Jessica Entwistle
August 3 2026
Microsoft Security Blog reports that Storm-2945, a sub-cluster of the Russian threat actor Midnight Blizzard, has been compromising the sign-in portals of hospitality-related organisations such as hotels since May 2026 in an operation called CaptiveCrunch. The attackers target the captive portal systems that travellers use to authenticate and access Wi-Fi in hotels, conference centres, and similar venues. Once compromised, these portals are used to deliver malware to connecting devices and to harvest credentials from users who authenticate through the portal. The campaign has been observed targeting travellers worldwide, with a focus on individuals who are likely to be of intelligence interest.
This incident highlights the operational security risks associated with business travel and the use of third-party network infrastructure. Hotel Wi-Fi portals are trusted by default by most users, and the authentication process often involves entering corporate email addresses, accepting certificates, or downloading configuration profiles. When these portals are compromised, they become a vector for credential theft, device compromise, and lateral movement into corporate networks once the traveller reconnects to their organisation's systems. This is particularly relevant for organisations with mobile workforces, international operations, or employees who frequently travel for client meetings, conferences, or site visits.
The attack demonstrates how threat actors are exploiting the trust relationships and operational dependencies that exist in everyday business activities, turning routine travel into a security risk. For UK businesses, this is a reminder that security controls need to extend beyond the corporate network perimeter and account for the risks that employees face when working remotely, travelling internationally, or connecting to untrusted infrastructure. The incident also highlights the importance of endpoint protection, credential hygiene, and user awareness as layers of defence that remain effective even when network-level controls are bypassed or unavailable.
UK businesses with travelling employees should review travel security guidance, endpoint protection policies, and the controls in place to protect devices and credentials when staff connect to untrusted networks. Consider whether your organisation provides clear advice on the risks of public Wi-Fi, whether VPNs or zero-trust network access tools are mandated for remote work, and whether endpoint detection and response capabilities are active on devices used outside the corporate network. Review whether multi-factor authentication is enforced for all corporate accounts, whether password management tools are provided and used, and whether employees understand the risks of entering credentials into unfamiliar portals or accepting unexpected certificates. Consider whether your organisation has a process for reporting suspicious network behaviour, unusual authentication requests, or potential device compromise while travelling. Ensure that security awareness training includes practical guidance on travel security, including how to recognise compromised portals, how to protect devices and credentials, and what to do if a device is suspected of being compromised.
Source: Microsoft Security Blog