Hackers Are Targeting Hotel Wi-Fi to Steal Microsoft 365 Logins. How Business Travelers Stay Safe

Microsoft says a Russian state-linked group has been hijacking hotel and conference-center Wi-Fi since May 2026 to steal Microsoft 365 access and plant spyware on travelers' laptops. Here is how the attack works and what stops it.

By NetWorthy Editors · · 10 min read · 20 sources

Laptop and white coffee cup on a desk by a window overlooking mountains and a turquoise lake
Photo: AS_Photography on Pixabay

Key takeaways

  • Microsoft Threat Intelligence reported on July 31, 2026 that Storm-2945, a sub-cluster of the Russian group Midnight Blizzard, has manipulated hotel and conference-center Wi-Fi traffic since early May 2026.
  • The hijacked networks sent travelers to fake Microsoft 365 sign-in pages, tricked them into entering device codes on Microsoft's real sign-in page, or pushed fake browser and operating system updates that installed spyware.
  • Microsoft updated its report on October 5, 2026 to say the group resumed the campaign on September 29 with a new variant of its CornFlake malware.
  • The device-code trick can hand attackers an MFA-approved session, so app-based MFA alone is not enough; Microsoft and the FBI both tell organizations to block device code flow where it isn't needed.
  • The simplest traveler fix is to skip venue Wi-Fi for work and use your phone's cellular hotspot or an eSIM, and never install software or certificates offered by a Wi-Fi login page.

What did Microsoft actually warn about?

Microsoft warned that a Russian state-linked hacking group has been taking over the Wi-Fi sign-in systems at hotels and conference centers to steal corporate travelers' Microsoft 365 access and install spyware. In a report published July 31, 2026, Microsoft Threat Intelligence wrote that "since early May 2026" it had observed Storm-2945, which it calls a sub-cluster of Midnight Blizzard, conducting "widespread but targeted traffic manipulation attacks involving hospitality sector networks served by captive portals worldwide." Microsoft named the campaign CaptiveCrunch.

Midnight Blizzard is the group also tracked as APT29 or Cozy Bear, which the U.S. and U.K. governments link to Russia's SVR foreign intelligence service, as The Hacker News and The Record noted in their coverage. The story then spread well beyond security trade press. Nepal's Kantipur Media Group, publisher of The Kathmandu Post, ran it on ekantipur as "Microsoft warns of a group actively hacking through hotel Wi-Fi networks".

The campaign is not over. On October 5, 2026, Microsoft added an update saying it saw Storm-2945 resume CaptiveCrunch on September 29, 2026, using "a Rust variant of CornFlake," its custom remote-access malware. If you have conference travel on the calendar this fall, this applies to you now.

How does the hotel Wi-Fi attack work?

The attackers compromise the captive portal, the gateway system behind the "accept terms / enter your room number" page, and then rewrite guests' traffic before it ever reaches the internet. Microsoft says the group manipulated "DNS and HTTP traffic from networks served by captive portals to redirect user traffic through actor-controlled infrastructure." Security firm ReliaQuest, which first published on the activity on July 23, put the core problem bluntly: "A single compromised gateway lets the threat actor silently redirect users' traffic without touching their devices."

  1. The gateway is taken over. ReliaQuest says access likely came through exposed management interfaces such as internet-facing SSH, SNMP and web admin consoles, combined with weak or reused admin passwords. Microsoft's investigation is ongoing, but it noted "notable commonalities in the equipment and management systems used across multiple affected networks."
  2. DNS is poisoned. When a guest's laptop looks up a Microsoft 365 address, the gateway answers with an attacker server instead. ReliaQuest listed lookalike domains including m365-owa[.]com, owa-ms365[.]com, ms365-device[.]com and ms365-live[.]com.
  3. Some traffic is proxied wholesale. In about one-third of cases, ReliaQuest saw attempts to abuse Web Proxy Auto-Discovery (WPAD), which could route all of a laptop's application traffic through the attacker's proxy.
  4. The guest gets a lure. Depending on the victim, the redirect leads to one of the three traps below.
The three CaptiveCrunch lures Microsoft and ReliaQuest describe
LureWhat you seeWhat the attacker gets
Fake Microsoft 365 sign-in pageA familiar-looking Outlook or Microsoft login on a lookalike domainYour username and password, and possibly your session
Device code phishing (since July 16, 2026)A page telling you to enter a short code on Microsoft's real sign-in siteAn OAuth token for your account, already MFA-approved
Fake browser or OS updateA "you must update to continue" prompt, sometimes with ClickFix-style copy-and-paste instructionsCornFlake spyware or the ChocoShell credential stealer on your device

Why the device code trick beats regular MFA

Device code sign-in exists so you can log in to a TV or printer by typing a code on another device. Microsoft says that since July 16, 2026, victims were "instructed to enter a device code into a legitimate Microsoft sign-in page." Because the page is genuinely Microsoft's and you approve your own MFA prompt, the attacker's session inherits a fully authenticated login. The Hacker News summarized it as MFA-bypassed access. The same technique powers Kali365, a phishing kit the FBI warned about in a May 21, 2026 public service announcement.

