Using free Wi-Fi? Microsoft warns hackers can steal your passwords and data
Microsoft warns that hackers are targeting hotel and guest Wi-Fi networks to steal passwords and sensitive data.
The CaptiveCrunch campaign uses fake update prompts, phishing pages and malware to compromise travellers’ devices.
Microsoft advises using mobile hotspots or private connections and avoiding software downloads prompted by public Wi-Fi portals.
If you travel often and love to use free hotel Wi-Fi then you should read along. Recently, Microsoft shared a warning that these networks are increasingly being used to deliver phishing attacks and malware. Microsoft Threat Intelligence has identified a campaign targeting hotel and other guest Wi-Fi networks across several countries. The campaign, called CaptiveCrunch, has been active since May 2026 and has been linked to Storm-2945, a group associated with Russia-linked hacking operation Midnight Blizzard.
SurveyHow hackers are attacking hotel Wi-Fi
The attackers are using networks that use captive portals, the login pages which appear when connecting to hotel, airport or conference Wi-Fi. Microsoft says Storm-2945 has been manipulating DNS and HTTP traffic to redirect users from legitimate portals to attacker-controlled websites.
These pages can then display convincing warnings asking the users to install a Windows or browser update, complete a security check or fix a supposed connection problem. Android users may get asked to download an APK file.
The campaign also uses the device code phishing. The victims may be directed to a genuine Microsoft sign-in page and asked to enter a code provided by the attacker. Completing the process can potentially give attackers access to the victim’s active session.
The company also said that the campaign combines traffic manipulation, phishing and malware delivery. It means that the users may not realise they have been targeted until after their device or account has been compromised.
What is at risk?
Microsoft has identified two malware families, CornFlake and ChocoShell, being used in the campaign. CornFlake can reportedly steal files, passwords and other credentials, while also capturing screenshots and recording audio and video. ChocoShell can target browser cookies, saved passwords, Microsoft 365 credentials and Wi-Fi passwords.
How to stay safe
The company recommends treating hotel, airport, conference and other public Wi-Fi networks as untrusted. Travellers should use personal hotspot, eSIM or other private connection where possible.
Ashish Singh is the Chief Copy Editor at Digit. He's been wrangling tech jargon since 2020 (Times Internet, Jagran English '22). When not policing commas, he's likely fueling his gadget habit with coffee, strategising his next virtual race, or plotting a road trip to test the latest in-car tech. He speaks fluent Geek. View Full Profile
