← All advisories
KSG-ADV-2026-006 Severity: High Audience: Business travellers

The Hotel WiFi Threat: What Business Travellers Need to Know

Executive Summary

Kariba Security Group is issuing this advisory for small business owners and employees who travel and connect to hotel WiFi. Anthropic's September 2026 threat intelligence report documents a sophisticated attack (part of the GTG-20006 operation, publicly identified by Microsoft as "CaptiveCrunch") in which a state-linked threat actor compromised the WiFi systems of multiple hotels by stealing administrator credentials from hotel management vendors.

Once inside the hotel's network infrastructure, the attackers modified DNS records so that guests connecting to hotel WiFi had their traffic, device identifiers, and IP addresses sent to the attacker's servers. Guests were then shown convincing fake prompts — designed to look like legitimate software updates — that, if clicked, delivered malware to Windows, Android, and iOS devices.

You did not need to be a specific target for this operation to affect you. Anyone who connected to the affected hotel WiFi during the period of the compromise was exposed.

How the Attack Worked

Compromising the hotel's infrastructure

The attacker did not hack individual guests directly. Instead, they compromised hotel WiFi management vendors — companies that provide and manage WiFi systems across many hotels simultaneously. By stealing administrator credentials from these vendors, the attacker gained control over the DNS configuration of multiple hotels at once.

DNS hijacking

With DNS control, the attacker redirected guest traffic. When you connected to hotel WiFi and your device tried to reach a website, your device first asked the hotel's DNS server where to send that request. The attacker controlled that DNS server, which meant they controlled where your traffic went.

The fake update prompt

Guests connecting to hotel WiFi saw a convincing prompt claiming that a software update was required to continue — designed to look like a legitimate Windows, Android, or iOS update notification. Guests who clicked and allowed the "update" installed malware on their device. The malware provided the attacker with ongoing access to the device and everything on it.

What the attacker could access

Once malware was installed, the attacker potentially had access to:

Signs Your Device May Have Been Compromised

If You Think Your Device Was Compromised

  1. Disconnect the device from all networks immediately — WiFi, Bluetooth, and mobile data
  2. Do not connect it to your business network — a compromised device can spread access to everything it connects to
  3. Change passwords from a different, unaffected device — prioritise business email, financial accounts, and any systems you access remotely
  4. Contact a technology professional to investigate and clean the device before reconnecting it to anything
  5. Check your accounts for unauthorised access — review login history on email, banking, and any business systems
  6. Notify your IT team or provider if you have remote access to business systems — they need to know a potentially compromised device may have connected

How to Protect Yourself When Travelling

Use a VPN

A VPN encrypts your traffic between your device and the VPN server, making DNS hijacking significantly less effective — an attacker who controls the DNS server can still redirect your connection, but they can't read the encrypted traffic. For business travel, a reputable commercial VPN is a worthwhile investment. When evaluating providers, look for a clear no-logging policy, independent security audits, and a jurisdiction with strong privacy protections.

KSG has no commercial relationship with any VPN provider and receives no compensation for any mention. Evaluate providers against your own requirements.

Use your phone as a hotspot instead of hotel WiFi

Your mobile carrier's network is significantly harder to attack than hotel WiFi. For anything sensitive — accessing business email, financial systems, or company data — tether to your phone rather than connecting to hotel WiFi.

Never click unexpected update prompts on untrusted networks

Legitimate operating system updates do not require you to click a prompt in your web browser while connected to a hotel network. If you see an update prompt immediately after connecting to hotel WiFi, do not click it. Disconnect from the WiFi, connect to your mobile hotspot, and check for updates through your device's official settings.

Keep your devices updated before you travel

Ensure your operating system, browser, and apps are fully updated before your trip. Malware delivered through these attacks often exploits vulnerabilities that patches have already addressed — a fully updated device is significantly more resistant.

Enable full-disk encryption on your devices

If your device is physically taken — left in a hotel room, lost, or seized — full-disk encryption protects the data on it. This is enabled by default on modern iOS and Android devices. On Windows, check that BitLocker is enabled. On Mac, FileVault should be enabled.

Use hardware security keys for important accounts

For your most critical accounts — business email, financial systems, administrative access — a hardware security key (such as a YubiKey) provides phishing-resistant two-factor authentication that malware on a compromised device cannot steal.

Before You Travel

  • Update your device OS, browser, and apps
  • Enable full-disk encryption
  • Install and test a reputable VPN
  • Confirm your mobile plan supports hotspot use
  • Enable MFA on business email and critical systems

While Travelling

  • Use your phone as a hotspot for sensitive work — avoid hotel WiFi for business access
  • Use your VPN whenever connected to any public or hotel network
  • Never click an update prompt that appears immediately after connecting to hotel WiFi
  • Lock your device when not in use and never leave it unattended

After You Return

  • Review account login history for any access from unfamiliar locations
  • If you clicked an unexpected prompt on hotel WiFi, treat the device as potentially compromised