Microsoft has issued a new security warning aimed at travelers, urging them to think twice before logging into hotel Wi-Fi. According to the report, the company said it identified widespread compromise of Wi-Fi networks at hospitality-related organizations, raising fresh concerns for anyone connecting to the internet while staying away from home this summer.
At the center of the alert is a specific threat actor. Microsoft said that Russian hackers are using fake sign-in pages to break into users accounts, and that Russian-backed hackers will use hotel Wi-Fi networks to target travelers. The warning frames the hotel network itself as the entry point that the attackers are seeking to exploit.
The method described is a form of credential theft built around imitation. According to the report, the hackers create fake pages that look like real Microsoft 365 logins, and then they either steal the users credentials or send malware. Microsoft cautioned that these pages can look very realistic, making them difficult for an ordinary traveler to distinguish from the genuine service.
To illustrate the danger, Microsoft shared a concrete example. The company published an example of a fake Microsoft 365 Windows update, showing the kind of convincing but fraudulent prompt that a user might encounter after connecting. The example was meant to underline how closely the malicious pages can mimic legitimate Microsoft interfaces.
Based on those findings, Microsoft offered a broad piece of guidance. The company said users should assume that public and hotel Wi-Fi networks might not be trustworthy. Rather than treating such networks as safe by default, travelers are advised to approach them with caution and to limit the exposure of their accounts while connected to them.
The alert also set out safer alternatives for staying online. According to the report, using a phone as a hotspot is a safer option, though Microsoft noted that travelers should first check their plans data allowance before relying on it. The advice points users toward connections they control instead of shared networks whose security cannot be verified.
Finally, Microsoft addressed how to harden accounts against this type of attack. For those using Microsoft 365, the company recommended considering passwordless login options such as passkeys, or enabling multi-factor authentication. These measures are presented as ways to reduce the risk that stolen credentials alone could give an attacker access to a users account.
