Microsoft said this week that Russian state-sponsored hackers are targeting hotel Wi-Fi networks to steal credentials and deliver malware [1].
This operation threatens travelers worldwide by weaponizing the login portals typically used to access hospitality internet services. Because these attacks target the gateway level, they can bypass standard security measures and compromise corporate accounts.
The hacking operation, nicknamed "CaptiveCrunch" [1], specifically targets Microsoft 365 credentials [2]. Reports said the attackers use hijacked Wi-Fi portals to harvest logins and bypass multi-factor authentication [3]. Once the attackers gain access to these credentials, they can penetrate secure corporate environments or install malware directly onto Windows PCs [2].
Microsoft issued the first public warning regarding this activity on Aug. 1, 2026 [1]. The campaign appears to be global in scope, focusing on hotel and other hospitality Wi-Fi networks [4].
Security analysts said that the attackers leverage the "captive portal" — the web page that appears when a user first connects to a public network — to deceive victims [3]. By mimicking legitimate login screens, the hackers can capture sensitive data before the user even realizes the connection is compromised [5].
Reports of the campaign continued to circulate through the week, with additional warnings appearing on Aug. 3, 2026 [6]. Microsoft has not detailed the specific number of compromised devices, but the company said Windows users should remain vigilant when connecting to public networks in hospitality settings [4].
Experts suggest using virtual private networks (VPNs), and ensuring all security software is updated, to mitigate the risk of credential theft [2].
“Russian state-sponsored hackers are targeting hotel Wi-Fi networks to steal credentials and deliver malware.”
The CaptiveCrunch campaign demonstrates a sophisticated shift in state-sponsored espionage, moving from traditional phishing emails to the physical infrastructure of global travel. By compromising the captive portals of hotels, attackers can target high-value corporate travelers who often assume a hotel's managed network is safer than a random public hotspot. This highlights a critical vulnerability in how multi-factor authentication is implemented, as these attackers have found ways to circumvent these protections at the network level.


