🔐
Security 📅 2026-08-04 · 03:35 AM IST ⏱ 3 min read

Russian Hackers Exploit Hotel Networks to Steal Google Passkeys from Travelers

APT29 targets hospitality Wi-Fi to intercept passwordless authentication tokens, putting business travelers at risk.

Attackers Weaponize Hotel Internet to Compromise Digital Keys

Security researchers have uncovered a coordinated hacking operation where Russian-linked cybercriminals are infiltrating the wireless networks of hotels and hospitality venues to steal passkeys stored on guest devices. The attackers, identified as part of a group known as Midnight Blizzard, have developed techniques to intercept the digital authentication tokens that sync through Google accounts—essentially capturing the "master keys" that unlock user accounts across multiple services.

Rather than targeting passwords in the traditional sense, these attackers are going after passkeys: modern security credentials that replace typed passwords with biometric verification or device unlock methods. Think of passkeys like fingerprints for the internet. When you use your fingerprint to unlock your phone, that same technology syncs to your Google account. Hackers who intercept these synced passkeys gain the ability to access your accounts without ever knowing your actual password.

The campaign specifically exploits the relatively open nature of hotel and airport Wi-Fi networks. These public connections lack the security barriers found in corporate or home networks, making them ideal hunting grounds for criminals. Once connected to a compromised network, attackers can intercept the data flowing between devices and cloud storage services, capturing authentication information in transit.

What This Means

This represents a meaningful shift in how cybercriminals approach account takeover attacks. Previously, hackers primarily focused on stealing passwords through phishing emails or data breaches. This new technique sidesteps password protection entirely by targeting the authentication system itself. It's like stealing someone's actual house key instead of forcing the lock.

The involvement of a Russian state-affiliated group suggests this isn't random cybercrime—it appears to be part of a broader intelligence-gathering operation. Business travelers in particular represent high-value targets because they often access corporate email, financial platforms, and sensitive company systems using the same devices and accounts.

Why You Should Care

If you travel frequently and use hotel or airport internet, your accounts could be at risk. Consider these scenarios:

The damage extends beyond your personal accounts. If you work for a company, compromised access puts your entire organization at risk.

What You Can Do

The rise of passkey technology represents genuine security progress, but this attack reminds us that no authentication method is foolproof without proper network security awareness.

📎 This is original ITVedas reporting. This story was inspired by coverage from bleepingcomputer.com. Visit the source for their original reporting.

Want to understand the technology behind this story? ITVedas has beginner-friendly guides on every IT topic.

Explore IT Chapters →