Public WiFi · security

A hijacked WiFi login page can't infect you. Being talked into running something can.

On 31 July 2026 Microsoft published its analysis of CaptiveCrunch, a campaign that takes over captive portals — the sign-in page a hotel or venue network puts in front of the internet — and uses them to manipulate traffic and push a fake browser or system update.

Who it is aimed at: corporate travellers on Windows with Microsoft 365 accounts. Microsoft attributes it to Storm-2945, a sub-cluster of the actor it tracks as Midnight Blizzard, and describes the goal as account access. If you are a holidaymaker with an iPhone, your exposure is far lower. The habits below are worth having anyway, and the best one is free.

Documented by Microsoft, 31 July 2026Infection needs you to run somethingThe most effective fix costs nothing
The chain

How CaptiveCrunch works, step by step

Four stages, as Microsoft describes them. Notice where the traveller has to act — that is where the chain breaks.

1 · The portal is taken over

Attackers gain control of a venue network's captive portal — the page you see before the internet works — and redirect DNS and HTTP traffic through their own infrastructure.

2 · A fake update appears

Instead of the page you expected, you get a browser or system update prompt. Microsoft calls the technique ClickFix: the page asks you to copy a command and run it yourself.

3 · The command installs malware

Running it delivers CornFlake, a Windows remote-access tool that logs keystrokes and steals browser passwords, or ChocoShell, a PowerShell infostealer that takes session cookies and Microsoft 365 tokens.

4 · Or you approve their session

Since 16 July 2026 some pages instead run device code phishing: you are given a code to type into the real Microsoft sign-in page, which signs the attacker in as you.

The one thing worth remembering

Connecting to the network is not what infects you. Every version of this chain needs a human step — pasting a command into a terminal, or typing a code into a sign-in page. Nothing installs itself just because you joined the WiFi.

Defences that work

What actually helps, in order

Ordered by how much of the chain each one removes. The first item removes all of it — and it is Microsoft's own first recommendation.

  1. 1Use your own mobile dataA phone hotspot, a travel eSIM or any cellular connection skips the venue network entirely: no captive portal, no manipulated DNS, nothing to take over. This is Microsoft's first recommendation and the only item here that removes the whole chain.
  2. 2Never install an "update" offered by a WiFi login pageA legitimate captive portal asks you to accept terms, enter an email or type an SMS code. It has no reason to update your browser or your operating system. Install updates only through the system's own updater.
  3. 3Never paste a command from a web page into PowerShell or TerminalThis is the ClickFix step, and the rule is worth keeping well beyond this campaign. Microsoft calls out prompts that invoke cmd.exe, PowerShell, rundll32.exe or mshta.exe. If a web page wants you in a terminal, the page is the problem.
  4. 4Don't reuse work credentials on a hotel sign-in pageRegistration pages ask for a name, a room number, an email. Give them the minimum, and never the password you use for work. Microsoft also suggests limiting how much you tell a venue form about your employer and your travel.
  5. 5Passkeys and MFA — and, for organisations, block device code flowPasswordless sign-in with passkeys blunts stolen credentials. For IT teams, Microsoft's specific advice is to permit the OAuth device code flow only where it is needed and block it everywhere else in Conditional Access, alongside sign-in risk policies and monitoring of risky sign-in reports.
  6. 6A VPN — as an extra layer, not as the answerGenuinely useful once you are on the network. But it covers one link in the chain above, and not the decisive one. The table below is the honest version.
Partner · affiliate

One layer of several

A VPN is worth having. Here is exactly what it does.

Encrypting your traffic on a shared network is a real benefit, and NordVPN does it well. It is not a defence against the chain above, and we would rather say so than sell you a false sense of safety.

Covers

  • Snooping on a shared network
  • DNS and HTTP manipulation, once connected
  • Home banking and apps that block foreign IPs

Does not cover

  • The WiFi sign-in page — it loads first
  • Anything you are persuaded to run
  • A sign-in you approve yourself

Big savingon 2-yr plans · price at checkout

Affiliate link — Packset may earn a commission. It never changes what we recommend or the price you pay.

The honest table

What a VPN actually covers here

We earn a commission when someone buys a VPN through this site, so here is the version that is not a sales pitch — checked link by link against what Microsoft describes.

Link in the chainDNS and HTTP manipulation on the network
Does a VPN stop it?Yes
WhyOnce the tunnel is up, your traffic is encrypted and resolved outside the venue's network. This is the part a VPN is for.
Link in the chainThe captive portal itself
Does a VPN stop it?No
WhyYou have to load and pass the sign-in page before you have internet, so before any tunnel exists. That is exactly where the fake update is served.
Link in the chainClickFix — you run the command
Does a VPN stop it?No
WhySocial engineering. The tunnel carries the download as faithfully as it carries anything else.
Link in the chainDevice code phishing
Does a VPN stop it?No
WhyThe code is typed into the genuine Microsoft sign-in page. Nothing about the connection is wrong; the approval is.
Link in the chainMalware already on the device
Does a VPN stop it?No
WhyIt sends data out over whatever connection is available, an encrypted one included.

One link out of five, and not the decisive one. A VPN is a reasonable layer against the ordinary risks of a shared network, and that is what we recommend it as. It is not a defence against this campaign, and anyone selling it to you as one is overselling.

The same applies to the threat-protection and DNS-filtering features bundled with VPN apps: they block domains already known to be malicious, which does nothing about infrastructure stood up for a fresh campaign.

And sometimes plan B is not available

Our own airport WiFi records include airports where travellers report VPNs being blocked outright — mostly in mainland China. That is the practical argument for plan A: if your connectivity depends on a tunnel you may not be able to open, bring your own data instead.

Browse airport WiFi records
Questions

Public WiFi, answered honestly

For ordinary browsing on an up-to-date phone, generally yes. The compromises Microsoft identified are at hospitality-related organisations — hotels, conference centres and shared venues — plus other networks running the same captive-portal equipment; no specific airport is named, and no figures are published for how many networks were affected anywhere. Microsoft's own advice is broader, and it does name them: treat hotel, conference and airport networks alike as untrustworthy. What makes any of them worth a second thought is the same thing: the captive portal is a web page somebody else controls. Treat what it shows you as untrusted and it is a much smaller problem.

Everything on this page comes from Microsoft Security's report of 31 July 2026, CaptiveCrunch: Midnight Blizzard targets travelers worldwide. Where Microsoft publishes no number, neither do we.

Plan the trip
Sort your connectivity before you land

Decide how you will get online — on your own data or on theirs — while you are still packing, not standing at a hotel desk.

Plan my trip