Microsoft issued a security warning this week regarding hackers targeting hotel Wi-Fi networks to steal passwords and record user audio and video [1, 2].

This threat represents a significant risk to business travelers and tourists who rely on public connectivity for sensitive work, as it targets the first point of connection in hospitality venues.

The campaign targets hospitality venue Wi-Fi networks worldwide [1, 3]. According to Microsoft, hackers use fraudulent captive-portal pages, the login screens users see when joining a network, to trick victims into providing credentials [1, 2]. Once a user is compromised, the attackers can gain unauthorized access to Microsoft 365 accounts [1, 2].

Beyond credential theft, the security warning noted that these attacks can allow hackers to record a user's audio and video [1, 2]. This level of surveillance suggests a highly invasive form of spying on travelers while they are away from secure home or office networks.

There are contradictions regarding the identity of the group behind the attacks. Some reports identify the campaign as "CaptiveCrunch" and attribute it to a Russian cyber-criminal group known as Storm-2945 [1, 2]. Other reports refer to the group as "Midnight Blizzard" and describe them as Russian state-sponsored hackers [3, 4].

Microsoft said travelers should avoid these risks by using cellular hotspots instead of hotel Wi-Fi [1, 2]. Using a personal data connection bypasses the fraudulent portals used by the attackers to intercept data.

The warnings were first published between Aug. 3 and Aug. 4 [3, 4]. Security experts said that any network requiring a login through a web browser should be treated with caution, especially when accessing corporate accounts.

Hackers can record your video and audio and steal passwords.

The shift toward using captive portals for surveillance indicates that threat actors are exploiting the inherent trust users place in hotel infrastructure. By mimicking a standard login process, hackers can bypass traditional security perceptions, making the use of independent cellular data a necessity for maintaining corporate and personal privacy during travel.