For frequent travelers, public Wi-Fi has become almost as routine as checking into a hotel. You arrive, open your laptop or phone, select the hotel network and accept the terms. A few seconds later, you’re online.
That convenience is exactly what scammers are exploiting. A hacking campaign reportedly linked to Russian attackers, known as CaptiveCrunch, has targeted Wi-Fi systems at hotels and conference centers. The concern isn’t simply that someone might be snooping on an unsecured network. Attackers can potentially manipulate the login page itself—the screen you see before you’re allowed onto the network.
That makes this scam particularly dangerous for travelers because the fake page can look completely legitimate. But, in this case, It may ask you to install a required browser update before continuing.
A legitimate hotel portal may ask you to accept terms, enter your room number or provide a password. It shouldn’t require you to install software. If anything looks unusual, disconnect. Ask the front desk for the correct network name and whether the login process you’re seeing is legitimate. Don’t download anything the page asks you to install.
Note also that even a legitimate hotel Wi-Fi isn’t where you want to conduct your most sensitive business. If you’re checking your bank account, accessing confidential company information or handling other sensitive transactions, your phone’s cellular connection is a better choice. A personal hotspot essentially turns your phone into your own private Wi-Fi network.
I also come across another scam that is rampant and fooled me. I received an email that appeared to come from a relative that looked like an invitation from Evite. The timing was impeccable because we were all getting together for a wedding and I assumed this event was connected.. The catch is that her account was compromised, allowing scammers to send the invitation to everyone in her contacts. In this case it told me to open the invitation on a computer for the “best experience.” When I clicked the link, it asked me to open what was an .exe file, fortunately not Mac combatible. But it was so convincing I emailed to tell her that I could not open her attachment.