Hackers are exploiting hotel Wi-Fi login portals using a deceptive "ClickFix" technique to trick travelers into installing malware and compromising their Microsoft 365 accounts and personal data.
Key Points
- Microsoft identified a new attack vector where hackers hijack hotel captive portals to display fake error messages.
- The "ClickFix" method prompts users to run malicious commands under the guise of fixing account or PC issues.
- Successful exploitation allows attackers to install malware, spy on user activity, and steal sensitive login credentials.
- Security experts recommend using a VPN, avoiding insecure HTTP websites, and utilizing mobile hotspots instead of public Wi-Fi.
- Legitimate hotel portals will never request that users run software commands or input credentials for unrelated third-party accounts.