Search This Blog

Powered by Blogger.

Blog Archive

Labels

Footer About

Footer About

Labels

Showing posts with label Hotel Wi-Fi Attacks. Show all posts

Think Hotel Wi-Fi Is Safe? Hackers Have Several Ways to Prove You Wrong

 



For many travelers, connecting to hotel Wi-Fi is one of the first things they do after checking in. But while some guests use the network for banking and work, others avoid sensitive activity unless they are connected through a VPN.

So, how safe is hotel Wi-Fi?

Cybersecurity experts say the answer is more nuanced than simply calling public Wi-Fi dangerous. Modern encryption has reduced many of the risks associated with public networks, but hotel Wi-Fi can still expose travelers to rogue networks, phishing attacks, poorly configured infrastructure and vulnerable devices.

In many cases, the biggest risk may not be the network itself, but how the user connects to and behaves on it.


The first risk can come from a fake network

Security analyst Udaya Vemuri advises travelers to be cautious about joining a network simply because its name appears to belong to the hotel.

Attackers can create fake Wi-Fi networks with names almost identical to legitimate hotel networks. The technique, known as an "evil twin" attack, can trick guests into connecting to an attacker-controlled access point.

The FBI's Internet Crime Complaint Center warned about this threat in a 2020 advisory, noting that criminals can create networks resembling legitimate hotel Wi-Fi and potentially monitor activity or redirect victims to fraudulent login pages. The agency also warned that hotel guests have limited control over the security of the infrastructure they are using, which may prioritize convenience over stronger security practices.

Travelers should therefore confirm the exact Wi-Fi name with hotel staff before connecting rather than selecting the network that merely looks familiar.


Simply sharing a network does not mean you are compromised

Dahvid Schloss, chief operating officer of cybersecurity firm Suzu Labs and a former government hacker who has security-tested hotel chains, takes a less alarmist view.

Schloss compares hotel Wi-Fi with other public networks, such as those in coffee shops. In his assessment, the likelihood of being attacked simply because another malicious user is connected to the same network is low.

That distinction matters because the common image of hackers automatically reading passwords from public Wi-Fi is outdated.

The Federal Trade Commission says most websites now use encryption, meaning information sent between a device and a legitimate website is generally protected even when the underlying network is public. HTTPS can therefore provide substantial protection against traffic interception.

However, HTTPS does not prove that a website is legitimate. Attackers can create encrypted fraudulent websites and use phishing or redirection to persuade victims to submit credentials.

This means a traveler can still be exposed even when the connection itself appears encrypted.


Fake hotel portals can steal credentials

Hotels commonly use captive portals that redirect guests to a webpage after they connect to Wi-Fi. These pages may request a room number, surname, email address or access code.

Because travelers expect this process, attackers can imitate it.

A rogue network may display a fake hotel login page or redirect users to a fraudulent Microsoft 365, email or banking page. In such cases, the attacker does not necessarily need to break encryption. The victim may simply be tricked into providing the information.

This makes phishing and social engineering an important part of the hotel Wi-Fi threat.


Network security is not a perfect guarantee

Recent research also shows why travelers should not assume that network-level protections make public Wi-Fi completely secure.

Researchers at the University of California, Riverside reported in February 2026 that weaknesses in Wi-Fi client isolation can, under certain conditions, allow attackers to bypass protections designed to prevent devices on the same network from interacting with one another.

Their AirSnitch research demonstrated techniques that could potentially allow an attacker to intercept or manipulate traffic despite client isolation.

The findings do not mean every hotel network is vulnerable, but they reinforce an important point: users should not rely entirely on the security mechanisms implemented by a public network.


Your device can be the weakest link

Both experts place considerable emphasis on user behavior.

Schloss argues that laptops can be particularly vulnerable to poor security habits because they are frequently used to download files, install software and access corporate systems. Smartphones are not immune, but their operating systems often impose stronger application restrictions.

The FBI recommends updating operating systems and applications before travel, keeping security software current, backing up important data, disabling Bluetooth when unnecessary and preventing devices from automatically reconnecting to public networks.

Automatic reconnection is particularly important because a device may join a previously saved network without the user consciously verifying that it is legitimate.

Browser warnings should also never be ignored. A certificate warning, unexpected redirect or request to install software can indicate that something is wrong with the connection or destination.


Use cellular data for sensitive activity

Vemuri takes a more cautious approach when handling sensitive information. For banking, work systems and other private activity, he uses a mobile hotspot instead of hotel Wi-Fi. When hotel Wi-Fi is unavoidable, he keeps devices updated, enables multifactor authentication and avoids sensitive tasks.

The FBI similarly recommends using a phone's hotspot instead of hotel Wi-Fi when possible, particularly for sensitive activity and telework.

A cellular hotspot is not completely immune to cyber threats, but it removes the user from the hotel's shared wireless environment and reduces exposure to risks associated with public Wi-Fi.


A VPN and MFA can add protection

For travelers who need to use hotel Wi-Fi, a reputable VPN can provide another layer of security by encrypting traffic between the device and the VPN provider. The FBI recommends reputable VPNs for telework over hotel Wi-Fi.

A VPN is not a substitute for other security measures, however. It cannot prevent phishing, malware downloads or users from voluntarily entering credentials into fraudulent websites.

Multifactor authentication can limit the damage if a password is compromised. The FBI recommends MFA for sensitive accounts and advises users to enable login notifications so suspicious activity can be detected quickly.

Travelers should configure MFA before leaving home rather than waiting until they are already on the road.


