Tech Translated

IT Security & Technology Blog

Practical IT insights for Australian businesses. Our team covers cybersecurity advisories, compliance updates, and plain-English explainers on the technology your business relies on, published regularly as the landscape shifts.

High angle view of guests at a hotel reception desk — WiFi and IT services for hospitality venues

Hotel and Venue Wi-Fi Is Now an Attack Vector — What Hospitality Operators Should Do

Microsoft has just confirmed that a Russian state-linked group — Midnight Blizzard, also tracked as APT29 — has been hijacking guest Wi-Fi at hotels and conference centres to steal Microsoft 365 logins. The campaign, which Microsoft calls CaptiveCrunch, tampers with the DNS settings on captive-portal Wi-Fi gear, then redirects guests to fake Microsoft 365 sign-in pages or bogus “update” prompts that quietly install credential-stealing malware. Microsoft says it’s been running since at least May.

There are two sides to this for Australian hospitality operators. If you run guest Wi-Fi — a pub, café, function venue or hotel — the equipment handing out that connection is now a target. And if your managers travel to conferences or stay in hotels, the network they join could be the compromised one. In venues we look after around Brookvale and the Northern Beaches, and out through the Central West, the pattern we see over and over is guest Wi-Fi running off consumer-grade gear on the same flat network as the POS and the back-office PCs. That’s exactly the setup this attack thrives on.

Three things to do now. First, separate guest Wi-Fi from everything else — it should never touch your POS, booking platform or office network. Second, put phishing-resistant MFA or passkeys on every Microsoft 365 account, so a stolen password on its own is useless. Third, tell your team to treat hotel and event Wi-Fi as hostile: no software “updates” offered by a captive portal, and never use work logins to register for a guest network.

If you’re not sure how your guest network is segmented, or whether your Microsoft 365 is locked down properly, that’s exactly the kind of thing we sort out for hospitality clients every week. A short review now beats a breach notification later.

Related Guide

Cybersecurity for Sydney SMBs

Explore our complete guide to protecting your business from cyber threats.

Read the Full Guide →