04 Aug 2026

Your Hotel Wi-Fi Login Page Is Part of Your Security System. That's What Got Hacked. Here's What Owners Can Do.

Nerd ModeIT and network teams Normal ModeHotel owners and operators
A laptop on a hotel room desk showing a browser sign-in pop-up over a Wi-Fi login page, with a wireless access point on the ceiling behind it.
Normal Mode is for hotel owners, general managers, franchisees, asset managers, and operations teams.You do not need to run the network. You need to know what to ask the people who do. Switch to Nerd Mode for the original technical article.

Guests expect hotel Wi-Fi to work like hot water. They connect, clear a sign-in screen, and move on. That familiar screen is also a point of trust. If someone takes control of it, a guest can be sent to a fake Microsoft login, hand over account access, or be told to install a fake update before realizing anything is wrong.

That is the business issue in the CaptiveCrunch campaign reported by BleepingComputer. Microsoft attributed the activity to Storm-2945, a sub-cluster of Midnight Blizzard, also known as APT29. The campaign targeted hospitality networks and could steal Microsoft 365 access or place malicious software on a guest's device. Microsoft said it could not determine the exact initial compromise, but it saw signs that shared infrastructure may have been breached rather than one hotel device at a time.

Your guest Wi-Fi login system is part of your security operation. It cannot be installed, forgotten, and replaced only when it stops working.

What was attacked

This was not an attack on the Wi-Fi radio signal. The attackers did not need to crack the wireless connection. They went after the system guests encounter when they first join the network.

That sign-in screen is called a captive portal. It is the page that asks for a room number, last name, email address, or acceptance of terms before internet access begins. Hotels use it to control access and present a branded welcome page.

Behind that page is usually a gateway. Think of the gateway as the front desk for internet traffic. It decides which connected devices can go online and where their requests should go. It may also provide DNS, which is the internet's address book. DNS takes a name such as microsoft.com and finds the correct destination for it.

If an attacker can change the gateway's DNS settings, that address book can lie. A guest who thinks the computer is opening a Microsoft page can be directed toward an attacker-controlled page instead. The fake page can look convincing, pass information through to the real service, and capture credentials or the session information that proves the guest already signed in.

The guest may still get online. From the guest's point of view, nothing obvious failed. That is why this deserves an operational response, not just a help desk ticket.

Why your service provider matters

Many hotels hire a managed service provider, usually called an MSP, to monitor and support networks across multiple properties. That can be the right model, but it creates a shared point of responsibility. If the systems an MSP uses to reach hotel gateways are compromised, an attacker may be able to affect more than one property.

This does not mean Microsoft confirmed an MSP as the entry point in every incident. It did not. It means operators need to understand who can remotely access their network, how that access is protected, and how quickly the provider can detect and stop unauthorized changes.

“We handle security” is not an answer. Ask for dates, device lists, update records, access controls, and a named person responsible for follow-up.

Firmware is maintenance, not an upgrade pitch

Firmware is the software built into network equipment. Manufacturers release firmware updates to fix security problems, correct defects, and keep equipment supported. A gateway can appear to work perfectly while running software with known weaknesses.

Patching may require a short maintenance window. Schedule the work, tell the front desk what to expect, and confirm afterward that every device returned to service on the intended version.

If the manufacturer no longer provides updates, the equipment has become an operational risk even if guests can still connect. When buying a gateway, ask how long it will receive security updates, how quickly critical fixes are released, and who is responsible for installing them. Cheap equipment is not cheap if it has to be replaced during an incident.

Keep guests away from hotel systems

Segmentation means dividing one physical network into separate, controlled areas. Guests should be able to reach the internet, but they should not be able to reach the property management system, staff devices, building controls, TVs, locks, or other connected equipment.

Do not accept a diagram as proof that this separation works. Ask the provider to test it from the guest network and document the result. A configuration that was correct at installation can change during upgrades, troubleshooting, or equipment replacement.

Why “use a VPN” is incomplete advice

A VPN creates an encrypted connection that can protect traffic after it starts. The timing matters. At many hotels, the guest must complete the captive portal before the VPN can connect. The dangerous fake login or fake update can therefore appear before VPN protection is active.

Guests should never install an update offered by a hotel sign-in page or use corporate credentials to register for guest Wi-Fi. A phone hotspot is a practical alternative when the portal looks unfamiliar or asks for something it should not need. Guest caution, however, does not replace the hotel's responsibility to maintain the network.

Where Passpoint fits

Passpoint lets an approved device join a compatible Wi-Fi network with secure credentials already stored on that device. In plain language, the device can connect without asking the guest to work through the usual pop-up page.

Removing that pop-up removes the specific attack opportunity used in this campaign. It does not make the entire hotel network immune to every threat. It does reduce reliance on a page guests must inspect and trust while they are trying to get online.

Ask whether your current equipment supports Passpoint, what identity or roaming service would be used, which guests and devices could participate, and what would remain in place for devices that do not support it. Treat Passpoint as part of a network plan, not a product name someone drops into a sales call.

Talk with SignalRoam

Leave your information and someone can contact you about using SignalRoam at your property.

What to ask your IT provider this week

  • Which companies and named people have remote access to our gateways, controllers, and captive portal systems?
  • Is remote access protected with multifactor authentication? Do you alert on unusual logins or configuration changes?
  • What gateway, controller, and access point models are installed at each property? What firmware version is each one running?
  • Are all current security patches installed? If not, what is the maintenance date and who will confirm completion?
  • Does each manufacturer still support our equipment with security updates? What is the replacement plan for unsupported devices?
  • Who controls DNS for the guest network? How would you detect an unauthorized DNS or captive portal change?
  • Can you prove, with a current test, that a guest device cannot reach hotel systems, staff networks, locks, TVs, building controls, or other connected equipment?
  • Does our current equipment support Passpoint? If not, what would need to change?
  • If you suspect a compromise, who calls us, who contains it, what records are available, and how quickly can you act?

Do not settle for a clean-looking dashboard

Hotel technology does not become safe because the internet light is green. The real test is whether the equipment is supported, patched, monitored, separated correctly, and managed by people who can explain their work.

Start with an inventory and a direct conversation with your provider. Get the answers in writing. Set dates for anything incomplete. Guest Wi-Fi is an amenity, but the systems behind it are security infrastructure. Operate them that way.

Source

Want this kind of thing weekly, in audio? That's the show.