What travelers should do

Before connecting to hotel Wi-Fi, users should:

  1. Confirm the legitimate network name with hotel staff.
  2. Update their operating system, browser and applications.
  3. Disable automatic connection to public networks.
  4. Enable MFA and account security alerts.
  5. Use a cellular hotspot for banking and highly sensitive activity where possible.
  6. Use a reputable VPN for sensitive work when hotel Wi-Fi is unavoidable.
  7. Verify the website address and HTTPS before entering credentials.
  8. Avoid unfamiliar downloads or software updates prompted by Wi-Fi portals.
  9. Disable Bluetooth when it is not needed.
  10. Never bypass browser security warnings.


So, is hotel Wi-Fi safe?

Hotel Wi-Fi is not automatically dangerous, but it should not be treated as a trusted network either.

Simply sharing a network with an attacker does not mean a modern device will automatically be compromised, particularly when legitimate services use encryption. At the same time, rogue access points, fake captive portals, phishing, vulnerable devices and weaknesses in network isolation can create opportunities for attackers.

For routine browsing, an updated device using legitimate HTTPS websites can be reasonably protected. For banking, corporate systems and other highly sensitive activity, using a cellular hotspot remains the more cautious option.

The practical rule for travelers is simple: do not panic about hotel Wi-Fi, but do not trust it blindly either. Verify the network, secure your devices and accounts, and keep sensitive activity off shared networks whenever possible.

Hotel Wi-Fi Attacks Linked to Russian Hackers Target Microsoft 365 Accounts With Custom Malware


In a sophisticated cyber campaign carried out by attackers using hotel and conference Wi-Fi networks, Microsoft uncovered the theft of Microsoft 365 credentials, and the deployment of custom malware. As reported by the company, CaptiveCrunch was carried out by Storm-2945, a subgroup of the Russian state-backed threat actor Midnight Blizzard (APT29). 

There have been several incidents of Wi-Fi networks being affected by the campaign in hotels, conference centers, and other venues that use captive portals. In the company's view, corporate travelers are the primary targets, since compromise of their Microsoft 365 accounts would allow attackers access to sensitive company information. 

A related phishing campaign has been conducted since at least May 2026, while the campaign is believed to have been active since then. Microsoft's investigation indicates that the attackers compromised shared network infrastructure used by hospitality Wi-Fi providers, allowing them to manipulate DNS and HTTP traffic. Using this technique, they were able to redirect users to fraudulent Microsoft 365 login pages, phishing portals containing device codes, or fake software update screens when connecting to hotel Wi-Fi. 

It is believed that the attackers gained access to infrastructure shared across multiple captive portal deployments, rather than isolated compromises at individual hotels, allowing the campaign to target multiple hospitality locations without having to target each venue individually. 

The attacks were carried out by CornFlake and ChocoShell malware families that had previously been undocumented. As a Go-based remote access trojan (RAT), CornFlake provides long-term access to infected systems by allowing attackers to execute commands remotely, log data, capture screenshots, steal credentials from websites, steal session tokens from Microsoft 365, monitor clipboards, and exfiltrate data. 

A fake Windows update or security scan screen is displayed during the installation process of the malware to avoid suspicion. Several persistence mechanisms are also established to survive system reboots. 

In addition, Microsoft noted that CornFlake provides secure command-and-control communication through modern cryptographic techniques, as well as support for dynamic reconfiguration, which allows attackers to modify infrastructure and targets without redeploying the malware. Further, the RAT utilizes multiple persistence mechanisms in order to remain active despite the removal of one method by security tools. 

ChocoShell is a PowerShell credential stealer that targets cookie files, passwords, Microsoft 365 tokens, and stored Wi-Fi credentials stored in memory. Additionally, Microsoft discovered a management panel controlled by attackers, dubbed FruitStone, that allowed administrators to remotely manage compromised devices, execute PowerShell commands, browse files, and capture screenshots and keystrokes. 

The malware has been identified as targeting access and refresh tokens for Microsoft 365 and Azure Active Directory, thereby allowing attackers to potentially hijack enterprise sessions without requiring users to enter their credentials again. Using ClickFix social engineering techniques, researchers observed fake updates to browsers and operating systems that tricked users into installing malware through these updates. 

Through the same infrastructure, attackers have attempted to distribute malicious Android APK files as well. Amid the campaign, Microsoft observed the scheme expanding to include Microsoft Entra device code phishing, in which the victims are tricked into completing a legitimate Microsoft authentication process that unknowingly allows the attackers' session to be authorized instead of their own. 

Upon analyzing both malware families, Microsoft believes artificial intelligence tools likely contributed to their development as analysts identified extensive AI-generated comments throughout the source code, demonstrating an increasing trend in malware development by threat actors incorporating AI into their code.

The Microsoft team recommends that users consider hotel and conference Wi-Fi networks to be untrustworthy, use mobile or managed network connections whenever possible, avoid installing software provided through captive portals, and use phishing-resistant authentication methods such as passkeys and multi-factor authentication whenever possible to reduce the risk of compromise. 

The organization is also advised to disable Microsoft Entra device code authentication where it is not necessary and to avoid using corporate credentials when registering for guest Wi-Fi services. Furthermore, security experts advise against registering for guest Wi-Fi services using company email addresses, since this may expose enterprise identities to targeted phishing attempts. 

Using trusted public Wi-Fi networks for cyber-espionage is an extremely dangerous practice. As attackers continue to perfect phishing and malware techniques, organizations and travelers alike must take additional precautions when connecting to public networks and implement stronger authentication measures.