National Cyber Directorate Warns Against Public Wi-Fi Risks in Hotels and Airports

Microsoft has identified the CaptiveCrunch hacking campaign, which uses fake pop-ups on public networks. The National Cyber Directorate advises users not to enter passwords or install software when connecting to public Wi-Fi.

MakoAuthor: Digital
Source
National Cyber Directorate Warns Against Public Wi-Fi Risks in Hotels and Airports
Photo: Mako / התחברות ל-Wi-Fi, אילוסטרציה | צילום: ymgerman, shutterstock

The National Cyber Directorate warns against suspicious messages appearing after connecting to Wi-Fi networks in hotels, airports, and other public venues. According to the report, Microsoft has identified a campaign in which attackers present fake notifications requesting users to download updates, install software, execute commands, or enter passwords.

The campaign, dubbed CaptiveCrunch, was described on Microsoft’s Threat Intelligence website as a new hacking activity with alleged ties to Russia. Since May, Microsoft has identified widespread compromise of Wi-Fi networks within the hospitality sector.

The fraud operates via pop-up windows that appear upon network connection, attempting to trick users into downloading malicious files. This access allows attackers to:

  1. Capture screenshots and keystrokes.

  2. Remotely take control of devices.

  3. Use fake login screens to gain access to personal email accounts.

The National Cyber Directorate emphasizes that connecting to Wi-Fi should never require the installation of software. Users are advised not to execute unknown commands, avoid entering passwords or verification codes on suspicious pages, and perform device updates only through official settings or authorized app stores.

For sensitive operations, it is recommended to use cellular data or a private hotspot. If you receive an unusual message after connecting to a Wi-Fi network, stop immediately, close the page, and do not follow any instructions provided.

Related News