Always Beyond White Icon Logo Small
Is Your Business Secure?
Take our FREE 2-minute IT Security Scorecard and get instant insights—no strings attached.
👉 Start Assessment
Insights & Guides
Cybersecurity & Risk

Hotel Wi-Fi Security: What CaptiveCrunch Means For Your Team

Russian state-backed attackers hijacked hotel and conference Wi-Fi sign-in portals worldwide. Here is what Canadian businesses should change before the next trip.
Aug 13, 2026
10 mins read

Your sales lead checks into a hotel the night before a conference. She joins the guest Wi-Fi, clicks through the sign-in page, and her browser tells her a driver update is needed before the connection will work properly. The instructions are clear and the page looks like Windows. She follows them. Ten minutes later she is answering email and nothing seems wrong. Nothing will seem wrong for weeks.

On 31 July 2026, Microsoft Threat Intelligence published research on a campaign it calls CaptiveCrunch. Since early May, a Russian state-backed group has been tampering with traffic on guest networks at hotels, conference centres and other shared venues around the world, redirecting travellers through attacker infrastructure and delivering malware dressed up as ordinary updates.

This is different from the usual warning about public Wi-Fi. The attackers were not sitting in the lobby with a laptop. They compromised the sign-in portals themselves, and Microsoft found enough overlap in the equipment across affected venues to suspect that access sits in shared services used by many locations rather than in one hotel's router.

Below: what the campaign does, what it steals, why multi-factor authentication does not stop it on its own, and the specific changes worth making before your team's next trip.

StatisticDescription
May 2026First confirmed captive portal compromises.
3Malware tools in the CaptiveCrunch kit.
0Extra MFA prompts once a token is stolen.
6Tenant controls that shut this down.
SourceMicrosoft Threat Intelligence, CaptiveCrunch research, 31 July 2026.

What CaptiveCrunch actually is

Microsoft attributes the campaign to Storm-2945, an operational sub-cluster of Midnight Blizzard. Midnight Blizzard is the Russia-based actor that the US and UK governments have attributed to the SVR, Russia's foreign intelligence service. Its usual targets are governments, diplomatic bodies, non-governmental organizations and IT service providers across North America and Europe. The goal is intelligence collection, not a ransom note.

Since early May 2026, the group has been manipulating DNS and web traffic on networks that sit behind captive portals. ReliaQuest reported related DNS poisoning in the hospitality sector on 23 July. Microsoft has identified compromised Wi-Fi networks at hospitality organizations in several countries, and ReliaQuest has seen the same activity at conference centres and other shared venues, with corporate travellers as the apparent target.

💡  A captive portal is the "accept the terms and click connect" page you see before a guest network lets you online. It sits between your device and the internet, which is exactly what makes it valuable to an attacker.

One detail deserves attention. Microsoft noted common equipment and management systems across multiple affected networks, which suggests the activity may not be a series of isolated hotel break-ins.

⚠️  If the compromise sits upstream of the venue, a hotel can run its IT well and still serve poisoned traffic. Asking the front desk whether their Wi-Fi is safe will not produce a useful answer.

The fake update prompt is the front door

Every laptop and phone runs a quiet connectivity check when it joins a network. Windows, Android, Apple devices and most browsers do this to work out whether a captive portal is in the way. On a compromised network, the attacker answers that check with a page of their own.

What the traveller sees is a Windows update screen, a browser update prompt, a driver repair tool, or a verification check that says it failed and offers steps to fix it. Those steps usually ask the person to copy something and run it in Terminal or PowerShell. The industry calls this ClickFix, and it works because it turns the person into the installer. No security product stops a user from pasting a command they were told to paste.

🚨  If a network prompts you to install an update, a certificate, a driver tool or a security utility, that is the attack. Real operating system updates never arrive through a Wi-Fi login page.

Microsoft has also seen these pages offer an Android APK file, so phones and tablets are in scope, not only Windows laptops.

