The New Wi-Fi Trap Travelers Should Know

For frequent travelers, public Wi-Fi has become almost as routine as checking into a hotel. You arrive, open your laptop or phone, select the hotel network and accept the terms. A few seconds later, you’re online.

That convenience is exactly what scammers have been exploiting. A hacking campaign linked to Russian attackers, known as CaptiveCrunch, has targeted Wi-Fi systems at hotels and conference centers around the world. The concern is that attackers can potentially manipulate the login page itself—the screen you see before you’re allowed onto the network.

That makes this scam particularly dangerous for travelers because the fake page can look completely legitimate. But, in this case, It may ask you to install a required browser update before continuing.

A legitimate hotel portal may ask you to accept terms, enter your room number or provide a password. It shouldn’t require you to install software. If anything looks unusual, disconnect. Ask the front desk for the correct network name and whether the login process you’re seeing is legitimate. Don’t download anything the page asks you to install.

Note also that a legitimate hotel Wi-Fi isn’t where you want to conduct your most sensitive business. If you’re checking your bank account, accessing confidential company information or handling other sensitive transactions, your phone’s cellular connection is a better choice. A personal hotspot turns your phone into your own private network.

I also came across another scam that is rampant and even fooled me. I received an email that appeared to come from a relative that looked like an invitation from Evite. The timing was impeccable because we were all getting together for a wedding in a month and I assumed this event was connected. The catch is that her account was compromised, allowing scammers to send the invitation to her contacts. In this case it told me to open the invitation on a computer for the “best experience.” When I clicked the link, it asked me to open what was an .exe file, fortunately not Mac combatible. But it was so convincing I emailed to tell her that I couldn’t open her attachment.

It’s a shame we have to be so wary and that are so many out there trying to scam so many. There’s no end to their ability to find new ways to take our money. With AI it’s only going to get worse.

4 thoughts on “The New Wi-Fi Trap Travelers Should Know

  1. Jeff Cornish says:

    I always look forward every week to your posts Phil. Thank you.

    Good warning we all need to be aware of.

    I am surprised you didn’t mention VPN’s as protections.

    • Phil Baker says:

      VPNs are a subject for another column, but they can prevent hackers from intercepting passwords etc. Some good ones are NordVPN, Surfshark, ExpressVPN, and Proton VPN. I tend not to use them because they can slow down browsing spped.

  2. Lyn Greenhill says:

    Put an eSim modem in your laptop and don’t use hotel WiFi, or any other WiFi for that matter, at all.

  3. Phil Brown says:

    “Free” Wi-Fi was rarely (if ever) free, but now more than ever you get what you pay for. Pay for cellular hotspot service, and/or a VPN if you’re so inclined (not that those don’t come without their own set of issues). If you can afford to travel you can afford to pay for Wi-Fi.
    Also, AI can already tailor spear fishing attacks right to you and adapt in real-time. We’re not ready for what’s coming and it’s going to get a lot worse…

Comments are closed.