Travelers are being warned about a hotel WiFi hack that uses convincing pop-up messages and fake login pages to infect devices and steal personal information.
Microsoft said it had identified a widespread cyber campaign targeting wireless networks operated by hotels and other hospitality businesses. The operation, known as CaptiveCrunch, reportedly began affecting organizations in May 2026.
According to Microsoft, the attackers may have links to Russia. The campaign is designed to exploit the moment travelers connect their laptops or other devices to hotel internet services.
Hotel WiFi Hack Uses Fake Pop-Ups
The hotel WiFi hack works by displaying malicious prompts shortly after a person connects to a compromised network.
These messages may look like legitimate Windows Update notifications, system alerts or other familiar software prompts. However, following the instructions can cause the user to download harmful files.
The timing makes the attack especially dangerous. Travelers often expect to see a browser window, login portal or connection message when joining public WiFi. Attackers can take advantage of that expectation by presenting a fake request that appears to be part of the normal connection process.
Users should be particularly cautious when an unexpected software update appears immediately after connecting to a hotel network.
Malware Can Capture Passwords and Keystrokes
Microsoft warned that the malicious software used in the campaign could give attackers access to sensitive information stored or entered on a device.
Once installed, the malware may allow hackers to capture screenshots and record keystrokes. This could expose passwords, private messages, financial information and other personal details.
In some cases, the attackers may also gain the ability to control a compromised device remotely.
The campaign reportedly uses fake login screens as well. These pages may ask travelers to enter an email address, password or other account details before accessing the internet.
Instead of connecting the user safely, the page can send those details directly to the hackers.
Why Hotel Networks Are Attractive Targets
Hotel WiFi is convenient, especially for people traveling for work or trying to avoid costly mobile data charges. However, hospitality networks often serve large numbers of guests using many different types of devices.
Travelers may also be less cautious when they are tired, rushing to join a meeting or trying to complete a task shortly after arriving at a hotel.
Captive portals add another opportunity for attackers. These are the pages that appear when users first connect to public WiFi and are asked to accept terms, enter a room number or provide other information.
A compromised network can make malicious prompts appear to be part of this familiar process.
Use a Mobile Hotspot When Possible
Microsoft advised travelers to use a more private internet connection, such as a mobile hotspot, instead of hotel WiFi whenever possible.
A hotspot allows a laptop or tablet to connect through a mobile phone’s cellular data connection. This can reduce exposure to compromised public wireless networks.
Travelers who must use hotel WiFi should carefully inspect every message that appears after connecting.
An unexpected update notification should be treated with suspicion, particularly when it appears immediately after joining the network.
How to Recognize the Hotel WiFi Hack
The hotel WiFi hack may be difficult to identify because the pop-ups are designed to resemble genuine system messages.
Warning signs may include an update request that appears at an unusual time, a prompt to download a file before using the internet or a login page requesting more information than expected.
Travelers should avoid downloading software or files from prompts that appear through a hotel network.
A genuine operating-system update should normally be managed through the device’s official settings rather than through a pop-up generated immediately after connecting to public WiFi.
Users should also be cautious about entering personal email passwords or other sensitive account information into unfamiliar network login pages.
What Travelers Should Remember
Public WiFi networks can be useful, but they should not automatically be trusted. Microsoft’s CaptiveCrunch warning shows how attackers can turn an ordinary hotel connection into a route for malware and account theft.
The safest option is to use a private mobile hotspot when one is available.
When hotel WiFi is necessary, travelers should ignore unexpected update requests, avoid unfamiliar downloads and closely examine any login screen requesting personal information.
A few seconds of caution could prevent hackers from capturing passwords, monitoring activity or taking control of a connected device.








