Man using a smartphone inside a hotel room.
© Tero Vesalainen/Shutterstock.com
No AI-generated content: this article is written and researched by humans
Table of contents

With summer holiday planning in the US on the up, experts are urging vacationers to watch out for malicious cybersecurity threats at hotels and other destinations.

Cybercriminals can take advantage of travelers’ laidback holiday spirit and infect their devices with malware or snoop on their activities while their guard is down.

Adrianus Warmenhoven, a cybersecurity specialist at NordVPN, warns that there are several ways for bad actors to target guests, including unsafe public Wi-Fi connections, USB charger slots, and compromised Smart TVs.

The security concerns highlight the need for greater consumer awareness and to maintain good cyber hygiene, no matter where you are.

Dangers of Hotel Wi-Fi Connections: Data Theft, Stalking, and Malware

Hotel Wi-Fi generally prioritizes convenience over security. When it becomes more important to offer guests Wi-Fi than to maintain high standards of protection, a lax security environment can emerge.

“Hackers can use a hotel’s cybersecurity vulnerabilities in several ways to reach you even in your room,” Warmenhoven said. “So while you’re on vacation and using the internet connection of where you’re staying, you should be cautious and manage cybersecurity risks.”

This sentiment was shared by the FBI in an advisory on the dangers of teleworking at hotels, which stated that there is no hotel industry standard for secure Wi-Fi access.

“Smaller hotels will often post placards at the service desk stating the password for Wi-Fi access, and change this password very infrequently,” the FBI advisory reads.

“At its most robust, access to a hotel Wi-Fi network is typically governed by a combination of room number and password. This combination only governs devices accessing the hotel’s network but does not provide a secure internet connection.”

As a consequence, malicious actors can compromise these networks and target guests in a number of ways. This includes monitoring internet activity and redirecting victims to fake login pages or other malicious sites. In the latter, the bad actors can either install malware onto the guests’ devices or nudge them to hand over personal or payment data.

Both the FBI and NordVPN have highlighted another common deceitful tactic known as “evil twin networks.”

Cybercriminals are able to create phony, unprotected Wi-Fi hotspots with unassuming names “like ‘Guest Wi-Fi’ or ‘Free Hotel Wi-Fi’ — and steal private information this way,” Warmenhoven said.

Tips to Stay Safe on Hotel Wi-Fi

The most important step in protecting yourself from these threats is to not blindly trust any hotel Wi-Fi network. Warmenhoven reminds travelers to be wary of any network that is not password protected.

“To avoid being hacked through hotel Wi-Fi, travelers must take a few steps,” Warmenhoven said. “First, ask the person at the reception desk to give the exact name and password for the provided Wi-Fi to avoid connecting to an ‘evil twin’ network.”

Even connecting to the right hotspot has huge security risks. The second step is to use a VPN to encrypt your data, which prevents third parties from intercepting it.

NordVPN, the service Warmenhoven works for himself, is used by millions already and is praised in many VPN reviews for its high performance.

Lastly, Warmenhoven reminds vacationers to use a firewall to filter out internet traffic. This, and equipping your devices with antivirus software operating in real-time, can amp up your cybersecurity.

If you’re using a hotel network without a VPN, do not log in to any sensitive accounts, such as your work email or bank account. If you’re prompted to do so upon login, make sure not to provide real personal information, such as passport numbers, date of birth, email, or phone numbers.

USB Charging Ports and ‘Juice Jacking’

While USB charging ports may seem convenient, especially for travelers who carry a different type of charging plug, they can pose severe security risks. Malicious actors can tamper with public USB charging ports and modify them to inject devices with info-stealing malware. This can allow actors to swipe credit card information, passwords, addresses and other sensitive data.

This type of attack is known as “Juice Jacking.” Recently, the FBI warned against using free USB charging stations in public places such as airports, shopping centers, and hotels. Instead, experts advise travelers to rely on wall socket chargers.

“Safe device charging on your way to your vacation spot might be challenging because you must carry a power bank or USB data blocker, but hotel rooms always have a socket. Usually, it’s the safest way to charge your devices,” Warmenhoven said.

Smart TV Snooping Concerns

It is now common for hotels to offer more Wi-Fi-connected devices in rooms, such as Smart TVs, to allow guests to access popular streaming sites like Netflix during their stay. However, Smart TVs have privacy risks, as they can store personal information such as browsing history and search queries. Many Smart TVs also have built-in microphones and cameras.

Couple that with the fact these Smart TVs are connected to the local Wi-Fi network — which can have questionable security — and malicious actors could potentially compromise these devices and use them for cyberstalking or to steal customer information.

To protect yourself, experts advise unplugging Smart TVs when they are not in use, covering the webcam, and avoiding logging in with personal login credentials.

Experts: Turn Off Automatic Connections, Watch Out for Phishing Attacks

NordVPN advises turning off automatic connections to Wi-Fi on smartphones and other devices. Staying connected to unprotected networks can leave your device vulnerable, even when it is not in use. Additionally, they recommend auto-connecting to security apps such as firewalls or VPNs to ensure that your device stays protected at all times.

Phishing attacks are another persistent threat that travelers need to be on the lookout for. NordVPN noted the example of the cybercrime group DarkHotel, which uses its access to unsecured Wi-Fi networks to launch highly tailored and convincing phishing attacks.

According to SecureList, DarkHotel usually goes after guests in luxury hotels with a combination of sophisticated techniques such as spear phishing, trojans, and botnet automation with the aim of stealing confidential information.

“Effective protection from sophisticated cyberattacks is possible by using trusted VPN and internet security apps as well as regularly updating software,” said Warmenhoven.

“Nevertheless, travelers should always be aware of phishing attacks: Verify the authenticity of suspicious emails and executable files and pay attention to odd spelling. These habits remain valuable during vacation as well as when you return to the office,” Warmenhoven added.

Leave a comment