Travellers connecting to hotel Wi-Fi networks are being warned to take extra care following the discovery of a sophisticated cyberattack capable of turning an everyday internet connection into a route for stealing passwords and compromising devices…

The campaign, known as “CaptiveCrunch”, targets Wi-Fi networks in hotels, conference centres and other hospitality venues. To guests, everything can appear perfectly normal; they select the hotel network and are presented with the familiar login page. Behind the scenes, however, attackers can manipulate internet traffic and redirect users towards convincing fake pages.

These may imitate Microsoft login screens or present apparently legitimate requests to update a browser, security software or other applications. Entering credentials can hand passwords and authentication details directly to criminals, whilst following instructions to download an “update” could install malware capable of stealing information or remotely accessing a device.

The simplest precaution whilst travelling is to use a mobile data connection or personal hotspot wherever possible. Those using public Wi-Fi should be particularly suspicious of unexpected requests to download software, certificates or updates.

A genuine hotel Wi-Fi connection should never require guests to install software simply to get online. Keeping phones and computers updated before travelling, using a reputable VPN and avoiding sensitive logins through unfamiliar portals can also significantly reduce the risk.

Image: FlyD