Your hotel Wi-Fi was compromised before you checked in.
Short answer
Hotel networks are a documented target for state-sponsored attackers and criminal groups. The risk lies in the network infrastructure rather than the hotel itself: routinely misconfigured, shared among hundreds of guests, and accessible to anyone in the building. The working assumption for any hotel stay is that the network is hostile, and the configuration of your devices should reflect that from the moment you connect.
Why hotel networks are different from home networks
A home network is managed by one household, uses credentials that are not shared broadly, and is accessed by a limited set of known devices. A hotel network is managed by hospitality IT staff whose primary concern is guest convenience, uses credentials that are distributed to every guest, and is simultaneously accessed by hundreds of people with unknown threat profiles and unknown devices.
The network configuration reflects these priorities. Encryption between devices on the same network is typically absent. Network isolation between guest devices is implemented inconsistently and often incompletely. The access point hardware may not have been updated since installation. And the physical access points themselves are in hallways, lobbies, and meeting rooms where they can be physically accessed by anyone who can get into the hotel.
Documented attacks against hotel networks
DarkHotel is the name security researchers gave to a series of attacks documented between 2007 and 2014 and continuing in evolved forms. The attacker group compromised hotel networks specifically to target high-value guests: executives, government officials, and research scientists. The attack delivered malware through the hotel’s software update mechanism, offering guests a legitimate-looking update prompt when they connected to the network. The malware gave the attacker persistent access to the device for collection of emails, documents, and credentials.
The targets were not random. Reservations were monitored to identify high-value guests, and the attack was timed to the specific check-in. The attack does not require the hotel to be compromised in advance, only that the attacker have access to the hotel network, which is something a paid reservation reliably provides.
Evil twin attacks require no compromise of the hotel’s infrastructure at all. An attacker creates a wireless access point with the same SSID as the hotel’s network. Devices that have previously connected to the hotel network connect automatically. The attacker performs man-in-the-middle operations on the traffic. The hotel’s actual network continues to function normally while the attack runs in parallel on the rogue access point.
What is actually at risk
Unencrypted traffic on a hotel network is visible to anyone with the capability to intercept it. In practice this means: login credentials sent over HTTP rather than HTTPS, unencrypted email protocols, and anything transmitted by applications that do not enforce encryption. The movement toward HTTPS by default has substantially reduced the practical attack surface compared to ten years ago. It has not eliminated it. Applications frequently leak data in plaintext even when the primary interface appears encrypted.
Lateral movement within the network is the more serious risk for high-value targets. If a device on the network has vulnerabilities, another device on the same network segment can exploit them without any action by the victim. Many corporate laptops have SMB sharing enabled. Many devices have management interfaces accessible on local networks that are not accessible from the internet. The hotel network puts all these devices within reach of each other.
Captive portal credential capture is a simple attack that requires minimal sophistication. The attacker creates a captive portal page that mimics the hotel’s login page. Guests submit their room number and surname to connect. The attacker collects those credentials. Combined with other information available from the hotel’s systems, this can enable social engineering attacks during the stay.
Operating safely on a hotel network
A VPN active from the moment you connect is the foundation of hotel network hygiene. A VPN encrypts your traffic between your device and the VPN server, meaning traffic intercepted on the hotel network is ciphertext rather than readable data. Use a VPN that does not log traffic and has been tested under a real legal request. Connect to the VPN before doing anything else on the hotel network.
Do not accept software updates offered over the hotel network. Legitimate operating system and application updates are delivered through the manufacturer’s update infrastructure, not through hotel Wi-Fi prompts. Any prompt to update software while connected to a hotel network should be treated as suspicious until verified through independent means.
Disable file sharing and network discovery on your device before connecting. On Windows, switch to the Public network profile. On macOS, disable file sharing in System Preferences before connecting to any unknown network. These settings prevent your device from advertising services to other devices on the same network.
Consider using your phone’s mobile data as a hotspot for laptop connections rather than the hotel network. Mobile data traffic is encrypted at the carrier level and does not put your laptop on a shared network with other guests. The cost of additional mobile data is usually less than the cost of a compromise. The full pre-travel security checklist includes this as a standard practice for high-risk destinations.
The physical access point risk
Access points in corridors and meeting rooms can be physically replaced with rogue devices that perform man-in-the-middle attacks on all traffic. This requires brief physical access to the access point, which a person with a hotel room key can obtain. The rogue device connects to the hotel’s network infrastructure and passes traffic through while recording or modifying it.
This attack is not common in budget hotels. It is documented in business hotels hosting high-value conferences, government delegations, and M&A meetings. If you are attending an event where the attendee list itself is sensitive, assume the network is adversarially controlled and operate exclusively over VPN or mobile data.
Frequently asked questions
Is the hotel Ethernet port safer than Wi-Fi?
Marginally. The wired connection reduces some wireless interception risks. The underlying network is still the same shared infrastructure. A device physically connected to the hotel network is still on the same network segment as other guests and is subject to the same lateral movement risks. A VPN remains necessary on wired hotel connections.
What about conference center Wi-Fi at professional events?
Treat it identically to hotel Wi-Fi. Conference networks are often less secured than hotel networks because they are set up quickly for the event period. The concentration of high-value targets at professional conferences makes them attractive for targeted attacks. The setup that protects you in the field should be active from the moment you connect to any network outside your control.
Should I use my phone’s hotspot instead of the hotel Wi-Fi?
Where the local mobile network is trustworthy, yes, the hotspot is materially safer than the hotel network because it removes the shared-infrastructure problem entirely. Where the local cellular network is itself a known surveillance target (some destinations, some carriers), the hotspot only changes the operator on the other side of the encryption boundary. The VPN-on-mobile combination remains the simplest baseline that holds across most travel scenarios, with the hotspot used in preference to hotel Wi-Fi whenever data costs allow.
Are luxury hotel networks any safer than budget chains?
Not in any way that matters operationally. Luxury hotel chains often run more sophisticated guest networks with portal authentication, but the underlying security model is the same: shared infrastructure, hospitality-grade IT staff, and guests with unknown threat profiles. The DarkHotel campaigns originally documented at high-end business hotels are the clearest demonstration that a higher room rate does not translate into a more defensible network. Treat every hotel network identically regardless of brand tier.
There’s no perfect setup. Anyone selling you perfect is selling fear. The goal is simple: make yourself a harder target than the person next to you.
