
Microsoft has warned that a Russian hacking group, Storm-2945, is using fake hotel Wi-Fi portals to steal passwords, record audio and video, and take over devices. The campaign, dubbed CaptiveCrunch, has been…
Microsoft has warned that a Russian hacking group, Storm-2945, is using fake hotel Wi-Fi portals to steal passwords, record audio and video, and take over devices. The campaign, dubbed CaptiveCrunch, has been active since at least May and targets corporate travelers at hotels, conference centres, and airports globally. Attackers compromise the Wi-Fi infrastructure and redirect users to fake login screens or browser update prompts. Once credentials are entered or malware downloaded, the hackers gain access to Microsoft 365 accounts, emails, and corporate networks. Microsoft advises travellers to use cellular hotspots and ignore unexpected pop-ups on public networks.
The CaptiveCrunch campaign is a reminder that hotel Wi-Fi is never truly secure, but the panic over Russian hackers can obscure a simpler truth: most public networks are poorly defended. Travelers and companies alike have long treated convenience as more important than safety. The real test is whether hotels now invest in proper network monitoring or continue to leave guests vulnerable to any actor, state-backed or not.
Source: timesofindia.indiatimes.com
This story was synthesised by AI from the source linked above.