Microsoft warns hackers are targeting hotel Wi-Fi networks

Conference centers, hotels and other hospitality venues are affected.

ByMason Leib GMA logo
Monday, August 3, 2026 9:36PM
Microsoft warns hackers are targeting hotel Wi-FI networks
Sade Baderinwa has the details.

Microsoft is warning travelers about a new threat targeting hospitality venues in "widespread but targeted" internet traffic manipulation attacks.

Microsoft Threat Intelligence published a warning on its website Friday, notifying the public about an internet hijacking operation nicknamed "CaptiveCrunch," which it attributed to Russian state-sponsored hackers Storm-2945, a "sub-cluster" of the cyber group Midnight Blizzard, also known as "APT29" and "Cozy Bear."

Midnight Blizzard has been linked to the Russian Foreign Intelligence Service, or SVR, the company said.

Microsoft said it had specifically identified "widespread compromise of Wi-Fi networks at hospitality-related organizations," among other networks.

The tech giant also shared information on the threat, how the group has carried out the hijacking, and the best practices for the public to avoid the threat.

Read on for more information.

How does hotel internet hack work?

The Storm-2945 hackers have targeted hotels and other hospitality venues worldwide, impacting those connected to Wi-Fi networks with guest logins, or captive portals, according to Microsoft.

Users are then prompted to download malicious files, after which the hijackers infect the user's device with malware that collects browser cookies, passwords, documents and more, Microsoft said. The hackers are able to capture keystrokes, screenshots, audio, and video, monitor the clipboard, and operate the device remotely.

In some instances, users attempting to access a compromised network may be redirected to fake login screens, at which point, the hijackers will be able to access the user's Microsoft 365 account, giving them further access to the person's email and OneDrive.

What does the hack look like?

Users who encounter the threat may see a variety of false windows designed to throw off the user from detecting the scam, according to Microsoft.

The tech giant listed a number of potential fake windows that may pop up upon logging into a compromised network, prompting users to download updates or patches. They include:

  • "winupdate": A Windows Update screen displaying the words "Working on updates Don't turn off your computer"
  • "defender": A fake Windows Security virus scan
  • "directx": A "DirectX End-User Runtime Web Installer"
  • "vcredist": A Microsoft Visual C++ 2015-2022 Redistributable installer
  • "sysopt": A disk optimization utility
  • "netfix": A false Windows Network Diagnostics tool
  • "browser": A browser update prompt
  • "pdfview": A document viewer installer

In other cases, users may be be prompted to update their browser "in response to automated connectivity checks," according to Microsoft.

These false "connectivity checks" may look like Google browser screens that read "Verify it's you," and "Our systems have detected unusual traffic from your computer network. Please complete the security check to access Google Search." Following the prompts allows the hijackers to gain access to a user's device and operate it remotely.

How can users protect themselves from being hacked?

Microsoft said users should exercise caution when using guest networks at hotels, conferences, airports or other public venues.

The company suggested users rely on private connectivity, like phone hotspots, rather then public options whenever possible.

Microsoft also urged the public to use caution when faced with pop-up requests, and to avoid "downloading software updates, certificates, browser updates, network troubleshooting tools, or security utilities presented through captive portals or other unexpected web prompts."

Microsoft also issued a warning to organizations, asking them to "review what information employees provide to hospitality providers when connecting to guest networks."

Copyright © 2026 ABC News Internet Ventures.