Russian Hackers Infiltrated Hotel WiFi Networks
The state-linked operation redirected travelers to malicious portals to deploy infostealer malware.
Updated on Oct. 6, 2026 in Cybersecurity

Live Poll
Do you trust the security of public WiFi networks when traveling at hotels or airports?
State-linked hackers known as Midnight Blizzard targeted traveler credentials by compromising three North American managed service providers. The campaign, dubbed Captive Crunch, remained active throughout the summer of 2026.
Why it matters
By compromising infrastructure at hotels, airports, and conference centers, the attackers targeted a high volume of transient users to harvest credentials and monitor traffic. The campaign highlights the vulnerability of third-party network management systems in public spaces.
Microsoft first detected DNS tampering in February 2026. Attackers successfully compromised three distinct North American managed service providers to execute the campaign.
The players
Midnight Blizzard
A state-linked hacking group known for sophisticated persistent threats and network infiltration.
Microsoft
A global technology company that provides enterprise security services and threat intelligence.
The details
The attackers utilized a method known as ClickFix to trick users into executing malicious downloads disguised as software updates or CAPTCHA prompts. By manipulating network traffic to redirect users to spoofed captive portals, they effectively deployed infostealer and remote access malware onto victim devices. This technique leverages the inherent trust users place in hotel or airport connectivity to facilitate unauthorized access.
Timeline
February 2026: Microsoft first detected the DNS tampering activity.
June 2026: The Captive Crunch activity was identified as ongoing since this month.
July 23, 2026: A new attack wave linked to a second managed service provider began.
July 24, 2026: A third attack wave linked to a different managed service provider began.
Summer 2026: Three North American companies managing WiFi networks were compromised.
The Tech Race
This campaign underscores the escalating risk associated with third-party software and infrastructure providers in a globalized digital economy. It follows the pattern of systemic failures seen in the 2024 global CrowdStrike outage by exploiting centralized access points.
Travelers using hotel, airport, and casino WiFi face elevated risks of credential theft and device infection. Security experts recommend using a virtual private network (VPN) to encrypt traffic when connecting to public networks managed by third-party service providers.
The takeaway
Travelers should treat public captive portals with high skepticism and avoid clicking on unexpected software prompts or updates. Monitor for future security advisories regarding the specific managed service providers identified in the July 2026 waves.
Further reading
For broader trends in network security and infrastructure threats, explore our Cybersecurity section.
Live Poll
Do you trust the security of public WiFi networks when traveling at hotels or airports?






