Monday, August 17, 2026

Public Wi-Fi just got riskier. Follow these 4 security tips

Click here to read the original web article:

 Hackers are targeting Wi-Fi networks at hotels and other locales in ever sneakier ways.

You probably trust public Wi-Fi. But you shouldn’t–at least not completely and not without any safeguards.

A new kind of attack is the latest reminder of this. As detailed by Microsoft, hackers have been infiltrating login portals at hotels. Previously, such hijacking was used to redirect users to fake Microsoft 365 login pages or subvert Microsoft’s corporate-grade authentication method (Entra ID). But now there’s a more dangerous variation that tricks people into installing malware.

It relies on a technique called ClickFix, where a popup appears with instructions that claim to fix a problem with an account or on your PC. Obviously, a phishing page is bad enough, but the malware deposited by this upgraded hack lets bad actors spy on you in addition to potentially stealing a Microsoft 365 account. And most people rarely question hotel Wi-Fi with a captive portal login system. At a property that nice, you’ll likely assume other users are a threat, not the portal itself.

So what should you do to stay safe when on public Wi-Fi, whether fully open or kept behind a portal? Here are the four things I always recommend:

  • Ensure you’re on the official public Wi-Fi network. Smart hackers will create networks that sound similar to legitimate ones, hoping to catch people who aren’t paying close attention. For example, just the other day, I saw an “XfinityWifi” hotspot available in a location that seemed unusual.
  • If you’re routed through a portal, pay attention to the instructions. Most will ask you to agree to terms before proceeding. Hotel portals may ask for your surname and your room number. No legitimate portal will tell you to run commands on your device, or input your login information for an account. (Especially an unrelated account.)
  • Once connected, use a VPN. This sets up an encrypted tunnel, where all your web traffic routes through a secure server. If someone also on the same public Wi-Fi network as you tries to snoop on your activity, they will only see that you’re connecting to the VPN service. (Obviously, this method is only as good as the VPN you choose, so pick one that has strong security, plus a verified no-logs policy to maintain your privacy.)
  • If you can’t use a VPN, avoid browsing insecure websites—anything that only has HTTP (no S) in the address. Such sites are not encrypted, meaning that anyone else on that public Wi-Fi network can see the exact data passed back and forth between your device and that insecure website. Also consider avoiding use of sensitive apps and websites (e.g., financial).

Of course, the easiest way to stay safe on public Wi-Fi is to just not use it. Cell phone connections are harder to hack—so keep using the data on your phone. If you need a connection for your PC, turn on your phone’s hotspot. If you have enough data on your plan, this solution requires the least amount of effort.