Microsoft Just Told Business Travelers to Stop Trusting Hotel Wi-Fi.

Microsoft is warning that hotel, airport and conference Wi-Fi networks are being hijacked by Russian state-linked attackers to steal Microsoft 365 logins and drop malware on laptops and phones. This isn’t the usual “public Wi-Fi is risky” advice.

In an advisory published on July 31, 2026, Microsoft Threat Intelligence said the compromises are widespread, they have been running since early May, and the target is business travelers specifically. If anyone on your team packs a laptop, this one matters.

We came across this story through Niagara This Week’s coverage of the warning. The technical details below come from Microsoft’s own advisory, which is worth a read if you’re the one responsible for IT at your company.

Here is our take on what it means for small and mid-sized businesses in Southern Ontario.

What Microsoft actually found

Microsoft calls the campaign CaptiveCrunch. It’s attributed to a group tracked as Storm-2945, which Microsoft assesses to be part of Midnight Blizzard. You might know that crew by its other names, APT29 or Cozy Bear, and it has been publicly linked to Russia’s foreign intelligence service.

The target is the captive portal. That’s the login page that pops up when you connect to guest Wi-Fi, the one asking for your room number or your email address before it lets you online. Microsoft says the attackers have been manipulating DNS and HTTP traffic on networks served by those portals so that a guest’s traffic runs through infrastructure the attackers control.

Victims get a prompt to download something, usually dressed up as a driver update, a browser patch, a certificate or a network troubleshooting tool. Install it and you’ve handed over remote access to the device.

Assume public and hospitality network infrastructure “might not be trustworthy,” and plan around that rather than hoping for the best.

If I have MFA, is my device safe?

Most people assume multi-factor authentication catches everything. On this campaign, it isn’t. Microsoft describes the attackers abusing device code and OAuth sign-in flows, which are the legitimate mechanisms that let you sign in to an app on one device by approving it on another.

That’s exactly why we keep pushing clients past the checkbox version of security. MFA is necessary. It just isn’t the whole plan, and campaigns like this are built specifically to go around it.

Where to watch out for Wi-Fi breaches in Ontario

Pearson is one of the largest airports we have access to in Ontario. But airports aren’t the only target of this attack.

Niagara Falls alone has thousands of hotel rooms, and there are conference centers, casinos and event venues across the Hamilton to Niagara corridor. If you operate one of those properties, your guest network is what Microsoft is describing as a target.

If a compromised account leads to a real risk of significant harm to someone’s personal information, you may be liable for any information that is leaked. We walk through what that actually requires in our compliance management services.

What to do before your team’s next trip

None of this requires a big project. Most of it is policy!

Make the hotspot the default, not the backup

Cellular data isn’t part of a compromised hotel network. Microsoft’s own top recommendation is private connectivity, and for most travelling staff a phone hotspot is enough. If your data plans don’t support it, that’s a cheaper fix than an incident response.

Do not install anything on guest Wi-Fi

No updates, no certificates, no “network agent,” no browser patch. A legitimate guest portal might ask for your email address and let you online. Anything asking for a download is the attack.

Tighten conditional access

Location-aware rules, compliant device requirements and phishing-resistant sign-in methods all make it harder for a bad-actor to get through. This is the kind of thing that gets configured once, and it’s a standard part of how we handle cybersecurity for small businesses.

Tell people how to report a bad feeling

If a device behaved strangely on a trip, you want to hear about it that day, not three weeks later. Give your team one number or one inbox and make it socially fine to use it for a false alarm. Our helpdesk support can respond to these concerns, and we would much rather check a laptop that turns out to be fine.

What do I do if my Wi-Fi is attacked?

If guest Wi-Fi is a service you provide, it’s now a target. Take a look at who actually administers the portal hardware, whether that firmware is current, whether guest traffic is properly segmented from your property management and payment systems, and whether anyone is watching that network at all. Our network services team does exactly this kind of review.

Frequently asked questions

Does a VPN protect me on hotel Wi-Fi?

A VPN helps, and you should use one, but it isn’t a complete answer here. A VPN protects your traffic in transit. It doesn’t stop you from approving a malicious sign-in code, and it doesn’t help if you install something the portal offered you before the VPN was up.

What is a captive portal?

A captive portal is the sign-in page that appears when you join a public network, before you get actual internet access. Hotels, airports, cafes and conference centers use them.

Should we ban public Wi-Fi for our employees?

For work devices and work accounts, that’s a reasonable policy if your data plans can handle it.

How do I know if a device was compromised on a trip?

Often you can’t tell by looking, which is the problem. Signs worth acting on include unexpected sign-in prompts, software you don’t remember installing, unfamiliar sign-in alerts on your Microsoft account, or a device running hot and slow after a trip. If something feels off, get the device checked rather than waiting to see.

We’re a small business. Are we really a target?

For this campaign, the targeting is about where you go, not how big you are. A ten-person firm with a director attending a conference is as reachable as a large enterprise. And smaller organizations usually have fewer controls in place to catch it afterward.

What do I do now?

Treat guest Wi-Fi as hostile. Use a hotspot. Never install anything a login page offers you. And don’t assume MFA has this covered, because this campaign was designed by people who knew you would assume that.

If you’re not sure how exposed your travelling staff are, that’s a conversation worth having before the next trip rather than after it. Get in touch with us and we’ll walk through it with you. Don’t go alone.