Hackers target travelers through hotel and public Wi‑Fi networks
microsoft.com Aug 3, 2026

Hackers target travelers through hotel and public Wi‑Fi networks

AI-summarised brief · reviewed before publication

Microsoft Threat Intelligence has identified CaptiveCrunch, a campaign by Storm-2945, a sub-cluster of Midnight Blizzard, targeting travelers via compromised hotel and public Wi-Fi networks. Since early May 2026, the group has manipulated DNS and HTTP traffic on captive portals to redirect users to phishing sites mimicking Microsoft services. This adversary-in-the-middle operation abuses device code authentication flows in Microsoft Entra ID to steal credentials. Additionally, Storm-2945 delivers malware, including Windows remote access trojans and Android APKs, disguised as system updates. The attackers leverage AI to support these operations and exploit commonalities in captive portal management systems, suggesting widespread ecosystem access rather than isolated venue compromises. ReliaQuest confirms the activity affects hotels, conference centers, and shared venues globally. Microsoft shares these findings to help organizations detect and mitigate the threat, emphasizing the risk to corporate travelers. The investigation highlights Storm-2945’s technical overlap with Midnight Blizzard and their sophisticated use of ClickFix techniques to trick users into executing malicious payloads.

💡 Why It Matters

  • · The compromise of shared captive portal infrastructure allows attackers to intercept traffic from countless travelers simultaneously, bypassing traditional perimeter defenses.
  • · This systemic vulnerability exposes corporate data through a single point of failure in the hospitality ecosystem.