Microsoft has issued a global cybersecurity warning for travellers after identifying a campaign targeting Wi Fi networks used by hotels and other hospitality organisations.
The campaign, named CaptiveCrunch by Microsoft Threat Intelligence, has been attributed to Storm 2945, which Microsoft describes as a subcluster of Midnight Blizzard. The activity involves manipulation of internet traffic on networks that use captive portals, the login pages commonly displayed when guests connect to hotel or other public Wi Fi networks.
Microsoft said it began observing the activity in early May 2026. The company reported widespread but targeted traffic manipulation involving hospitality sector networks in different parts of the world.
The warning is particularly relevant for people who frequently use hotel Wi Fi while travelling. Public wireless networks can provide convenient internet access, but compromised network infrastructure can create opportunities for attackers to redirect users to websites controlled by criminals.
In the CaptiveCrunch campaign, Microsoft said attackers manipulate DNS and HTTP traffic from networks served by captive portals. This allows traffic to be redirected through infrastructure controlled by the attackers.
One of the methods identified by Microsoft involves redirecting users to pages that appear legitimate but are designed to trick them into providing sensitive information.
The attackers can reportedly use fake Microsoft 365 login pages to attempt to collect account credentials. Microsoft also identified activity involving device code authentication and other techniques intended to gain access to accounts.
Another part of the campaign involves fake software update notifications. A traveller may connect to a compromised Wi Fi network and encounter a message suggesting that a browser or another application needs to be updated.
Instead of delivering a legitimate update, the page can direct the user towards malicious software.
Microsoft has linked the campaign to the delivery of malware, including a remote access trojan known as CornFlake. Security reporting based on Microsoft's findings says the malware can provide attackers with capabilities such as capturing keystrokes, screenshots and potentially audio or video from compromised systems.
This makes the threat more serious than a simple attempt to steal a Wi Fi password. If a traveller's device becomes infected, attackers may potentially gain access to sensitive information stored or processed on the device.
Business travellers could be particularly exposed because hotel networks are frequently used to connect laptops and mobile devices containing work related information.
Microsoft said Storm 2945 had also conducted other phishing campaigns before the CaptiveCrunch activity. Since February 2026, the group has reportedly used AI assisted device code and OAuth phishing techniques targeting Microsoft 365 users.
The use of captive portals is significant because these systems are a familiar part of hotel and public Wi Fi networks. Guests generally expect to see a login or terms and conditions page after connecting.
Attackers who gain control over the relevant network infrastructure can potentially manipulate what users see during this process.
Microsoft has not said that every hotel Wi Fi network is compromised. The warning concerns specific networks and infrastructure that attackers have managed to manipulate.
Therefore, travellers should not assume that every public Wi Fi connection is malicious. However, the campaign demonstrates why users should exercise caution when connecting devices to networks they do not control.
Microsoft recommends avoiding unnecessary sensitive activities over untrusted public networks. Travellers can consider using mobile data or a personal hotspot when handling banking, corporate or other sensitive information.
A virtual private network can also provide an additional layer of protection by encrypting network traffic. Microsoft itself provides a safer Wi Fi feature through Microsoft Defender that can identify potentially unsafe wireless connections and recommend additional protection.
Another important precaution is to avoid installing software simply because a public Wi Fi login page requests it.
Users should be particularly suspicious of unexpected requests to install browser updates, security certificates, applications or other software after connecting to a hotel network.
Legitimate software updates should preferably be obtained directly through the operating system's normal update mechanism or the official website or application store of the software provider.
Travellers should also keep their operating systems, browsers and security applications updated before starting a trip. Security updates can address vulnerabilities that attackers may otherwise exploit.
Automatic connection to previously used public networks should also be reviewed. Cybercriminals can create networks with names that resemble legitimate Wi Fi services, potentially tricking devices into connecting automatically.
Microsoft's security guidance warns that attackers can create fake Wi Fi hotspots with names similar to popular public networks. It recommends avoiding automatic connections to networks that users do not control.
Password security is another important consideration. Users should avoid entering important account passwords into unexpected login pages displayed after connecting to public Wi Fi.
If a login page looks unusual, contains spelling mistakes or redirects to an unfamiliar website, users should disconnect and verify the network with hotel staff or through an official channel.
Multi factor authentication can also provide additional protection for online accounts. Even if a password is exposed, an additional authentication requirement can make unauthorised access more difficult.
However, users should remain cautious about unexpected authentication requests. Attackers increasingly use phishing techniques designed to convince victims to approve fraudulent sign in attempts.
The CaptiveCrunch campaign also highlights the changing nature of cyber threats. Instead of attacking individual users directly, criminals can target network infrastructure and use that access to reach many people who connect to the affected network.
This approach can be particularly effective in environments such as hotels, conference centres and other locations where large numbers of visitors use shared internet connections.
Microsoft said its investigation into how the captive portal networks were initially compromised remains ongoing. This means the precise method used to gain initial access to the affected infrastructure has not been fully established.
The company has attributed CaptiveCrunch to Storm 2945 based on observed technical similarities and other intelligence gathered during its investigation.
Midnight Blizzard is a Russia linked threat actor that has previously been associated with cyber espionage activity. Microsoft tracks different operational clusters associated with the group, including Storm 2945.
For ordinary travellers, the warning does not mean that hotel Wi Fi should never be used. Instead, it highlights the importance of treating public networks as less trusted than personal or private connections.
Travellers can reduce their exposure by using mobile data for sensitive activities, enabling security protections, keeping devices updated and avoiding unexpected downloads.
People should also be careful about what information they enter into websites while connected to public networks. Banking transactions, corporate credentials and other sensitive activities should preferably be performed through trusted connections.
If a device suddenly displays an unusual update message after connecting to hotel Wi Fi, users should close the page rather than immediately following the instructions.
The CaptiveCrunch campaign demonstrates how attackers can combine compromised network infrastructure, social engineering and malware delivery to target travellers.
As more people work remotely and carry valuable personal and professional information on laptops and smartphones, public network security is becoming increasingly important.
Microsoft's warning serves as a reminder that convenience should not come at the expense of basic cybersecurity precautions. Hotel Wi Fi can be useful for everyday browsing, but travellers should remain cautious when handling sensitive information or responding to unexpected prompts.
The safest approach is to verify unusual login requests, avoid untrusted downloads, use updated security software and rely on mobile data or other trusted connections whenever possible.
The CaptiveCrunch campaign remains under investigation, and Microsoft continues to monitor activity associated with Storm 2945. For travellers, maintaining basic digital security practices can help reduce the risk of credential theft, malware infection and unauthorised access while using public Wi Fi networks.

