
Microsoft's Threat Intelligence team has warned of a global cyberattack campaign called 'CaptiveCrunch' that targets hotel and conference centre Wi-Fi networks. The attacks, active since at least May (Deccan Herald reports the…
Microsoft's Threat Intelligence team has warned of a global cyberattack campaign called 'CaptiveCrunch' that targets hotel and conference centre Wi-Fi networks. The attacks, active since at least May (Deccan Herald reports the campaign started in February 2026), are attributed to Storm-2945, a subgroup of the Russian state-sponsored hacking group Midnight Blizzard. Hackers compromise the Wi-Fi infrastructure and redirect guests to fake login screens or pop-ups that trick them into downloading malware or handing over Microsoft 365 credentials. Once infected, the attackers can steal passwords, record audio and video, and remotely control the device. Microsoft advises travellers to use cellular hotspots instead of hotel Wi-Fi and never to download software updates from captive portals.

The 'CaptiveCrunch' warning is real, but the panic should be measured. Similar phishing attacks on public Wi-Fi have existed for years. The real test is not whether this group is new, but whether corporate IT departments finally enforce the basic rule: never trust a captive portal. Watch for the fake update prompts Microsoft listed, if a hotel Wi-Fi asks you to run a 'DirectX' installer, you are already compromised.
Sources (2): timesofindia.indiatimes.com, deccanherald.com
This story was synthesised by AI from the 2 sources linked above.
Updated: this story now draws on 2 sources.