Hotel Wi-Fi Hacked: How to Stay Safe

Hotel Wi-Fi Hacked: How to Stay Safe

Hotel Wi-Fi security is no longer just a minor travel concern. Microsoft’s threat intelligence team has uncovered an active Russian hacking campaign, dubbed Capidbug (also reported as “Captiv8” in some outlets), that is specifically targeting hotel Wi-Fi networks to surveil and compromise guests’ devices. According to Microsoft’s findings, the operation is linked to a threat actor known as APT28, also called Fancy Bear, a group with longstanding ties to Russian military intelligence. The disturbing reality: most travelers will never even realize they have been targeted.

What Is the Hotel Wi-Fi Threat?

The attack works by exploiting weaknesses in hotel network infrastructure. Once hackers gain a foothold inside a hotel’s internal network, they can intercept unencrypted traffic, inject malicious code into web sessions, and even gain access to devices connected to the same network. The attack is sophisticated enough that guests see nothing unusual on their screens. They log in to the hotel’s Wi-Fi portal, browse the web, check email, maybe log in to a work VPN, and the entire time an adversary may be watching and recording.

APT28 has used this playbook before. The group was behind the “EvilGinx” style credential-harvesting proxy attacks and has a well-documented history of targeting business travelers, government officials, and executives who frequent international hotels. The goal is not always immediate financial theft. Often, the objective is espionage, gathering login credentials, corporate communications, and sensitive documents that can be exploited weeks or months later.

Why Hotel Wi-Fi Security Is So Weak

Hotels are not technology companies. Their IT budgets are typically thin, their network hardware is often years out of date, and the sheer volume of guests connecting and disconnecting daily creates a chaotic environment that is difficult to secure. Many hotel networks still run on flat architectures that do not properly segment guest traffic from administrative systems. That means a hacker who compromises one device, or one access point, can sometimes pivot across the entire network.

Public Wi-Fi in general carries inherent risks. The Cybersecurity and Infrastructure Security Agency (CISA) has long warned travelers to treat any public network as hostile territory and to avoid accessing sensitive accounts without additional protection layers.

Who Is Most at Risk?

Business travelers are the primary target. If you are carrying a laptop with corporate credentials, access to a company VPN, or sensitive client data, you are exactly the kind of guest APT28 is interested in. That said, leisure travelers are not immune. Stolen banking credentials, personal email access, and social media accounts all have value on criminal markets, even if they are not the primary objective of a state-sponsored campaign.

Frequent travelers to Europe, Asia, and anywhere near geopolitically sensitive regions should be especially cautious. Microsoft’s research specifically flagged hotels in those areas as active hunting grounds for this campaign.

Hotel Wi-Fi Security: What You Can Do Right Now

The good news is that protecting yourself does not require advanced technical skills. Here are the most effective steps any traveler can take:

  • Use a VPN on every connection. A reputable VPN encrypts all of your traffic before it leaves your device, making interception far less useful to an attacker. Make this a non-negotiable travel habit.
  • Enable HTTPS-only mode in your browser. Most modern browsers support this. It will warn you or block connections to sites that do not use encrypted transport.
  • Avoid accessing sensitive accounts on hotel Wi-Fi. If you must log in to banking, corporate systems, or anything truly sensitive, do it over a trusted connection.
  • Keep your device software up to date. Attackers frequently exploit known vulnerabilities in outdated operating systems and applications.
  • Use your phone’s mobile hotspot instead. Cellular networks are far harder to intercept at scale than hotel Wi-Fi. If you have a solid data plan, tethering from your phone to your laptop is one of the simplest security upgrades available to travelers.
  • Travel with a personal portable router. Devices like the Katalyst Spark let you create your own private Wi-Fi network using a cellular connection, completely bypassing the hotel network. This is rapidly becoming a best practice for security-conscious road warriors.

The Case for a Portable Cellular Router

Using your phone as a hotspot is a great starting point, but a dedicated portable router offers meaningful advantages. The Katalyst Spark, available through 5Gstore, is purpose-built for exactly this use case. It creates a private, password-protected Wi-Fi network powered by a cellular connection, keeping all of your devices completely off the hotel’s network. You get better battery life than running your phone as a hotspot for hours, the ability to connect multiple devices simultaneously, and often faster throughput.

For business travelers who routinely handle sensitive communications, the math is simple: the cost of a portable router is trivial compared to the cost of a single credential compromise or data breach. You can see how other travelers are thinking about redundant, secure connectivity in our guide to internet failover strategies.

What About Hotel VPNs?

Some hotels now advertise that they offer VPN access or “secure” networks. Treat these claims with healthy skepticism. A VPN provided by the hotel itself does not protect you from a hotel network that has already been compromised at the infrastructure level. If the hotel’s own systems are the attack surface, a hotel-managed VPN offers very little additional protection. Your VPN needs to be one you control, running on your own device, routing traffic to a trusted server outside the hotel environment.

5Gstore Take

This is not a theoretical threat. Microsoft’s threat intelligence team has documented real, active operations against hotel networks by a sophisticated nation-state actor. For most leisure travelers, the risk may feel abstract. But for anyone traveling for business, attending conferences, or carrying corporate credentials, hotel Wi-Fi is now a legitimate attack surface that deserves the same caution you would give an unknown USB drive.

Our recommendation: carry a portable cellular router like the Katalyst Spark, use a trusted VPN, and treat hotel Wi-Fi the way you would treat any untrusted public network. The slight inconvenience of setting up your own connection is nothing compared to the consequences of a successful attack. At 5Gstore, we carry routers and connectivity solutions from Peplink, Cradlepoint, Teltonika, Semtech, Inseego, Digi, and Katalyst, and we are happy to help you find the right travel setup for your needs. Contact us to get a recommendation.

Frequently Asked Questions

Is hotel Wi-Fi really that dangerous?

Based on Microsoft’s recent threat intelligence report, yes, hotel Wi-Fi is an active target for sophisticated hackers, including state-sponsored groups. The risk is especially high for business travelers carrying sensitive data or corporate credentials.

Does using a VPN fully protect me on hotel Wi-Fi?

A reputable, independently operated VPN significantly reduces your risk by encrypting your traffic. However, no single measure is a complete guarantee. Combining a VPN with a personal cellular hotspot or portable router provides the strongest protection.

What is APT28 and why do they target hotels?

APT28, also known as Fancy Bear, is a threat group linked to Russian military intelligence. They target hotels because business travelers, executives, and government officials all converge in hotel environments and frequently connect sensitive devices to shared networks, creating an efficient espionage opportunity.

What is the Katalyst Spark?

The Katalyst Spark is a compact portable cellular router that creates a private Wi-Fi network using a cellular data connection. It is designed for travelers who need secure, reliable internet access without relying on hotel or public Wi-Fi networks.

Should I just use my phone’s hotspot instead of hotel Wi-Fi?

Yes, using your phone’s mobile hotspot is a significant security improvement over hotel Wi-Fi. A dedicated portable router like the Katalyst Spark takes this further by offering better battery management, multi-device support, and more consistent performance for extended use.

Are all hotels equally risky?

Not all hotels have the same level of network security, but it is safest to treat any hotel Wi-Fi as potentially compromised, especially when traveling internationally or to regions flagged in threat intelligence reports.

Michael Ginsberg, founder of 5Gstore.com

About the Author

Michael Ginsberg is the founder of 5Gstore.com, a trusted source for cellular routers and failover networking solutions since 2005. With a background in software and networking dating back to 1988, he writes about cellular connectivity, IoT infrastructure, network security, and fleet management. Connect with Michael on LinkedIn or reach the 5Gstore team through our contact page.