Travelers may want to think twice before automatically connecting to hotel Wi-Fi. Microsoft says it uncovered a hacking campaign targeting commercial routers used by hotels and other businesses in the hospitality industry. The activity was first detected in early May and was linked to a well-known Russian hacking group.
How to Stay Safe on Hotel Wi-Fi
Hotel Wi-Fi is designed to be convenient. The network name and password are often posted at the front desk, printed on a room key sleeve, or displayed inside the room. Guests can connect within seconds, often without giving the security of the network much thought.
According to Microsoft, attackers were able to compromise some hotel networks and redirect guests to convincing fake websites and pop-up messages. One fake page appeared to come from Google and told users they needed to complete a security check before continuing. Another displayed a false Windows update and instructed the user to install a driver or click a button to fix a supposed problem.
Microsoft recommends avoiding software updates and downloads while connected to public Wi-Fi. Travelers should also avoid clicking unexpected pop-ups, security alerts, or update messages. A legitimate update should be installed through the computer or phone’s settings, not through a surprise browser window.
If a suspicious pop-up appears, do not click any buttons inside the message. Do not enter a password or other personal information. Close the browser or force it to quit. Disconnect from the Wi-Fi network. Select “Forget this network” in the device’s Wi-Fi settings.
Consider using a travel router. A portable travel router can provide another layer of separation between your devices and a hotel’s network. Some hotel rooms still have an Ethernet port. A traveler can plug the portable router into that port and connect phones, computers, tablets, and streaming devices to a private Wi-Fi network created by the router.
Original reporting: KTBS 3 (Shreveport) — read the source article.