What gets taken

Three pieces of tooling do the work. Two run on the victim's machine and one is the attacker's own console.

ToolWhat it doesWhy it matters to you
CornFlakeA remote access trojan that installs itself as a fake Windows service named "Cloud Sync Service" and rebuilds itself if you remove it. Records keystrokes, screenshots, clipboard, webcam and microphone, and copies documents off the machine.The attacker has a live seat at that laptop, including everything typed into it.
ChocoShellA PowerShell tool that runs entirely in memory. Harvests browser session cookies, saved passwords, Microsoft 365 sign-in tokens and stored Wi-Fi passwords, then disables the parts of Windows that would normally flag it.This is the payload that reaches your Microsoft 365 tenant, and it does not need your password to do it.
FruitStoneThe attacker's web console for managing infected machines, building new payloads and reviewing stolen screenshots, keystrokes and credentials.This is run as an operation with staff and process behind it, not as a one-off.

The part that gets past MFA

Most owners assume multi-factor authentication (MFA) closes this off. It does not, for two reasons.

Stolen session tokens. When you sign in to Microsoft 365 and complete MFA, your device receives a token that says this person already proved who they are. ChocoShell collects those tokens. An attacker replaying one is never asked to authenticate, because as far as Microsoft 365 is concerned, they already did. It is the difference between stealing the ticket and stealing the wristband after you are already inside.

Device code phishing. Since mid-July, some CaptiveCrunch pages have displayed a code and asked the traveller to enter it on a real Microsoft sign-in page. The page is genuine and the address bar is correct, so nothing looks off. But the sign-in the person completes authorizes the attacker's session, not their own. Microsoft has tracked Midnight Blizzard using this technique since 2024. Wrapping it inside a hotel Wi-Fi flow makes it feel routine.

📋  Nobody at Always Beyond, Microsoft, or any vendor will ever ask you to type a code into a Microsoft sign-in page to get onto Wi-Fi. If that happens, stop and contact us through the Always Beyond Support Portal.

How your team should connect

The simplest way to remove this risk is to stop using venue Wi-Fi for work. Here is how the options compare.

Connection methodRiskUse it when
Company mobile hotspot or eSIM data planLowDefault choice for anything work-related, on every trip.
Tethering to a managed company phoneLowPractical fallback when the hotspot did not make it into the bag.
Managed travel router with a tunnel back to your environmentLowLonger stays, multi-person trips, or work involving client data.
Venue Wi-Fi on a managed device behind a security service edgeModerateOnly when cellular is genuinely unavailable and tenant controls are enforced.
Venue Wi-Fi on an unmanaged or personal laptopHighNot for company work. Personal browsing at most, and even then be careful.
✅  The cheapest control on this page is a data plan. Cellular on a managed device removes the captive portal from the picture entirely for most trips, and it costs less than one hour of incident response.

What we change on the back end

Traveller habits help. The controls that matter are the ones that hold when someone makes a tired decision at 11pm in a hotel room. These are the changes Always Beyond configures and manages inside your Microsoft 365 tenant:

  1. Block the device code sign-in flow. Microsoft recommends turning it off wherever it is not needed. We set this in Conditional Access and maintain a short exception list for the few devices that genuinely require it.
  2. Move to phishing-resistant sign-in. Passkeys and hardware security keys defeat the lookalike Microsoft sign-in pages used in this campaign. We roll these out to leadership, finance and anyone who travels, first.
  3. Turn on sign-in risk policies with continuous access evaluation. When Microsoft flags a risky sign-in, access is revoked mid-session rather than at the next login attempt.
  4. Restrict which Wi-Fi networks a managed device may join. Windows can be configured through Intune so company laptops only connect to networks you have approved in advance.
  5. Put a security service edge in front of internet traffic. Traffic leaves the laptop through your controls regardless of whether the underlying network can be trusted.
  6. Hunt for the aftermath. Defender for Endpoint carries specific detections for this campaign, and Microsoft published indicators of compromise. We check devices and sign-in logs against them.
⚠️  If your tenant still allows legacy authentication or unrestricted device code sign-in, none of the traveller advice above will save you. Fix the tenant first, then train the people.

