What Happened: Russian Spies Target Hotel Wi-Fi
Microsoft has revealed that Russian intelligence operatives are compromising public Wi-Fi networks in hotels and conference centers to deliver malware and steal credentials. The campaign, dubbed 'CaptiveCrunch,' targets business travelers and could affect any company with employees who travel.
According to Microsoft, the operation dates back to February 2026, with active traffic manipulation since early May. The attackers, part of the SVR's Midnight Blizzard group, use a sophisticated approach to intercept and redirect network traffic.
Does This Affect Your Business?
If your employees use public Wi-Fi while traveling, your business is at risk. The attackers can steal login credentials, access cloud accounts, and even take over devices. This could lead to data breaches, financial loss, and reputational damage.
Even if you don't have a large corporate network, a single infected laptop can expose sensitive client information or intellectual property.
How the Attack Works
The attackers compromise the captive portal—the login page you see when connecting to hotel Wi-Fi. They then manipulate DNS and HTTP traffic to redirect users to malicious sites. Users are shown fake prompts, such as 'Windows Update' or 'Driver Repair,' which trick them into installing malware.
One malware strain, CornFlake, is a full-featured remote access tool that can record keystrokes, capture screenshots, and even turn on your webcam. Another, ChocoShell, steals browser cookies and passwords, giving attackers access to your cloud accounts.
Even multi-factor authentication (MFA) can be bypassed through a technique called device code phishing, which tricks users into authorizing the attacker's session.
What This Means for Your Business
This attack is a clear reminder that public Wi-Fi is not safe for business use. The hospitality industry is a prime target because travelers are often relaxed and less cautious.
For small and mid-sized businesses, the risk is real. A single compromised device can lead to a costly data breach. The good news is that there are simple steps you can take to protect your team.
Your Move: Protect Your Team Today
Start by requiring employees to use a virtual private network (VPN) when traveling. A VPN encrypts internet traffic, making it much harder for attackers to intercept. Also, advise employees to use personal hotspots instead of hotel Wi-Fi.
Additionally, disable the device code authentication flow in your Microsoft 365 tenant if possible. This will block a key attack vector.
Finally, educate your team about these fake prompts. Remind them never to install software or enter credentials when prompted by a public Wi-Fi login page.
Bottom Line
This is a serious, state-sponsored attack that targets the exact scenario your business travelers face. Don't wait for an incident to happen. Implement these security measures now to protect your data and your reputation.
FAQ
Use a VPN, prefer personal hotspots, and disable device code authentication in your cloud services.
Disconnect from the network, run a security scan, and change all passwords immediately. Report the incident to your IT team.


