Microsoft warns hotel/airport Wi-Fi is being hijacked to steal your login
In a recent Microsoft Security Blog post, the company has raised awareness of a widespread attack campaign called CaptiveCrunch. In short, Russian hackers are using manipulated DNS queries to redirect users to phishing sites that mimic Microsoft’s official online services. As a result, Microsoft is warning against the use of public Wi-Fi networks.
With these fake phishing sites, the attackers are attempting to intercept and steal login credentials for Microsoft accounts. Some security researchers previously published a warning to this effect back in July, and now Microsoft is supplementing that report with its own new information based on what it has been monitoring since May 2026.
According to the report, the attackers redirect users—for example, those who are logging into their Microsoft accounts via a hotel Wi-Fi network—to imitation phishing sites. There, the attackers capture device and OAuth codes, which they can use to take over said Microsoft accounts.
In addition, the attackers are believed to be installing malware on victims’ devices, including Trojans that record keystrokes, eavesdrop on device activity, spy via hijacked cameras, and forward sensitive files and passwords. Furthermore, the malware sets up remote access for the attackers to the infected devices.
It’s apparently made possible by compromised public Wi-Fi networks, like the ones you’d rely on in hotels and airports. The key question, of course, is how the attackers gain access to those networks, which Microsoft is currently investigating. It’s possible that the captive portals, where users agree to terms of use, play a role.
Microsoft states the following on this matter:
Although our investigation into the initial compromise vector for the captive portal networks is ongoing, we have observed notable commonalities in the equipment and management systems used across multiple affected networks. These similarities suggest that the activity might not be limited to isolated compromises of individual venues and could reflect access to shared services within portions of the captive portal ecosystem.
Microsoft believes the hacker group Storm-2945 is responsible for this wave of CaptiveCrunch attacks. This group is associated with Midnight Blizzard, which in turn is believed to be part of the Russian Foreign Intelligence Service.
What you can do to stay safe
Public Wi-Fi networks are risky. Not only is there a non-zero chance for your data to be intercepted, but Wi-Fi hotspots can be exploited to track your physical location and even identify your physical body.
The safest thing you can do is to never use public Wi-Fi. Of course, that isn’t always the way to go—who can deny the convenience of Wi-Fi at coffee shops, hotels, and airports, especially if you don’t have unlimited mobile data to use as your own personal hotspot?
If you are going to use public Wi-Fi, make sure your devices are protected with a VPN. A good VPN encrypts your network activity, hiding it from the network and making it virtually uncrackable by hackers. Just make sure you don’t settle for a free VPN, which comes with its own issues. Choose one from PCWorld’s roundup of the best VPNs and you’ll be golden.
Microsoft warns: “When traveling, users should treat hotel, conference, airport, and other guest wireless networks as untrustworthy.” You should opt for private connections (like your own mobile hotspot) when you can, and never download software updates, certificates, or apps that are presented through public Wi-Fi captive portals and web prompts.
Further reading: I use public Wi-Fi despite the risks. Here’s how I stay safe