The compliance side for Canadian businesses

If a laptop is compromised on a trip and client information leaves with it, this stops being only an IT problem. Alberta's Personal Information Protection Act requires an organization to notify the Office of the Information and Privacy Commissioner of Alberta without unreasonable delay where a breach creates a real risk of significant harm to an individual. Activity that falls under PIPEDA carries its own reporting obligation, plus a requirement to keep records of every breach of security safeguards, whether or not it meets the reporting threshold.

Token theft makes the timing awkward. A stolen session can be used weeks after the trip, and the first visible sign is often a mail forwarding rule or a redirected payment rather than a security alert. Being able to show when the token was taken and what it touched depends entirely on logging you already had switched on.

⚠️  Cyber insurance renewals increasingly ask whether you enforce phishing-resistant MFA and restrict older authentication flows. Answering yes when the tenant configuration says otherwise becomes a claims problem later.

A short briefing for anyone travelling

Send this to the team before conference season. It is six lines and it covers most of the risk.

  • Use cellular data for work. Treat hotel, airport and conference Wi-Fi as a last resort.
  • Never install an update, driver, certificate or verification tool offered by a network.
  • Never paste a command into Terminal or PowerShell because a web page told you to.
  • Never enter a code on a Microsoft sign-in page in order to get onto Wi-Fi.
  • Never register for guest Wi-Fi with your work email and password. Use a personal address.
  • Report anything odd the same day, even if you are not sure. Early is cheap. Late is not.
✅  Run this as a ten minute item at a team meeting rather than a policy document nobody opens. The prompts in this campaign are convincing, and people spot them far more reliably once they have seen a screenshot.

Frequently asked questions

Is this only a hotel problem?

No. Microsoft and ReliaQuest have both seen the activity at conference centres and other shared venues. Anywhere a captive portal serves a steady flow of business travellers is worth an attacker's time, which includes airport lounges and co-working space.

Does a VPN solve it?

Only partly. A VPN protects traffic once the tunnel is up, but this attack usually lands before that, in the window where the device is still talking to the portal page. It also does nothing about malware you installed yourself after a convincing prompt. A VPN is worth having and is not a substitute for the tenant controls above.

Are Macs and iPhones safe?

Not inherently. Microsoft saw the same landing pages offering Android installer files, and published separate research days later on a macOS campaign using the same ClickFix approach. The technique targets the person, and the person is the same on every platform.

We are a small Alberta company. Would anyone actually bother with us?

This kind of portal poisoning is not selective. Whoever joins the network gets served the same page. The actor's interest is in corporate travellers generally, and IT service providers and their clients are squarely inside its historical targeting. Being small is not a control.

Someone on our team used hotel Wi-Fi last month. What should we do?

Tell us. We check the device against the published indicators, review sign-in and token activity for the account, look for unexpected app consents or new mail rules, and revoke active sessions if anything looks wrong. That is a same-day exercise, not a project.

Should we stop letting staff travel with laptops?

No. Manage the connection instead. A data plan, a properly configured tenant and a six-line briefing handle this without changing how your team works.

Not sure how your tenant would hold up? Always Beyond reviews Conditional Access, sign-in flows and travel device posture as part of your security baseline, then handles the rollout and the monitoring that follows. Reach out to start the conversation.
On this page

Ready to Make IT One Less Thing to Worry About?

Book a no-pressure consultation to see how Always Beyond can help you simplify, secure, and future-proof your IT.

See exactly how your current IT setup measures up to our Hack Free standards. Enter your business email to receive:

  • Free 10-point security scorecard for your business
  • Complete Hack Free Guarantee eligibility checklist
  • Exclusive case studies from our protected clients