What the malware does

Microsoft describes CornFlake as a "full-featured Windows RAT written in Go" with keylogging, clipboard monitoring, screenshots, audio and video surveillance, browser credential theft and a remote shell. ChocoShell is a PowerShell stealer that runs entirely in memory and targets browser cookies, saved passwords, Microsoft 365 single sign-on tokens and saved Wi-Fi credentials. The Record reported that some fake update pages also targeted Android phones.

Hotel and conference-center networks are shared by hundreds of guests, which is exactly why attackers went after the gateways instead of individual laptops. Video: Coverr-Free-Footage on Pixabay
Black wireless router with three antennas on a white background
The attack starts at the Wi-Fi sign-in page that appears when you join a hotel or venue network. Photo: USA-Reiseblogger on Pixabay

Who is being targeted, and where?

Corporate travelers in regulated, data-rich industries are the target. ReliaQuest traced compromised gateways to multiple U.S. cities, India and Saudi Arabia, with hotels accounting for most affected venues, and said the traffic came from organizations in financial services, professional services, legal, healthcare, energy and retail. Microsoft's own report does not name countries; it says it found "widespread compromise of Wi-Fi networks at hospitality-related organizations and other networks serviced by captive portal equipment in several countries."

The two reports also differ on timing and attribution. ReliaQuest dated the activity to "at least June 2026" and saw tradecraft overlapping with APT28 (Forest Blizzard) without attributing it. Microsoft, with more telemetry, dates it to early May and attributes it to Storm-2945 and Midnight Blizzard. When this article cites a country or sector, it comes from ReliaQuest's research as reported by CyberInsider and iTnews.

None of this is new territory for Russian intelligence. In 2017, FireEye (now Google's Mandiant) reported that APT28 targeted hotels in at least seven European countries and described a 2016 case where a victim was compromised after joining hotel Wi-Fi; twelve hours later the attackers logged in with the stolen credentials. FireEye's conclusion then holds now: "Publicly accessible Wi-Fi networks present a significant threat and should be avoided whenever possible."

“Hotel Wi‑Fi is not automatically unsafe, but it is never a network you should blindly trust.”

— Tom Eston & Scott Wright, Shared Security Podcast · Long-running security podcast hosts, in their September 7, 2026 episode on CaptiveCrunch

What are the red flags on a hotel or conference network?

The biggest red flag is any Wi-Fi sign-in page that asks you to install, download or paste something. A legitimate captive portal needs, at most, your room number, last name, a voucher code or a click. Microsoft explicitly tells travelers to avoid "software updates, certificates, browser updates, network troubleshooting tools, or security utilities presented through captive portals or other unexpected web prompts."

  • An "update required" page right after you connect. Microsoft says the fake updates appeared "in response to automated connectivity checks" your browser makes when joining a network. Real Windows and macOS updates come from Settings, not a web page.
  • A prompt to install a certificate or "network profile." Microsoft lists certificates among the things never to accept from a portal; installing one could let a network operator read encrypted traffic.
  • Copy-and-paste instructions. ClickFix lures tell you to press keys and paste a command into Run or Terminal. No hotel login ever requires this.
  • A Microsoft login on a strange domain. Look at the address bar. Lookalikes such as m365-owa or ms365-live are not Microsoft.
  • A request to enter a device code you didn't start. If you didn't just try to sign in on a TV, printer or command-line tool, don't enter a code on Microsoft's device sign-in page.
  • The portal asks for your work email and password. Microsoft advises: "Do not reuse corporate credentials on hotel, conference, or guest-network registration pages."
  • Repeated Microsoft 365 sign-in prompts or MFA requests you didn't trigger. Treat them as a sign someone else is trying to log in.

How do business travelers stay safe on hotel Wi-Fi?

The most effective protection is to not use hotel or conference Wi-Fi for work at all. Microsoft's first recommendation for travelers is to "prefer private connectivity (including mobile hotspots, satellite, and eSIM-based cellular data connections) over public Wi‑Fi whenever practical." The FBI gave similar advice in a 2020 public service announcement on working from hotels, suggesting a phone's hotspot as an alternative and warning that criminals can "redirect them to false login pages."

