← Blog

When the hotel Wi-Fi is the attack

Tenant Strike3 min read

Microsoft has tied a campaign to Russian intelligence that takes over Wi-Fi at hotels and conference centers, then serves fake software updates and fake Microsoft sign-in pages. Three rules for anyone who travels.

Someone from your company checks into a hotel for a conference, joins the guest Wi-Fi, and gets a prompt to install a browser update. They install it. There was no phishing email and nothing looked wrong — the network itself was the attack.

Microsoft published that campaign on July 31 and calls it CaptiveCrunch. It attributes the activity to a group inside Midnight Blizzard, which the US and UK governments have tied to Russia's foreign intelligence service. The security firm ReliaQuest reported the same activity a week earlier. Microsoft dates the campaign to February and the Wi-Fi tampering itself to May, at hotels, conference centers and other shared venues across several countries.

Why simply joining is enough

When your laptop joins a network, it asks that network where to find things — including the address of Microsoft's sign-in page. The network answers, and your laptop believes the answer. That isn't a flaw. It's how joining a network has always worked.

Take over the venue's Wi-Fi gateway and you get to answer instead. One compromised box covers every guest for the day, and it has no idea who any of them are.

Getting into that box is usually mundane: an admin screen reachable from the internet, sitting behind a weak or reused password. The hotel's bad password becomes your Microsoft 365 problem.

What the guest actually sees

Two things, depending on the day.

An update that isn't one. Your laptop quietly checks whether a new network is real, and the attackers answer that check with a page telling you to update Windows, your browser, or a security tool. Install it and you get remote-access malware that stays put, plus a second piece that collects saved browser passwords, Microsoft 365 sign-in tokens, and the Wi-Fi passwords for every other network that laptop remembers.

A Microsoft sign-in page that isn't one. Lookalike domains take the password. Sometimes they skip the password altogether and push you through device code sign-in — a real Microsoft feature — where you approve a sign-in that turns out to be the attacker's. Multi-factor authentication doesn't help, because you passed it for them. We covered that trick in July; blocking it is a ten-minute change.

Three rules that fit on a card

Tether to your phone. On hotel, airport or conference Wi-Fi, a work laptop should use the phone's cellular connection instead. That bypasses the compromised gateway entirely. It's Microsoft's own first recommendation, and on most unlimited plans it costs nothing.

Never install an update a network offers you. Real updates come from Windows Update or from the app itself — never from a page that appears just after you join Wi-Fi. This one rule stops the malware half of the campaign.

Ask your IT provider to block device code sign-in. Say it by name: "block the device code authentication flow in Entra ID." Most small businesses never use the feature.

If someone has already typed their password into a page they weren't sure about, change it and have whoever administers your Microsoft 365 sign that account out of all sessions — stolen tokens outlive the old password, so the sign-out matters as much as the reset. If they installed something, the laptop needs attention too, not just the account.

Two of those three rules are things you say out loud before a trip. The third is a setting — and settings are the kind of thing nobody checks until an incident makes them. Whether device code sign-in is still open in your tenant is one of the things Tenant Strike looks at: a read-only scan that grades your Microsoft 365 setup and shows the exact fix for anything it finds. It can see settings; it can't change them.

The uncomfortable part of this story is that the employee who joins that hotel Wi-Fi did nothing wrong. Which is why as much of the defense as possible belongs in settings closed before they pack — and the rest in a rule simple enough to follow while tired, in a lobby, at 9pm.


Sources: Microsoft Threat Intelligence, ReliaQuest

AI-researched from public sources. We label AI-assisted writing — see our trust page.

See your own risk

Want this for your own Microsoft cloud?

Tenant Strike runs 130+ read-only checks across Microsoft 365 and Azure and hands you a plain-English fix for every gap. Start a 7-day Pro trial — no credit card.