Your Hotel Wi-Fi Might be Watching You: Inside Microsoft’s “CaptiveCrunch” Warning
Understanding Windows’ Device ID
If you’ve connected to a hotel’s guest Wi-Fi and clicked through one of those “click to continue” login pages, you’ve used a captive portal and according to Microsoft, that everyday travel ritual has become a doorway for state-sponsored hackers.
On July 31, 2026, Microsoft Threat Intelligence published a detailed warning about a campaign it’s calling CaptiveCrunch. The company says a group it tracks as Storm-2945, which it assesses is an operational sub-cluster of the notorious Russian threat actor Midnight Blizzard (also known as APT29 or Cozy Bear), has been quietly manipulating traffic on Wi-Fi networks at hotels, conference centers, and other hospitality venues around the world since early May 2026. Midnight Blizzard has previously been tied by the U.S. and U.K. governments to Russia’s Foreign Intelligence Service (the SVR).
ABC News picked up the story a few days later, noting that Microsoft didn’t say why it waited roughly three months to disclose the threat publicly, the company declined to comment on the timing when asked.
How the attack actually works
The campaign hinges on something almost every traveler encounters without a second thought: the captive portal, that login page hotels and airports use to get you onto their guest network. Microsoft says Storm-2945 has compromised the equipment and systems behind captive portals at multiple venues, giving the hackers the ability to intercept and redirect traffic from anyone who connects.
Here’s the general flow, as Microsoft and ABC News describe it:
- You connect to the guest Wi-Fi. Your device automatically performs a routine “connectivity check” in the background, this is the small ping every phone or laptop does to confirm it has real internet access.
- The hackers intercept that check. Instead of a normal response, compromised infrastructure serves up a fake prompt disguised as a legitimate system message.
- You’re shown a convincing fake update screen. These pop-ups mimic everyday software prompts, a Windows Update screen, a security scan, a browser update, a disk optimization tool, or similar. Microsoft catalogued several fake window types being used, including ones disguised as DirectX installers, antivirus scans, and network troubleshooting utilities.
- Following the prompt installs malware. If you click through and run what it asks, you install malicious software that can log keystrokes, capture screenshots, record audio and video, monitor your clipboard, steal saved browser passwords and cookies, and hand attackers a remote shell on your machine.
- In some cases, you’re redirected to a fake Microsoft sign-in page. This can trick you into handing over credentials that give attackers access to your Microsoft 365 account, including email and OneDrive.
Microsoft’s technical write-up goes further into the weeds, describing a Windows-based remote-access trojan and a separate PowerShell-based credential-stealing tool used in the campaign, along with a web-based control panel the operators use to manage infected devices. The company says it also found signs the attackers may be targeting Android devices with similar fake-update tactics, and that AI tools appear to have supported “a significant portion” of the operation.
Why hotels, specifically?
Microsoft and the threat-intelligence firm ReliaQuest, which first flagged part of this activity in July, believe the endgame is access to corporate travelers’ accounts. Business travelers are a high value target: they carry corporate laptops, hold access to sensitive company systems, and often let their guard down on the road in ways they wouldn’t at the office.
It’s also worth noting the scale implied here. Microsoft says it found “notable commonalities” in the equipment and management systems compromised across multiple, unrelated venues suggesting this isn’t a series of one-off break-ins at individual hotels, but possibly deeper access into shared infrastructure that many properties rely on.
How to protect yourself
The advice from Microsoft boils down to treating any public or hotel Wi-Fi as inherently untrustworthy, not because you’re doing anything wrong, but because you have no way to verify who’s actually running the network you just joined. Concretely:
- Use your phone’s hotspot or a cellular/eSIM data plan instead of hotel Wi-Fi whenever it’s practical. It’s harder for attackers to insert themselves into your traffic when you’re not sharing the venue’s network.
- Never install software prompted by a Wi-Fi login page. Legitimate operating system and browser updates don’t arrive as pop-ups on a hotel’s guest network. If a page tells you to run a script or download an installer to “verify” your connection, close it.
- Be suspicious of update or “verification” pop-ups in general especially anything asking you to open a command prompt, PowerShell, or similar tool and paste in a command. That’s a known social-engineering technique called ClickFix, and it’s a red flag regardless of how official the prompt looks.
- Turn on multi-factor authentication, and use a passkey where you can. Even if credentials get phished, a passkey or properly configured MFA makes it much harder for an attacker to actually get into your account.
- Think twice before giving hotels or venues unnecessary personal details when registering for guest Wi-Fi, Microsoft specifically flagged this as a way attackers can profile potential targets.
- If you’re traveling for work, ask your IT or security team whether your company has a managed travel router or VPN policy routing your connection through trusted infrastructure before it touches anything sensitive closes off a lot of this attack surface.
The bigger picture
CaptiveCrunch is a reminder that the weakest link in a lot of corporate security isn’t a firewall or a password, it’s the assumption that “connected” means “safe.” A captive portal login page feels routine precisely because we’ve all clicked through hundreds of them without incident. That familiarity is exactly what makes it useful cover for an espionage operation.
Microsoft’s advice, and the industry’s broader consensus, is straightforward: on the road, default to your own connection when you can, and treat any pop-up asking you to install or “fix” something as suspicious until proven otherwise, no matter how official it looks.