Russian state-sponsored hackers, specifically the Storm-2945 group affiliated with APT29, have been compromising hotel Wi-Fi networks to steal Microsoft 365 tokens from unsuspecting travelers since early May 2026. By manipulating DNS and HTTP traffic on captive portals, the attackers redirect victims to malware and credential theft operations. This campaign, dubbed CaptiveCrunch, highlights the group's ability to exploit vulnerable public networks to gain access to sensitive information. The fact that APT29, also known as Cozy Bear, is involved shifts the threat model from traditional cybercrime to geopolitical motivations1. This distinction is crucial, as it implies a more sophisticated and potentially more damaging threat. The use of such tactics by state-aligned groups underscores the importance of heightened security measures, particularly when connecting to public Wi-Fi networks. So what this means for practitioners is that they must adopt a more nuanced approach to threat modeling, one that accounts for the unique motivations and capabilities of nation-state actors.