Public Wi-Fi Faces Growing Cyber Threats
Microsoft has warned business travellers about CaptiveCrunch, a cyberespionage campaign targeting hotel, airport, conference, and other public Wi-Fi networks.
The campaign reportedly exploits captive portals—the login pages users encounter before joining guest Wi-Fi—to redirect victims to fraudulent Microsoft sign-in pages and fake software-update prompts.
Attackers can then steal credentials or deliver malware, creating significant risks for executives and employees accessing corporate systems while travelling.
The campaign has reportedly been associated with Storm-2945, described as linked to the broader Russian state-aligned threat ecosystem.
The incident demonstrates why public Wi-Fi should increasingly be treated as untrusted infrastructure.
Travellers should avoid entering sensitive credentials, downloading software, or accessing critical corporate applications over unknown networks, using trusted mobile hotspots or secured connections whenever possible.
Enterprises should strengthen defenses through phishing-resistant authentication such as passkeys, Zero Trust access controls, endpoint monitoring, and tighter restrictions on device-code authentication.
As attackers target the connectivity layer itself, travel cybersecurity must extend beyond protecting devices to verifying the networks employees use.
See What’s Next in Tech With the Fast Forward Newsletter
Tweets From @varindiamag
Nothing to see here - yet
When they Tweet, their Tweets will show up here.




