August 10, 2026
Hotel Wi-Fi Attacks Should Worry Every Orlando Business
Russian state hackers are hijacking hotel Wi-Fi to steal Microsoft 365 logins. Why Orlando businesses and travelers sit squarely in the target zone.
What Microsoft found
Microsoft disclosed in late July that a Russian state group it tracks as Storm-2945, an operational arm of the SVR-linked Midnight Blizzard, has been quietly compromising hotel and conference-center Wi-Fi around the world. The campaign, which Microsoft named CaptiveCrunch, has been running since February 2026. Since May, the group has been manipulating the captive portals travelers see when they join a hotel network, the familiar “welcome, accept our terms” page.
Control that page and you control the traveler’s first click. Microsoft documented three plays: fake Microsoft 365 sign-in pages that harvest credentials, Microsoft Entra device-code prompts that trick users into authorizing an attacker’s session, and fake browser or system update pages that install malware. The payloads include CornFlake, a remote-access tool with keylogging, and ChocoShell, a stealer that lifts browser cookies and cloud access tokens straight from memory.
The hotel is not the prize. The prize is the Microsoft 365 account of the person on the lobby Wi-Fi, and everything that account can reach back at the office.
Why Orlando sits inside the target zone
Orlando is one of the most visited destinations in the country, with a convention calendar that keeps hotel ballrooms and conference centers full nearly year round. For local businesses, that cuts two ways.
First, your people travel. Sales reps at trade shows, executives at industry conferences, attorneys at out-of-town CLEs, property managers moving between sites. Every one of them connects to hotel Wi-Fi, usually within minutes of check-in.
Second, a lot of Central Florida businesses are the venue. Hotels, resorts, event spaces, restaurants, and property managers operate exactly the guest networks and captive portals this campaign hijacks. If your splash page gets poisoned, the attacker is stealing from your guests under your brand.
There is a third group worth naming: the staff who run these properties. Front desk machines, kiosks, and back-office systems often share infrastructure with guest networks that was segmented on paper years ago and never re-checked. An attacker with a foothold in portal infrastructure is one weak firewall rule away from reservation and payment systems.
To be clear about what we know: Microsoft has not published a list of affected properties, and we are not aware of a confirmed Orlando incident. The exposure argument does not depend on one. This is a worldwide campaign aimed at the exact traffic Orlando produces more of than almost anywhere else.
MFA alone will not save a stolen session
Here is the detail that should change how you think about security on the road. Once someone signs in, a token proves the session is valid so they are not re-prompted every few minutes. CaptiveCrunch steals those tokens, and a replayed token works without the password and without triggering MFA. The attacker does not need to beat your MFA. They skip it.
Multifactor authentication still matters. It just is not the finish line. The controls that address this campaign directly, drawn from Microsoft’s own guidance: block the device-code sign-in flow unless your business genuinely uses it, require managed or compliant devices through conditional access so a stolen token from an unknown machine gets refused, move toward phishing-resistant methods like passkeys or hardware keys, and watch sign-in logs for the telltales, such as a login from another continent minutes after one from Orange County.
What to tell traveling employees this week
Send this to anyone who travels for you. It fits in one email.
- Treat hotel and conference Wi-Fi as hostile. Use your phone’s hotspot when you can.
- Never install a browser or system update offered by a web page on hotel Wi-Fi. Real updates come from your device settings, not a splash page.
- A Wi-Fi welcome page asking for your Microsoft 365 password is a red flag. Close it and tell IT.
- If a sign-in screen shows a short code and asks you to approve it, and you did not start that process, do not approve it.
- Anything felt off? Report it the same day. A stolen token is a fixable problem if it gets revoked quickly, and a quiet one if it does not.
If your business runs the Wi-Fi
For hotels, multi-location operators, and property managers, the guest network is part of the brand now. The work here is unglamorous and effective: keep guest Wi-Fi fully segmented from operations, harden and patch the edge routers and access points that serve the captive portal, lock down who can change portal and DNS settings, and check periodically that the page your guests see is actually yours. A poisoned splash page at one property damages trust at every property wearing the same logo.
Getting ahead of it
Most of the fixes above are configuration, not new spending, but someone has to own them and watch the logs afterward. The human-run security operations behind Cyber Command’s cybersecurity service does that work daily: hardening Microsoft 365 tenants with conditional access and device-code restrictions, rolling out phishing-resistant sign-in, and monitoring for the anomalous session activity token theft leaves behind. It is built to reduce the odds of a bad week and to shrink the damage when one arrives anyway.
We are headquartered in Winter Springs and provide cybersecurity for Orlando, Tampa Bay, and Jacksonville businesses, from single offices to operators with a dozen properties. If your team travels, or your guests log into your Wi-Fi, talk to a real person about where you stand. The first conversation costs nothing.