A hijacked WiFi login page can't infect you. Being talked into running something can.
On 31 July 2026 Microsoft published its analysis of CaptiveCrunch, a campaign that takes over captive portals — the sign-in page a hotel or venue network puts in front of the internet — and uses them to manipulate traffic and push a fake browser or system update.
Who it is aimed at: corporate travellers on Windows with Microsoft 365 accounts. Microsoft attributes it to Storm-2945, a sub-cluster of the actor it tracks as Midnight Blizzard, and describes the goal as account access. If you are a holidaymaker with an iPhone, your exposure is far lower. The habits below are worth having anyway, and the best one is free.
How CaptiveCrunch works, step by step
Four stages, as Microsoft describes them. Notice where the traveller has to act — that is where the chain breaks.
1 · The portal is taken over
Attackers gain control of a venue network's captive portal — the page you see before the internet works — and redirect DNS and HTTP traffic through their own infrastructure.
2 · A fake update appears
Instead of the page you expected, you get a browser or system update prompt. Microsoft calls the technique ClickFix: the page asks you to copy a command and run it yourself.
3 · The command installs malware
Running it delivers CornFlake, a Windows remote-access tool that logs keystrokes and steals browser passwords, or ChocoShell, a PowerShell infostealer that takes session cookies and Microsoft 365 tokens.
4 · Or you approve their session
Since 16 July 2026 some pages instead run device code phishing: you are given a code to type into the real Microsoft sign-in page, which signs the attacker in as you.
The one thing worth remembering
Connecting to the network is not what infects you. Every version of this chain needs a human step — pasting a command into a terminal, or typing a code into a sign-in page. Nothing installs itself just because you joined the WiFi.
What actually helps, in order
Ordered by how much of the chain each one removes. The first item removes all of it — and it is Microsoft's own first recommendation.
- 1Use your own mobile dataA phone hotspot, a travel eSIM or any cellular connection skips the venue network entirely: no captive portal, no manipulated DNS, nothing to take over. This is Microsoft's first recommendation and the only item here that removes the whole chain.
- 2Never install an "update" offered by a WiFi login pageA legitimate captive portal asks you to accept terms, enter an email or type an SMS code. It has no reason to update your browser or your operating system. Install updates only through the system's own updater.
- 3Never paste a command from a web page into PowerShell or TerminalThis is the ClickFix step, and the rule is worth keeping well beyond this campaign. Microsoft calls out prompts that invoke cmd.exe, PowerShell, rundll32.exe or mshta.exe. If a web page wants you in a terminal, the page is the problem.
- 4Don't reuse work credentials on a hotel sign-in pageRegistration pages ask for a name, a room number, an email. Give them the minimum, and never the password you use for work. Microsoft also suggests limiting how much you tell a venue form about your employer and your travel.
- 5Passkeys and MFA — and, for organisations, block device code flowPasswordless sign-in with passkeys blunts stolen credentials. For IT teams, Microsoft's specific advice is to permit the OAuth device code flow only where it is needed and block it everywhere else in Conditional Access, alongside sign-in risk policies and monitoring of risky sign-in reports.
- 6A VPN — as an extra layer, not as the answerGenuinely useful once you are on the network. But it covers one link in the chain above, and not the decisive one. The table below is the honest version.
One layer of several
A VPN is worth having. Here is exactly what it does.
Encrypting your traffic on a shared network is a real benefit, and NordVPN does it well. It is not a defence against the chain above, and we would rather say so than sell you a false sense of safety.
Covers
- Snooping on a shared network
- DNS and HTTP manipulation, once connected
- Home banking and apps that block foreign IPs
Does not cover
- The WiFi sign-in page — it loads first
- Anything you are persuaded to run
- A sign-in you approve yourself
Big savingon 2-yr plans · price at checkout
Affiliate link — Packset may earn a commission. It never changes what we recommend or the price you pay.
What a VPN actually covers here
We earn a commission when someone buys a VPN through this site, so here is the version that is not a sales pitch — checked link by link against what Microsoft describes.
One link out of five, and not the decisive one. A VPN is a reasonable layer against the ordinary risks of a shared network, and that is what we recommend it as. It is not a defence against this campaign, and anyone selling it to you as one is overselling.
The same applies to the threat-protection and DNS-filtering features bundled with VPN apps: they block domains already known to be malicious, which does nothing about infrastructure stood up for a fresh campaign.
And sometimes plan B is not available
Our own airport WiFi records include airports where travellers report VPNs being blocked outright — mostly in mainland China. That is the practical argument for plan A: if your connectivity depends on a tunnel you may not be able to open, bring your own data instead.
Browse airport WiFi recordsPublic WiFi, answered honestly
For ordinary browsing on an up-to-date phone, generally yes. The compromises Microsoft identified are at hospitality-related organisations — hotels, conference centres and shared venues — plus other networks running the same captive-portal equipment; no specific airport is named, and no figures are published for how many networks were affected anywhere. Microsoft's own advice is broader, and it does name them: treat hotel, conference and airport networks alike as untrustworthy. What makes any of them worth a second thought is the same thing: the captive portal is a web page somebody else controls. Treat what it shows you as untrusted and it is a much smaller problem.
Partly, and less than you would hope. It encrypts your traffic once it is running, which handles the DNS and HTTP manipulation. It does not cover the sign-in page itself, because that loads before the tunnel exists, and it cannot stop you running a command or approving a sign-in. The table above goes link by link.
The malware Microsoft describes is Windows-only, and the campaign targets corporate Microsoft 365 accounts. Microsoft adds that the same pages carry instructions for Android users to install an APK, and that the actor might be targeting Android as well. It does not describe macOS or iOS payloads — which is not the same as saying none exist, so the rule about never running what a WiFi page tells you to run still applies.
Assume the device is compromised and stop using it for anything sensitive. From a different, clean device, change the passwords of the accounts that device was signed into and sign out of all active sessions. If it is a work laptop, tell your IT or security team immediately: with Microsoft 365 tokens involved they can revoke sessions centrally, which you cannot. Reconnecting and hoping is not a plan.
The page that intercepts your browser when you join a network and asks you to accept terms, enter an email or type an SMS code before letting any traffic through. It is how most free WiFi is gated. Our airport pages record which sign-in method each airport uses.
Microsoft describes the goal as account access for corporate travellers, in order to collect intelligence. If you travel for work with a Windows laptop and a Microsoft 365 account, you fit the description more closely than most. If you do not, this particular campaign is unlikely to be aimed at you — the habits are still cheap.
Everything on this page comes from Microsoft Security's report of 31 July 2026, CaptiveCrunch: Midnight Blizzard targets travelers worldwide. Where Microsoft publishes no number, neither do we.
Decide how you will get online — on your own data or on theirs — while you are still packing, not standing at a hotel desk.