making travel harder, especially on work-linked devices.
READ MORE: Google faces massive EU blow over Search and Play Store.
ALSO READ: SpaceX clears key Starship milestone with 20 Starlink satellites.
READ NEXT: Apple may lock iPhones over missed lease payments.