  1. Use your phone's hotspot or a travel eSIM. Cellular data never touches the hotel gateway. If your U.S. plan's roaming is expensive, a travel eSIM such as Saily or Jetpac is a cheap way to keep your laptop off venue Wi-Fi.
  2. If you must use venue Wi-Fi, connect a VPN immediately after the portal. ReliaQuest's top recommendation is an always-on, full-tunnel VPN so DNS goes to trusted resolvers instead of the hotel gateway. Note the gap: the portal page itself loads before most VPNs connect, so be suspicious of anything it asks you to do. Our VPN comparison and guide to VPNs on every device cover setup, and most providers offer free trials so you can test one at home first.
  3. Never install anything a Wi-Fi page offers. No updates, certificates, "security tools" or profiles. Run updates from your operating system's own settings before you travel.
  4. Move to passkeys or a FIDO2 security key. CISA's phishing-resistant MFA fact sheet calls phishing-resistant MFA "the gold standard" and says FIDO/WebAuthn is "the only widely available phishing-resistant authentication." A passkey won't work on a lookalike domain like ms365-live.
  5. Know what a device code prompt looks like, and refuse unexpected ones. Passkeys stop fake login pages but not a code you type yourself into Microsoft's real page.
  6. Keep work credentials off portal forms. Use your room number and last name, never your work email and password.
  7. Turn off auto-join. The FBI recommends disabling auto-reconnect for public networks and forgetting the hotel network when you check out.
  8. Report anything odd to IT the same day. A fake update prompt on a hotel network is useful intelligence for your security team.

“eSIM and ubiquitous internet travel pricing means the hotel wifi may be the LEAST valid path to access things.”

— ggm, Hacker News · Commenter in a July 2026 thread about travel router firmware

Travelers who rely on a travel router (a pocket device that logs in to the hotel network once and shares a private network to your devices) can pair it with a VPN so every device gets protection. One Hacker News user described the routine:

“I just connect to the travel router AP, then connect the travel router to the hotel's WiFi, and browse neverssl.com to get the captive portal.”

— avidiax, Hacker News · GL.iNet travel router owner, December 2025

For more on locking down shared networks, see our coworking Wi-Fi security checklist and the broader 2026 business traveler's security guide.

Woman in a denim jacket using a smartphone by a window with plants
Microsoft's first recommendation: use your own cellular connection instead of venue Wi-Fi whenever practical. Photo: StefanCoders on Pixabay

What should IT teams tell traveling staff?

IT teams should tell travelers to treat every venue network as hostile, then back that up with controls that work even when someone clicks. The guidance from Microsoft, the FBI and CISA lines up on five points.

  1. Block device code flow. Microsoft's Conditional Access documentation says: "We recommend organizations get as close as possible to a unilateral block on device code flow." The FBI's Kali365 PSA says the same: block it for all users except where necessary for business operations, after auditing who uses it, and keep emergency access accounts excluded.
  2. Roll out phishing-resistant MFA. Microsoft recommends passkeys, including in Microsoft Authenticator, plus Conditional Access and sign-in risk policies. CISA advises starting with high-value accounts and email.
  3. Enforce always-on, full-tunnel VPN or an SSE client. Microsoft points to Security Service Edge tools such as Global Secure Access; ReliaQuest also recommends disabling WPAD via Group Policy where it isn't needed. Remote staff who live overseas have extra considerations, covered in our guide to VPNs for expats.
  4. Control which Wi-Fi networks laptops can join. Microsoft notes organizations can "prevent Wi-Fi connections to networks that have not been provisioned via Mobile Device Management (MDM)," and can issue managed travel routers or hotspots.
  5. Brief travelers before and after trips. Microsoft suggests minimizing employee names and affiliations shared with hotels when booking. The FBI's business travel brochure tells returning travelers to change passwords, check devices for malware and report anything unusual.

“You cannot reliably block Microsoft Entra device code flow without Entra ID Premium P1.”

— buccal, Hacker News · Commenter on a May 2026 thread about an AI-enabled device code phishing campaign

That licensing point matters for small firms: Conditional Access is the documented way to block device code flow, so check which Entra ID tier your Microsoft 365 plan includes before assuming you're covered.

What should you do if you already entered a code or ran an "update"?

Disconnect from the network and call your IT or security team immediately, because a stolen token can stay valid after you change your password. Microsoft says ChocoShell steals Microsoft 365 single sign-on tokens and cookies, which are what let an attacker stay signed in.

