
Microsoft: Russian-linked hackers target global hotel wi-fi networks

Microsoft has reported that, since May 2026, the Russian-linked threat actor Storm-2945 has conducted targeted phishing campaigns against users of hospitality Wi-Fi networks worldwide. The campaign uses a spoofed Microsoft authentication page, supported by AI-assisted social engineering techniques, to harvest credentials and other sensitive information from corporate users connecting through hotels and conference venues.
Storm-2945 is a sub-group of Midnight Blizzard (APT29), which has been attributed by the US, UK, Australian and Canadian governments to Russia's Foreign Intelligence Service (SVR). The group has a longstanding history of espionage operations targeting government organisations, NGOs and technology providers across the US, UK and Europe.
The campaign demonstrates the continued targeting of business travellers and highlights the growing use of AI to enhance credential theft and social engineering. Organisations should treat public Wi-Fi networks as untrusted, encourage the use of VPNs or mobile hotspots where possible, and reinforce phishing awareness for employees travelling on business.