Advertiser Disclosure: Eye of the Flyer, a division of Chatterbox Entertainment, Inc., is part of an affiliate sales network and may earn compensation when a customer clicks on a link, when an application is approved, or when an account is opened. This relationship may impact how and where links appear on this site. This site does not include all financial companies or all available financial offers. Opinions, reviews, analyses & recommendations are the author’s alone, and have not been reviewed, endorsed, or approved by any of these entities. Reader comments reflect the views of the individuals who wrote them, are not reviewed or endorsed by Eye of the Flyer or by any advertiser, and should not be treated as advice. Some links on this page are affiliate or referral links. We may receive a commission or referral bonus for purchases or successful applications made during shopping sessions or signups initiated from clicking those links.
Before you log on to the Wi-Fi at your hotel — or the airport, or that conference you’re attending — read this. Russian state-backed hackers are compromising hotel and conference Wi-Fi networks around the world, using fake login pages and phony software updates to load malware onto travelers’ laptops, according to a warning Microsoft published Friday. If you travel — and if you’re reading this site, chances are you do — the fix costs you almost nothing. The consequences of skipping it? Maybe considerably more.
I can already hear the comments: CLICKBAIT! You’re just trying to scare people! Or the chances of this happening are so low! Sure. Every security warning sounds paranoid — right up until you’re the one changing every password you own from a hotel lobby. I’d rather you roll your eyes at me now than do that later.
What’s Actually Happening
Microsoft Threat Intelligence says a campaign it’s calling “CaptiveCrunch” has been active since at least May. The group behind it — a sub-cluster of Midnight Blizzard, the Russian espionage outfit you may know by its cuddlier nicknames APT29 or Cozy Bear — isn’t setting up fake “Free Hotel WiFi” networks. That’s the part that makes this nastier than the usual airport-lounge scaremongering. They’re compromising the legitimate hotel network — specifically the captive portal, that login page you tap through when you connect.
Once you’re on a compromised network, you might get redirected to a very convincing Microsoft 365 sign-in page, or prompted to install a “Windows update” or “browser update” that is, in fact, malware. Microsoft says the fake prompts include a Windows Update screen (“Working on updates… Don’t turn off your computer”), a fake Windows Security virus scan, a browser update prompt, and even a fake Google “Verify it’s you” security check.
The malware itself can steal your passwords, session cookies, and files — and log your keystrokes and activate your camera and microphone. Android devices have been targeted too, so this isn’t just a laptop problem.
The campaign has mostly targeted business travelers, government folks, and similar high-value types in the U.S. and Europe. But security researchers quoted in coverage of the report note the same technique works against any captive-portal network — airports included. You know, those places we all spend an unreasonable amount of our lives.
How to Protect Yourself
Here’s the good news: the defenses are simple, and you’ve heard most of them before. Now you have a state-sponsored espionage campaign as motivation to actually do them.
1. Use your phone’s hotspot instead of public Wi-Fi. This is Microsoft’s own top recommendation, and it’s what I do. I run my hotspot off my iPhone. (We have a Spectrum business wireless plan with unlimited data. At least in our area, Spectrum rides on Verizon’s network, and switching saved us about $150 each month.) Your phone’s hotspot is a private network. Like some politicians on both sides of the aisle, your hotel’s captive portal could be a Russian intelligence asset. Choose accordingly.
2. Never install a software update from a Wi-Fi network’s prompt. Ever. Real Windows, macOS, and browser updates come from the operating system itself — not from a pop-up that appears when you connect to the Marriott’s Wi-Fi. If a captive portal asks you to install anything — an update, a certificate, a “network troubleshooting tool” — disconnect and walk away.
3. If you must use public Wi-Fi, use a VPN. When the hotspot isn’t an option — poor signal, data throttling, a hotel built like a Faraday cage — I use Proton VPN. A VPN encrypts your traffic so that even on a compromised network, what you’re doing isn’t readable. It won’t save you if you voluntarily install malware (see rule #2), but it dramatically shrinks what a hostile network can see and manipulate. (Disclosure: that’s my referral link — I may earn subscription credits if you sign up. It’s also genuinely what’s on my devices.)
4. Look twice at login pages. If the hotel Wi-Fi suddenly wants your Microsoft 365 credentials, ask yourself why the Hampton Inn needs those. (It doesn’t.)
5. Get a Mac. (I’m kidding — Macs aren’t impervious, and this particular malware happens to target Windows and Android. But they are the best.)
Final Approach
Here’s the thought I can’t shake: premium travel rewards cards will hand you statement credits for CLEAR+, Global Entry, TSA PreCheck, airport lounges, rideshares, streaming services, and — in at least one case — event tickets. All in the name of making travel smoother and safer. Meanwhile, the single most common digital risk a traveler faces is the hotel Wi-Fi network, and as far as I’m aware, no major issuer offers a VPN credit.
A VPN subscription runs $50–$100 a year — rounding-error money next to a $300 travel credit. It’s travel-relevant, it’s sticky (people renew security products), and “we protect you on the road” is exactly the brand story premium cards are trying to tell. If you’re an issuer product manager reading this: it’s a free idea. You’re welcome.
Until that happens, the protection is on us: hotspot first, VPN second, and never — never — install an update because a hotel login page asked nicely. If you’re deciding which travel rewards card earns a spot in your wallet for your next trip, protections and credits are worth weighing right alongside the points.
Advertiser Disclosure: Eye of the Flyer, a division of Chatterbox Entertainment, Inc., is part of an affiliate sales network and may earn compensation when a customer clicks on a link, when an application is approved, or when an account is opened. This relationship may impact how and where links appear on this site. This site does not include all financial companies or all available financial offers. Opinions, reviews, analyses & recommendations are the author’s alone, and have not been reviewed, endorsed, or approved by any of these entities. Reader comments reflect the views of the individuals who wrote them, are not reviewed or endorsed by Eye of the Flyer or by any advertiser, and should not be treated as advice. Some links on this page are affiliate or referral links. We may receive a commission or referral bonus for purchases or successful applications made during shopping sessions or signups initiated from clicking those links.









Any related issues with using airline wifi while in air?
Hi, Cecilia. I haven’t heard anything (yet).
Using your phone’s cell service as a mobile hotspot is not completely safe either. Just Google IMSI catcher devices, like the StingRay. It’s probably best to always establish a VPN connection before authenticating anything, whether it’s a cell connection or WiFi.
Many home routers support VPN servers. For example, many TP-Link routers support OpenVPN and WireGuard VPN servers. I have my home router set up with WireGuard, and I have the WireGuard client installed on all my devices. Doing this is completely free.
When I used to travel to China every year, this worked better for me than commercial VPNs, which are typically blocked. Also, some countries, such as India, have such stringent VPN regulations that commercial VPN providers have pulled out, such as NordVPN, Proton VPN, ExpressVPN, and Surfshark. However, a VPN connection to your home router should work fine.
Another good option is a travel router, such as the travel routers made by GL.iNet. Travel routers typically have VPN clients, so you can create your own private WiFi network that is secure. If the hotel has wired Ethernet, that’s better than using the hotel’s WiFi since it is easy for a hacker to create a WiFi hotspot that mimics the hotel’s WiFi.