Friday, August 07, 2026

Russian hackers target hotel Wi-Fi networks in campaign affecting users across Europe

August 7, 2026
3 mins read
Russian hackers target hotel Wi-Fi networks in campaign affecting users across Europe
Russian hackers target hotel Wi-Fi networks in campaign affecting users across Europe

Microsoft says a Russian hacking group linked to the country’s foreign intelligence service has targeted public Wi-Fi infrastructure in hotels, conference centres and other venues across several countries. The campaign could allow attackers to compromise large numbers of users through shared authentication services and turn staff devices into gateways to corporate or government networks.

The operation, reported on 5 August 2026 by Meduza, has been attributed by Microsoft to hackers known as Storm-2945. The group is linked to Midnight Blizzard, an elite Russian hacking organisation associated with Russia’s foreign intelligence service. The campaign targeted networks using captive portals – the web pages that appear when a user connects to public Wi-Fi and is asked to authenticate.

Attackers used familiar update prompts

Microsoft said the hackers may have gained access to shared services used by several operators of public Wi-Fi networks. That created the possibility of reaching numerous hotels and other public locations through one successful intrusion, rather than attacking each venue separately.

Once inside the relevant infrastructure, the attackers quietly redirected users through phishing systems under their control. They then distributed malicious software disguised as updates for a browser or operating system. The prompts appeared after browsers carried out automatic checks of the internet connection, a routine process that takes place when a device joins a new network.

The method relies on an ordinary digital habit: accepting a request to update software while trying to get online. A user who follows the fraudulent prompt can unknowingly install malware on a device used for work, travel or access to sensitive services.

The potential victims include people using hotel and conference-centre networks during business trips, international meetings and official travel. Public Wi-Fi is commonly used in precisely those settings by diplomats, government officials and business representatives, whose devices may contain confidential information or provide access to protected systems.

One breach could open many locations

The significance of the campaign lies in the infrastructure chosen by the attackers. Services shared by multiple Wi-Fi operators can act as a force multiplier: control over one common platform may expose users in hundreds of hotels and public venues in different European countries. It also makes the operation harder to detect quickly, because the compromise is distributed across familiar local networks rather than concentrated in one government system.

The most serious risk is the infection of a work device while its user is travelling. That device could then become an entry point into a company’s or public institution’s internal information systems. Instead of breaking directly through an organisation’s perimeter defences, Russian intelligence services can exploit a trusted device belonging to an employee and use it to reach networks that would otherwise be better protected.

The campaign therefore extends the battlefield of cyber espionage beyond ministries and other high-value state systems. Hotels, conference centres, airports and similar public digital environments are also places where sensitive professional activity takes place. Their networks can provide access not only to documents, but potentially to information about movements, official contacts and working relationships.

Storm-2945’s role in Russian cyber espionage

Microsoft uses the Storm prefix followed by a four-digit number for temporary or tracked threat clusters before they are fully identified and connected to a known group. Storm-2945 is described as a specialist unit within Midnight Blizzard, focusing on technical attacks and conventional cyber espionage rather than disinformation.

Midnight Blizzard has been associated with the 2020 SolarWinds attack on US government institutions and with the 2023 compromise of the Outlook email client. Storm-2945, by contrast, has concentrated on local network infrastructure, including captive portals and public Wi-Fi systems in hotels.

The operation illustrates a broader shift in Russian cyber-intelligence activity towards the everyday digital infrastructure used by officials, journalists, military personnel and company executives. By combining access to devices with the ability to observe professional contacts and travel patterns, the service can pursue a longer-term picture of western activity rather than simply steal individual documents.

European governments, international organisations and businesses will now need to treat travel security as part of their wider cyber-defence responsibilities. Avoiding unsecured public Wi-Fi, disabling automatic connection to open networks and installing updates only from official sources are basic safeguards, but the campaign shows why they cannot be left to individual discretion when sensitive information is involved.

The unresolved issue is whether shared public-network providers can introduce common security standards and continuous monitoring quickly enough to prevent a single compromise from spreading across multiple countries and venues.

Should organisations impose stricter limits on staff use of public Wi-Fi, or focus on securing the networks themselves?

Leave a Reply

Your email address will not be published.

Don't Miss

Russian drones hit German freighter near Odesa, raising stakes for Black Sea shipping

Russian drones hit German freighter near Odesa, raising stakes for Black Sea shipping

Russian drone strikes on two merchant vessels near Odesa have widened the
Russians fleeing mobilisation turn Georgia into a hub for talent and investment

Russians fleeing mobilisation turn Georgia into a hub for talent and investment

Georgia is becoming a leading destination for Russians seeking to escape the