Microsoft’s Threat Intelligence team has issued a global alert regarding a cyberattack campaign known as 'CaptiveCrunch,' which targets hotel and hospitality Wi-Fi networks. Attributed to the hacker group Storm-2945, the campaign has been active since May and focuses on compromising corporate travelers by manipulating traffic through captive portal screens at hotels and conference centers worldwide.
Attackers redirect guests to fraudulent portals, prompting them to download fake software updates or enter credentials. Once a device is compromised, hackers can record audio and video, capture keystrokes, and access sensitive corporate data. Common deceptive prompts include fake Windows updates, security scans, and network diagnostic tools.
Microsoft advises travelers to use personal cellular hotspots or encrypted connections instead of public Wi-Fi. Users should ignore unexpected update prompts while connected to hospitality networks, and companies are encouraged to restrict the sensitive information employees access while traveling.

