In a detailed advisory published on its Security Blog on July 31, 2026, Microsoft has brought attention to a sophisticated and widespread threat campaign it has dubbed CaptiveCrunch. The campaign involves Russian hackers manipulating public Wi-Fi networks at hotels, airports, and conference centers to intercept user data, steal Microsoft account credentials, and deploy malicious software on travelers’ devices.
This warning follows earlier reports from independent security researchers, including a ReliaQuest analysis published in July, which highlighted similar DNS poisoning tactics in the hospitality sector. Microsoft’s own monitoring of the threat dates back to May 2026, and the company is now providing its own technical breakdown of how the attack unfolds and why it poses a significant risk to anyone relying on guest wireless networks.
How the CaptiveCrunch Attack Works
At the core of the CaptiveCrunch attack is the manipulation of Domain Name System (DNS) queries. When you connect to a compromised public Wi-Fi network, your device requests the address for a legitimate service, such as the Microsoft login portal. Instead of receiving the correct IP address, the attacker’s infrastructure intercepts this request and redirects your browser to a spoofed website that closely mimics the official Microsoft sign-in page.
Once you enter your credentials on this fake page, the attackers capture your username and password. More critically, they also harvest device and OAuth codes. These codes can be used to bypass two-factor authentication and take full control of your Microsoft account without needing your password again.
Beyond credential theft, the CaptiveCrunch campaign involves the installation of persistent malware. According to Microsoft, the malicious software deployed on infected devices includes Trojans capable of recording keystrokes, eavesdropping on device activity, and hijacking cameras for surveillance. The malware also forwards sensitive files and passwords to the attackers and establishes a remote access channel, giving the threat actors direct control over your device.
The Scope of the Threat
Microsoft attributes the CaptiveCrunch campaign to a hacker group known as Storm-2945. This group is closely associated with Midnight Blizzard, a well-known threat actor believed to be linked to the Russian Foreign Intelligence Service (SVR). Midnight Blizzard has previously been involved in high-profile cyberattacks targeting government and private sector organizations worldwide.
What makes this campaign particularly concerning is the scale of the infrastructure involved. Microsoft’s investigation has revealed notable commonalities in the networking equipment and management systems used across multiple affected public Wi-Fi networks. These similarities suggest that the attackers are not just compromising individual venues but are likely gaining access to shared services within the captive portal ecosystem. This means a single point of failure in a network management provider could expose users across dozens of hotels or airports simultaneously.
While Microsoft continues to investigate the initial compromise vector for these captive portal networks, the evidence points to a systemic vulnerability in how some public Wi-Fi providers manage their authentication systems. The attackers may be exploiting weaknesses in the captive portal software itself, rather than targeting individual network administrators.

What You Can Do to Stay Safe
Microsoft’s advisory includes clear guidance for travelers looking to protect themselves from the CaptiveCrunch attack and similar threats. The company emphasizes that users should treat hotel, conference, airport, and other guest wireless networks as inherently untrustworthy.
The most effective defense is to avoid using public Wi-Fi for sensitive activities. If you must connect, use a reputable Virtual Private Network (VPN) to encrypt your internet traffic. A VPN ensures that even if your connection is intercepted, the data remains unreadable to attackers. However, not all VPNs are created equal; free services may log your data or lack robust security features, so it is advisable to choose a paid service with a strong privacy track record.
Another reliable option is to use your mobile device as a personal hotspot. This allows you to bypass public Wi-Fi entirely and connect using your cellular data plan. While this may incur additional data charges, it significantly reduces your exposure to network-based attacks.
Microsoft also warns against downloading software updates, certificates, or applications presented through captive portals or web prompts on public networks. These prompts are often the delivery mechanism for the malware associated with the CaptiveCrunch campaign. If a website or app asks you to install something before you can access the internet, it is best to disconnect and seek an alternative connection method.

What This Means for You
For everyday Windows users, the CaptiveCrunch attack highlights the ongoing risks of relying on public Wi-Fi while traveling. Even if you are not actively logging into your Microsoft account, simply being connected to a compromised network can expose your device to malware and surveillance.
The association of this campaign with state-sponsored groups like Midnight Blizzard underscores the sophistication and resources behind these attacks. This is not a random act of cybercrime but a targeted effort that may have broader geopolitical implications.
By following Microsoft’s recommendations and adopting a cautious approach to public Wi-Fi, you can significantly reduce your risk of falling victim to the CaptiveCrunch attack. Prioritizing secure connections and being vigilant about suspicious prompts will help keep your data and devices safe while you are on the go.
Source: PCWorld
Over to you: Do you rely on public Wi-Fi while traveling, or do you always use a mobile hotspot to stay safe?



