Russian foreign intelligence operatives, specifically the Storm-2945 subdivision of the SVR's Midnight Blizzard, have been compromising public Wi-Fi networks to deliver malware such as infostealers and keyloggers. This campaign, which targets users of public Wi-Fi in hotels, conference centers, and other shared venues, has been uncovered by Microsoft with the help of ReliaQuest's earlier research1. The attackers are using captive portal networks to spread the malware, putting users' sensitive information at risk. The fact that state-aligned actors are involved in this campaign shifts the threat model from criminal to geopolitical, requiring a different approach to mitigation. This development is significant because it highlights the increasing use of public Wi-Fi networks as a vector for cyber attacks, making it essential for users to exercise caution when connecting to these networks. So what matters to practitioners is that they must now consider the geopolitical implications of such attacks and adjust their security strategies accordingly.