  1. Switch off Wi-Fi and move to your phone's cellular hotspot.
  2. Tell IT exactly what you saw: the network name, the page address, and whether you entered a code, a password, or ran a file.
  3. Ask IT to revoke your active sessions and refresh tokens, not just reset your password.
  4. Do not keep using a laptop that ran an unknown "update"; let IT examine or reimage it.
  5. Change passwords for any personal accounts saved in that browser, from a different, clean device.

If you're heading somewhere with heavier network restrictions, read our guide to VPN setup for China, the UAE and Russia before you land.

Frequently asked questions

Is hotel Wi-Fi safe for Microsoft 365?

Not reliably. Microsoft reported in July 2026 that a Russian state-linked group compromised hotel and conference-center captive portals to redirect guests to fake Microsoft login pages, device code phishing and fake updates. Use your phone's hotspot or an eSIM for work, or a full-tunnel VPN if you must use venue Wi-Fi.

What is CaptiveCrunch?

CaptiveCrunch is Microsoft's name for a campaign by Storm-2945, a sub-cluster of Midnight Blizzard, that has manipulated DNS and web traffic on hospitality Wi-Fi networks since early May 2026. Microsoft reported it on July 31, 2026 and said on October 5 that the group resumed activity on September 29.

Does MFA protect me from the hotel Wi-Fi attack?

Only partly. App-based MFA does not stop device code phishing, because you approve the login yourself on Microsoft's real page. Passkeys and FIDO2 keys stop fake lookalike login pages, and organizations should also block device code flow with Conditional Access, as Microsoft and the FBI recommend.

Will a VPN stop the attack?

A full-tunnel VPN that is connected sends your DNS and traffic past the hotel gateway, which is ReliaQuest's top recommendation. But the captive portal page loads before most VPNs connect, so you still must refuse any download, certificate or code that page asks for. See our VPN explainer.

Which countries were affected?

Microsoft's report says several countries without naming them. ReliaQuest, which published first on July 23, 2026, traced compromised gateways to multiple U.S. cities, India and Saudi Arabia.

Sources

  1. CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft — Microsoft Threat Intelligence, 2026-07-31
  2. DNS Poisoning Tactics Expand to Hospitality Wi-Fi — ReliaQuest, 2026-07-23
  3. Russian hackers hijack hotel Wi-Fi networks to spy on travelers, Microsoft says — The Record, 2026-08-03
  4. Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware — The Hacker News, 2026-08-01
  5. Midnight Blizzard Targets Travelers via Captive Portals — Infosecurity Magazine, 2026-08-03
  6. Russian hackers abuse hotel Wi-Fi networks to steal Microsoft 365 credentials and deploy malware — Help Net Security, 2026-08-04
  7. Hackers use DNS poisoning on hotel Wi-Fi to steal Microsoft 365 accounts — CyberInsider, 2026-07-24
  8. Russia-linked "Midnight Blizzard" group hijacks hotel wi-fi with CaptiveCrunch — iTnews, 2026-08-04
  9. Microsoft warns of a group actively hacking through hotel Wi-Fi networks — Kantipur (ekantipur), 2026-08-05
  10. Block authentication flows with Conditional Access policy — Microsoft Learn, 2026-03-24
  11. Kali365 Phishing-as-a-Service Kit Hijacks Microsoft 365 Access Tokens (I-052126-PSA) — FBI Internet Crime Complaint Center, 2026-05-21
  12. A COVID 19-Driven Increase in Telework from Hotels Could Pose a Cyber Security Risk for Guests (I-100620-PSA) — FBI Internet Crime Complaint Center, 2020-10-06
  13. Implementing Phishing-Resistant MFA (fact sheet) — CISA, 2022-10
  14. Safety and Security for the Business Professional Traveling Abroad — FBI (copy hosted by Brookhaven National Laboratory)
  15. APT28 Targets Hospitality Sector, Presents Threat to Travelers — FireEye / Google Cloud (Mandiant), 2017-08-11
  16. Is Hotel WiFi Safe? — Shared Security Podcast, 2026-09-07
  17. Comment by ggm on travel routers and hotel Wi-Fi — Hacker News, 2026-07-08
  18. Comment by avidiax on travel routers and captive portals — Hacker News, 2025-12-24
  19. Comment by buccal on device code phishing mitigation — Hacker News, 2026-05-11
  20. Saily: Travel eSIM & Data (App Store listing) — Apple App Store

Quotes from social posts are reproduced verbatim from public posts and linked to the original. Read our editorial standards.

From Rotation

Every story, one email, 8am daily.

Subscribe at the bottom of this page.

More travel guides