A Russia-linked hacking group known as Midnight Blizzard has been tied to a campaign targeting hotel and conference Wi-Fi systems around the world. According to the report, the attackers compromised captive portals — the login pages guests often see before accessing wireless internet — and used them to push users toward phishing pages and fake software updates.

The goal of the operation was to collect valuable digital access data, including credentials, session tokens and other sensitive information. By abusing trusted Wi-Fi login screens in hotels and event venues, the campaign appears designed to catch travelers and business attendees at a moment when they are likely to connect quickly and pay less attention to warning signs.

Microsoft said the activity was linked to Midnight Blizzard, the threat actor it previously tracked under the name NOBELIUM. The group has also been attributed by US and UK authorities to Russia's SVR foreign intelligence service, adding to concerns that the hotel Wi-Fi operation fits a broader pattern of espionage-focused cyber activity.

The incident highlights how public and semi-public wireless networks can become effective delivery points for credential theft when login pages are altered or spoofed. For hotels, conference organizers and travelers, the case underscores the security risks around captive portals, software update prompts and any request for account details delivered through shared Wi-Fi environments.