SOCLYDE logo
Current languageEN
Security newsSecurityWi-FiCredentials

Captivecrunch: when hotel wi-fi becomes a credential trap

The CaptiveCrunch campaign hijacks hotel captive portals to deliver fake updates and steal business access. Here is what SMB teams should learn.

Business traveler facing a compromised hotel Wi-Fi portal

In summary

  • Microsoft documented CaptiveCrunch, a campaign observed since May 2026 on captive-portal Wi-Fi networks.
  • A compromised portal can redirect travelers to a fake update, a login page, or a device-code authentication flow.
  • The safest travel rule is never to install software or approve an authentication request offered by public Wi-Fi.
Article contents

A connection that looks ordinary

On July 31, 2026, Microsoft Threat Intelligence published an analysis of a campaign called CaptiveCrunch. Since early May, attackers have been manipulating traffic on networks that use captive portals, particularly in hospitality. The activity also involves conference centers and other shared venues; initial reporting by ReliaQuest, cited by specialist coverage, suggests that business travelers are a preferred target.

The lesson is not that every hotel Wi-Fi network is dangerous. It is that a network can be genuine and provided by the right venue while still presenting an attacker-controlled page if the equipment managing the portal has been compromised.

The captive portal as a trust boundary

When a laptop or phone joins public Wi-Fi, the network tells it where to find certain services, including the sign-in page. Normally this is invisible. In CaptiveCrunch, Microsoft observed DNS and HTTP manipulation that redirected users to attacker-controlled infrastructure.

Several follow-on actions were observed: fake browser or operating-system updates, Microsoft 365 pages designed to capture credentials, and, since July 16, abuse of the device-code authentication flow. The delivered malware could collect files, keystrokes, credentials, and session tokens.

Why the page can feel legitimate

A page that appears immediately after joining Wi-Fi benefits from the context. The user expects to click, accept, or wait, so a software update can look like a normal part of getting online.

The device-code flow is even more deceptive. It is a legitimate Microsoft feature, but an attacker can provide a code and persuade the victim to enter it on the real sign-in site. The page is genuine; the session belongs to the attacker. Approving MFA in that situation does not make the request legitimate.

Rules worth sharing with a team

While traveling, one simple rule blocks most of the scenarios described: a captive portal may request network access, but it should never request a work password, a system update, a Microsoft device code, or an unexpected MFA approval.

In practice:

  1. Use your phone’s hotspot for sensitive work, or a full-tunnel VPN already configured by your organization.
  2. Do not install software or run commands suggested by a page that appeared after joining Wi-Fi.
  3. Reject any device-code or MFA request that you did not initiate yourself.
  4. If you must sign in, open the usual bookmark directly from an up-to-date device and verify the domain and the context of the request.
  5. Report unusual pages to IT immediately, even if you did not install anything.

What this means for an SMB

Security does not stop at the office. A traveling employee may have several sensitive accounts on one laptop: email, invoicing, CRM, document storage, and administration tools. A stolen session token or password can therefore be more valuable than the device itself.

Reducing the impact requires unique secrets, phishing-resistant MFA where available, short-lived sessions, and the ability to revoke access quickly. Soclyde can help with the secret-management layer: generate different passwords for each service and keep them in a local-first vault. That does not secure public Wi-Fi or a Microsoft 365 configuration, but it limits the blast radius of a compromise and avoids centralizing every credential in a cloud repository.

To review your team’s practices, read the Soclyde guide to local-first password managers.

Frequently asked questions

What is a captive portal?

It is the page shown before access to hotel, conference-center, or airport Wi-Fi. It may ask you to accept terms or enter a venue-provided access code.

Does MFA protect against CaptiveCrunch?

MFA remains essential, but some scenarios abuse a legitimate device-code flow to authenticate the attacker’s session. An unexpected approval should therefore be rejected, even when the Microsoft page is genuine.

What should someone do after following a fake update?

Isolate the device, alert IT, revoke the affected sessions and tokens from a clean device, and have the workstation checked before using it for work again.

References

Sources and references

Need advice?

Design your password strategy with Soclyde

Schedule a dedicated walkthrough with the team to see how local-first security adapts to your stack.

Talk with us

Keep reading