Microsoft Warns Russian Hackers Are Compromising Hotel Wi-Fi to Steal Credentials
Microsoft identified Russian state-backed hackers exploiting hotel Wi-Fi networks to steal credentials and hijack devices. Here is what traveling employees need to know.

Microsoft published a threat intelligence advisory warning that Russian state-sponsored hackers have been compromising hotel Wi-Fi networks to steal credentials and remotely take control of guest devices. The campaign targets business travelers connecting to hotel networks during conferences, client visits, and corporate travel, and it has been active across multiple countries.
If your employees travel for work, this affects you directly. Every hotel stay is now a potential entry point into your corporate environment.
How the Attack Works
The threat actors, tracked by Microsoft as part of the GRU-affiliated group commonly known as APT28 or Fancy Bear, are targeting the Wi-Fi infrastructure at hotels rather than attacking individual devices one at a time. By compromising the hotel’s network equipment, they can intercept traffic from every connected guest.
Once an employee connects to a compromised hotel Wi-Fi network, the attackers can capture login credentials transmitted over the network, inject malicious content into unencrypted web traffic, and exploit vulnerabilities in the device itself. The technique is particularly effective because hotel Wi-Fi networks are inherently trusted by most users. Your employees connect, open their laptops, and start working without a second thought.
What makes this campaign different from typical public Wi-Fi risks is the scale and persistence. These aren’t opportunistic attackers sitting in a lobby with a rogue access point. They are compromising the hotel’s actual network infrastructure, which means the malicious network looks completely legitimate. The network name matches what the front desk provides. The captive portal looks normal. There’s no obvious sign anything is wrong.
Why This Matters for SMBs, Not Just Government Targets
Russian state-sponsored groups have historically focused on government agencies, defense contractors, and large enterprises. But hotel Wi-Fi attacks don’t discriminate by target. When APT28 compromises a hotel network, they collect credentials from every guest who connects, including the sales director from a 200-person company who checked in for a trade show.
Stolen credentials from a business traveler give attackers a foothold into your Microsoft 365 tenant, VPN, or internal applications. From there, the playbook is the same one we’ve covered in posts about credential theft and ransomware and infostealers bypassing MFA: lateral movement, privilege escalation, and data exfiltration or ransomware deployment.
Your company doesn’t need to be a high-value espionage target. It just needs one employee connecting to the wrong hotel network.
What Your Employees Should Do When Traveling
Share these rules with anyone who travels for work. Keep it short and direct.
Use your phone’s hotspot instead of hotel Wi-Fi. A cellular connection doesn’t route through the hotel’s compromised infrastructure. If your company provides mobile hotspot devices, require their use for work tasks while traveling.
If you must use hotel Wi-Fi, connect through a VPN first. A properly configured VPN encrypts all traffic between the device and your corporate network, preventing attackers on the hotel network from intercepting credentials or injecting content. Make sure employees know how to connect to the VPN before they leave the office, not when they’re standing in a hotel lobby.
Do not log into corporate accounts on hotel business center computers. Shared terminals in hotel lobbies and business centers are even riskier than Wi-Fi. Keyloggers, cached sessions, and compromised browsers are common. Use only company-managed devices for work.
Report anything unusual immediately. If a device behaves oddly after connecting to hotel Wi-Fi, such as unexpected MFA prompts, new browser extensions, or unfamiliar login notifications, contact your IT team before doing anything else. Early detection matters. A compromised device caught on day one is containable. A compromised device that goes unnoticed for two weeks is a breach.
What Your IT Team Should Do This Week
Technical controls reduce your exposure regardless of whether employees follow the rules perfectly.
Enforce VPN usage on managed devices. Configure your endpoint management to require VPN connection before allowing access to corporate resources when the device is on an untrusted network. Microsoft Intune and most MDM platforms support this with conditional access policies. Block split tunneling so all traffic routes through the VPN, not just traffic destined for internal resources.
Enable phishing-resistant MFA. SMS and push-based MFA are better than nothing, but they can be bypassed through real-time phishing proxies on a compromised network. FIDO2 security keys or passkeys are resistant to these attacks because the authentication is bound to the legitimate domain. If full FIDO2 rollout isn’t feasible yet, at minimum enable number matching on push notifications to block blind-approve attacks.
Review sign-in logs for travel anomalies. Check Azure AD (Entra ID) sign-in logs for logins from unexpected locations, especially hotel IP ranges or foreign countries your employees don’t visit. Configure risk-based conditional access to require step-up authentication when a sign-in comes from a new location or an unfamiliar device. Our post on admin access audits covers how to set up these monitoring patterns.
Confirm endpoint protection is active and updated on all laptops that leave the office. Devices that travel are the most likely to have stale antivirus definitions or lapsed endpoint detection agent connections. Run a compliance check on your fleet before the next round of business travel.
Segment your network so a compromised traveler’s device can’t move laterally. When an employee returns from a trip and plugs back into the office network, a compromised laptop shouldn’t have direct access to file servers, admin consoles, or other sensitive systems. Network segmentation and zero trust policies limit the blast radius.
The Bigger Picture: Public Networks Are Hostile Territory
Hotel Wi-Fi has always been risky, but this Microsoft warning elevates it from “general best practice” to “active, state-sponsored threat.” The difference between a theoretical risk and an observed campaign with named threat actors matters when you’re deciding how much to invest in travel security controls.
This also applies beyond hotels. Airport Wi-Fi, conference venue networks, and coworking spaces carry the same risks. The principle is simple: any network you don’t control is a network you can’t trust. Build your security controls around that assumption, and a compromised hotel network becomes a nuisance rather than a breach.
Need Help Securing Your Traveling Workforce?
Our team can configure VPN enforcement, deploy phishing-resistant MFA, and set up travel-specific conditional access policies for your environment.
Get a Free AssessmentServing Businesses Across Texas & Oklahoma