Do not use free hotel Wi-Fi, Microsoft warns travellers

Do not use free hotel Wi-Fi, Microsoft warns travellers

Do you use free hotel Wi-Fi while travelling? Microsoft warns that you should not trust it if you want to protect your sensitive information.Microsoft warns that Russian hacking group is targeting free hotel and hospitality Wi-Fi networksDo you frequently use free hotel Wi-Fi while travelling? It’s convenient and can help you get quick access to the internet if your mobile data is not working. But as helpful as it is, you should probably not trust it. Microsoft warns that using free Wi-Fi could mean walking into a malware trap without even realising it. The company says hackers are targeting hotel and other guest Wi-Fi networks worldwide to steal user’s passwords, infect malware and potentially access sensitive data. Microsoft Threat Intelligence has found a hacking campaign called CaptiveCrunch, which has been targeting hotel and other guest Wi-Fi networks worldwide since early May 2026. The activity has been linked to Storm-2945, a sub-group of Midnight Blizzard, the Russia-linked hacking group also known as APT29 or Cozy Bear. According to the company these hackers appear to be particularly interested in business travellers and their corporate accounts to steal their data. How hackers are targeting hotel Wi-FiMicrosoft says the hackers of Storm-2945 have been manipulating DNS and HTTP traffic on networks that use captive portals. These are pages you usually see when you connect to hotel Wi-Fi and are asked to log in or accept the terms. So by manipulating these pages, hackers can redirect travellers to websites and infrastructure controlled by them. Microsoft says it has found compromised Wi-Fi networks at hospitality organisations and other shared venues in several countries.Once connected to free Wi-Fi and landing into the fake sites, travellers may see pop-ups asking them to install an update or fix a problem. However this update can then help hackers control users’s devices and steal their sensitive data. Microsoft says hackers are using fake prompts that look like Windows or browser updates. Some pages also pretend to be Google security checks and ask users to verify their identity. Android users may even be asked to install an APK file. Microsoft says Storm-2945 has also used device-code phishing, another trick designed to steal access to accounts. In this case, victims may be redirected to a legitimate Microsoft sign-in page and asked to enter a code. The page may look genuine, but entering the code could allow attackers to gain access to the victim’s session. In short, hackers can record a user’s device screen, capture keystrokes, steal credentials and even record audio and video. Microsoft’s warning is particularly concerning because the attack does not necessarily depend on a traveller connecting to a suspicious network. “The campaign involves traffic manipulation attacks, follow-on phishing and malware delivery,” reads the official blog post. What can hackers steal? Microsoft has identified two types of malware used in the campaign: CornFlake and ChocoShell.CornFlake can steal files, passwords and other login details. It can also take screenshots and record audio and video from an infected device. The other one which is ChocoShell can steal browser cookies, saved passwords, Microsoft 365 login details and Wi-Fi passwords.According to Microsoft, hackers could use these tools to spy on a device and steal sensitive information, including work-related data.How to stay safe on hotel Wi-FiTo stay safe from these hacking attempts, Microsoft advises travellers to treat hotel, conference, airport and other guest Wi-Fi networks as untrusted. Where possible, travellers should use a mobile hotspot, eSIM or another private connection instead.Most importantly, the company asks travellers not to download software updates, certificates, browser updates or security tools just because a Wi-Fi portal asks them to. If you need an update, download it through the device’s operating system or the software’s official update system.- EndsPublished By: Divya BhatiPublished On: Aug 10, 2026 13:39 IST

Original Source

Read the full article at Indiatoday →

KhanList aggregates and links to publicly available news content. We do not host full articles from third-party sources. Always verify important information with original sources.