Microsoft warns Russian hackers are hijacking hotel Wi-Fi to steal Microsoft 365 accounts

https://www.techspot.com/images2/news/ts3_thumbs/2026/08/2026-08-04-ts3_thumbs-28d.jpg

Serving tech enthusiasts for over 25 years.
TechSpot means tech analysis and advice you can trust.

In a nutshell: Most people know to be careful when using hotel Wi-Fi, and Microsoft has just reminded us why. The Redmond firm has uncovered a Russian state-backed campaign that compromises hotel and conference Wi-Fi networks, redirecting travelers to fake login pages and malicious software disguised as legitimate system updates.

Microsoft calls the operation the almost cereal-sounding name of CaptiveCrunch. It says the attacks have been active since at least early May and are being carried out by Storm-2945, an operational sub-cluster of Midnight Blizzard. The infamous Midnight Blizzard, also known as Cozy Bear, APT29, and Nobelium, is linked to Russia's Foreign Intelligence Service, the SVR.

The campaign targets hospitality networks that use captive portals – the login or terms-and-conditions pages that appear when someone connects to guest Wi-Fi. Once the underlying...

Copyright of this story solely belongs to techspot.com. To see the full text click HERE

Read more