Microsoft Warns Russian State Hackers Compromise Hotel Wi-Fi Portals to Target Travelers

Rather than creating fake wireless networks or phishing pages that users might recognize as suspicious, the attackers exploit trusted infrastructure already operated by hotels and other travel venues, according to Microsoft’s report.
Published: 8/3/2026, 4:23:18 PM EDT
Microsoft Warns Russian State Hackers Compromise Hotel Wi-Fi Portals to Target Travelers
A person wearing a balaclava is silhouetted as he poses with a laptop in Zenica, Bosnia-Herzegovina, on Oct. 29, 2014. (Dado Ruvic/Reuters)

Microsoft has announced that a Russian state-sponsored cyber espionage group has launched a sophisticated campaign that compromises legitimate hotel and travel Wi-Fi login systems to steal credentials and deploy malware against travelers worldwide.

In a report published July 31, Microsoft detailed a campaign it calls CaptiveCrunch, saying that Storm-2945, a subgroup of the Russian threat actor Midnight Blizzard, is responsible for the hacking activity.
“This threat actor is known to primarily target governments, diplomatic entities, non-governmental organizations (NGOs), and information technology (IT) service providers, primarily in the US and Europe,” Microsoft said in a statement. “Midnight Blizzard is consistent and persistent in their operational targeting, and their objectives rarely change. Their focus is to collect intelligence through longstanding and dedicated espionage in support of Russian foreign policy interests,” the company added.

U.S. intelligence and law-enforcement agencies under the Trump administration have previously sounded the alarm over such cyber and influence threats and continue to identify Russia as a source.

Rather than creating fake wireless networks or phishing pages that users might recognize as suspicious, the attackers exploit trusted infrastructure already operated by hotels and other travel venues, according to Microsoft’s report.

Microsoft’s researchers say the attackers are compromising the legitimate captive portals used by hotels and other hospitality providers, unlike traditional attacks that rely on fake Wi-Fi hotspots or counterfeit login pages. As a result, travelers may unknowingly connect to authentic Wi-Fi networks while having their traffic manipulated behind the scenes.

According to Microsoft, the Russia state-sponsored campaign has been designed to steal Microsoft 365 credentials, deliver malware to Windows devices, and collect intelligence from targeted organizations. The company said attackers use adversary-in-the-middle phishing techniques and abuse Microsoft’s device code authentication process to convince victims to authorize access to their accounts.

Once access is obtained, the attackers can potentially maintain long-term access to email, cloud services, and other Microsoft 365 resources. In some cases, Microsoft says victims may also receive malware capable of stealing browser cookies, authentication tokens, saved credentials, and other sensitive information while providing attackers with persistent remote access.

Microsoft said it is urging organizations to use various strategies to strengthen identity protections. This includes deploying phishing-resistant multi-factor authentication, monitoring for suspicious device registrations, and securing captive portal infrastructure against compromise.

For travelers, the company recommends they remain cautious of unexpected Microsoft authentication prompts while using public Wi-Fi, enable phishing-resistant MFA such as passkeys or hardware security keys, consistently keep devices updated, and use only trusted VPN services.