Hotel Wi-Fi Hacking Campaign Targets Travelers with Stolen Login Details
Microsoft has warned businesses about a global hacking campaign targeting travelers through compromised hotel Wi-Fi networks. The attackers, linked to Storm-2945 and Russia's Midnight Blizzard group, are using fake verification pages, sign-in prompts, and software updates to steal login details.
The campaign, called CaptiveCrunch, has been active since early May and is using AI tools to support the attacks. Once a victim enters their login credentials, the attackers can access accounts without needing passwords or bypassing multi-factor authentication.
Microsoft also found that the attacks can install malware on devices, which can steal account information, track keystrokes, collect files, take screenshots, and monitor device audio and video.
The company advised travelers to use mobile data when possible and avoid using hotel Wi-Fi for important activities. Microsoft worked with Anthropic and OpenAI during the investigation and warned that attackers are targeting hospitality organizations through compromised Wi-Fi networks in several U.S. cities and countries including India and Saudi Arabia.