Indonesian Political, Business & Finance News

Microsoft Warns of Hotel Wi-Fi Danger: CaptiveCrunch Campaign Targets Tourist Data

| | Source: MEDIA_INDONESIA Translated from Indonesian | Technology
Microsoft Warns of Hotel Wi-Fi Danger: CaptiveCrunch Campaign Targets Tourist Data
Image: MEDIA_INDONESIA

Microsoft has issued a stern warning for travellers to be more vigilant when connecting to hotel Wi-Fi networks. The warning comes after the technology company uncovered a cyber espionage campaign that hijacks public internet connections to steal passwords, business data, and other sensitive information.

In its latest report, Microsoft stated that a hacking group known as Storm-2945 compromised Wi-Fi networks used by hotels, conference centres, and other public venues that rely on captive portals—web pages users must complete before accessing free internet.

Microsoft has named this campaign CaptiveCrunch. The attack, attributed to Russia, has been observed since early May 2026 and appears to be aimed primarily at corporate travellers or businesspeople.

The modus operandi of CaptiveCrunch involves manipulating internet traffic immediately after a traveller joins a hotel Wi-Fi network. Instead of directing users to a legitimate website, the attackers redirect them to a fake Microsoft login page or a fictitious software update screen designed to steal credentials or infect devices with malware.

Some victims were even tricked into completing a legitimate Microsoft sign-in process using a device code controlled by the attacker. Although the login page was genuine, entering the code gave the hackers full access to the victim’s Microsoft account rather than connecting them to the intended internet service.

Beyond account theft, Microsoft found that the hackers delivered malware disguised as browser updates, Windows updates, or network repair tools. This malicious software has alarming capabilities, including the ability to steal data and maintain persistent access to compromised systems.

Android users were also targeted through fake prompts encouraging them to install malicious application files.

Microsoft attributes Storm-2945 as a sub-group of Midnight Blizzard, a hacking organisation linked by US and UK authorities to Russia’s Foreign Intelligence Service (SVR). The report also revealed that Storm-2945 uses artificial intelligence (AI) to support a significant portion of its operations, including phishing campaigns and malware development.

“Users should treat guest wireless networks at hotels, conferences, airports, and other venues as untrusted networks,” Microsoft stressed in its report.

View JSON | Print