⚠ Cybersecurity Alert
Hotel Wi-Fi Security: Why Your Next Las Vegas Business Trip Is a Target
A Russian state-sponsored hacking group is hijacking hotel and convention Wi-Fi to steal Microsoft 365 logins — and Las Vegas books more conventions than any other city in America.
Published by CMIT Solutions of Las Vegas · Cybersecurity · 7 min read
What Is CaptiveCrunch, and Why Should Las Vegas Businesses Care?
On July 31, 2026, Microsoft Threat Intelligence disclosed an ongoing campaign it calls CaptiveCrunch — a hotel Wi-Fi security threat in which attackers took control of the captive-portal equipment that powers guest Wi-Fi at hotels and conference venues in multiple countries. Microsoft attributes the activity to Storm-2945, an operational sub-cluster of Midnight Blizzard — also tracked as APT29 or Cozy Bear — which the U.S. and U.K. governments have formally attributed to Russia’s Foreign Intelligence Service, the SVR.
The campaign has been running since at least early May 2026, and it is not aimed at the hotels themselves. It is aimed at the Microsoft 365 accounts of the business travelers who connect to that Wi-Fi. That distinction matters enormously for a city like Las Vegas, which hosts more trade shows and conventions than anywhere else in the country. Every executive checking email from a Strip hotel room, every sales rep logging into a client portal from a convention center lobby, and every out-of-town vendor visiting a Las Vegas gaming or hospitality business is connecting through exactly the kind of network this group has learned to compromise.
Microsoft found that Storm-2945 compromised shared captive-portal vendor infrastructure serving many hotels and venues at once — not individual properties. One vendor breach can silently expose guest Wi-Fi across dozens of hospitality locations simultaneously, including the convention hotels Las Vegas depends on to fill its calendar year-round.
How the Attack Works
CaptiveCrunch is technically sophisticated, but the entry point is something every business traveler does without thinking — clicking “Connect” on a hotel Wi-Fi splash screen. Here is what happens on a compromised network:
- Infrastructure-level compromise: attackers gained control of the shared equipment behind captive portals, not individual hotel networks, giving them reach across many properties from a single foothold.
- DNS and HTTP traffic manipulation: before the real login page ever loads, the attackers redirect the guest’s traffic through an adversary-in-the-middle position they control.
- Fake Microsoft 365 sign-in pages: victims are shown a convincing Microsoft login prompt that captures both the password and the live session token — the token that normally proves MFA was already completed.
- Device code phishing: some victims are shown a legitimate-looking Microsoft device authentication code and told to enter it at the real microsoft.com sign-in page — unknowingly authorizing the attacker’s device instead of their own.
- Fake update prompts (ClickFix): other victims are served a fake browser or OS update that installs the CornFlake remote access trojan and the ChocoShell PowerShell infostealer, giving attackers persistence and ongoing data collection.
- ⚠Traveling executives and sales staff risk their entire Microsoft 365 account — email, SharePoint, Teams — being silently taken over mid-trip.
- ⚠A stolen session token bypasses MFA entirely — resetting the password afterward does not undo the damage already done.
- ⚠Out-of-town clients, vendors, and partners visiting Las Vegas conventions connect through the same compromised hospitality infrastructure as everyone else.
- ⚠A hijacked executive inbox is a proven launchpad for wire-fraud and vendor-impersonation schemes aimed at the business back home.
- ⚠Gaming, hospitality, and legal firms with staff traveling to industry events carry outsized exposure, given how much Las Vegas business runs through the convention calendar.
Three Fixes Before Your Next Business Trip
• Traveling employees trust the Wi-Fi splash screen by default
The GapMost employees connect to hotel or conference Wi-Fi and click through the captive portal without a second thought — it looks exactly like a routine check-in page, because until recently, it always was one.
The FixRequire a company VPN to be active before any business application traffic leaves the device on hotel or venue networks. A properly configured VPN encrypts traffic before it reaches the captive portal, making a hijacked DNS redirect irrelevant.
• Standard MFA does not stop a stolen session token
The GapApp-based or SMS MFA protects the password, not the session. CaptiveCrunch’s adversary-in-the-middle technique captures the session token after the victim has already completed MFA, so the login looks fully legitimate to Microsoft.
The FixMove traveling executives to phishing-resistant authentication — FIDO2 security keys or Windows Hello for Business — and enable Conditional Access policies that flag sign-ins from new devices, unfamiliar locations, or impossible travel.
• Device code phishing goes unnoticed until the account is gone
The GapDevice code sign-in is a legitimate Microsoft feature abused by attackers: a fake page displays a real authentication code and instructs the victim to enter it at the genuine Microsoft login page, unknowingly authorizing the attacker’s device.
The FixDisable the device code authentication flow at the tenant level unless a specific business need requires it, and train traveling staff to never enter a sign-in code they did not personally initiate on their own device.
Las Vegas Businesses: Don’t Wait for the Breach.
Defending Las Vegas with CMIT Solutions
Las Vegas runs on its convention calendar, which means Las Vegas businesses are exposed on both ends of a threat like CaptiveCrunch — through employees who travel to industry events, and through the out-of-town clients, vendors, and partners who fly in and connect from Strip and convention-area hotels. CMIT Solutions of Las Vegas configures Conditional Access, phishing-resistant MFA, and travel-safe VPN policies for Clark County businesses in gaming, hospitality, healthcare, and legal — the industries most likely to have people on the road, or hosting the people who are.
• Microsoft Security Blog — CaptiveCrunch: Midnight Blizzard Targets Travelers Worldwide (July 31, 2026)
• Zscaler ThreatLabz — Midnight Blizzard Launches CaptiveCrunch
Protect Your Las Vegas Business Today
We’ll review your travel security, MFA configuration, and Conditional Access policies — before your next employee books a flight.
Prefer to talk? Call (702) 725-2877 or email LVSales@cmitsolutions.com