Shawn Freeman
CEO

Your sales lead checks into a hotel the night before a conference. She joins the guest Wi-Fi, clicks through the sign-in page, and her browser tells her a driver update is needed before the connection will work properly. The instructions are clear and the page looks like Windows. She follows them. Ten minutes later she is answering email and nothing seems wrong. Nothing will seem wrong for weeks.
On 31 July 2026, Microsoft Threat Intelligence published research on a campaign it calls CaptiveCrunch. Since early May, a Russian state-backed group has been tampering with traffic on guest networks at hotels, conference centres and other shared venues around the world, redirecting travellers through attacker infrastructure and delivering malware dressed up as ordinary updates.
This is different from the usual warning about public Wi-Fi. The attackers were not sitting in the lobby with a laptop. They compromised the sign-in portals themselves, and Microsoft found enough overlap in the equipment across affected venues to suspect that access sits in shared services used by many locations rather than in one hotel's router.
Below: what the campaign does, what it steals, why multi-factor authentication does not stop it on its own, and the specific changes worth making before your team's next trip.
Microsoft attributes the campaign to Storm-2945, an operational sub-cluster of Midnight Blizzard. Midnight Blizzard is the Russia-based actor that the US and UK governments have attributed to the SVR, Russia's foreign intelligence service. Its usual targets are governments, diplomatic bodies, non-governmental organizations and IT service providers across North America and Europe. The goal is intelligence collection, not a ransom note.
Since early May 2026, the group has been manipulating DNS and web traffic on networks that sit behind captive portals. ReliaQuest reported related DNS poisoning in the hospitality sector on 23 July. Microsoft has identified compromised Wi-Fi networks at hospitality organizations in several countries, and ReliaQuest has seen the same activity at conference centres and other shared venues, with corporate travellers as the apparent target.
💡 A captive portal is the "accept the terms and click connect" page you see before a guest network lets you online. It sits between your device and the internet, which is exactly what makes it valuable to an attacker.
One detail deserves attention. Microsoft noted common equipment and management systems across multiple affected networks, which suggests the activity may not be a series of isolated hotel break-ins.
⚠️ If the compromise sits upstream of the venue, a hotel can run its IT well and still serve poisoned traffic. Asking the front desk whether their Wi-Fi is safe will not produce a useful answer.
Every laptop and phone runs a quiet connectivity check when it joins a network. Windows, Android, Apple devices and most browsers do this to work out whether a captive portal is in the way. On a compromised network, the attacker answers that check with a page of their own.
What the traveller sees is a Windows update screen, a browser update prompt, a driver repair tool, or a verification check that says it failed and offers steps to fix it. Those steps usually ask the person to copy something and run it in Terminal or PowerShell. The industry calls this ClickFix, and it works because it turns the person into the installer. No security product stops a user from pasting a command they were told to paste.
🚨 If a network prompts you to install an update, a certificate, a driver tool or a security utility, that is the attack. Real operating system updates never arrive through a Wi-Fi login page.
Microsoft has also seen these pages offer an Android APK file, so phones and tablets are in scope, not only Windows laptops.
Three pieces of tooling do the work. Two run on the victim's machine and one is the attacker's own console.
Most owners assume multi-factor authentication (MFA) closes this off. It does not, for two reasons.
Stolen session tokens. When you sign in to Microsoft 365 and complete MFA, your device receives a token that says this person already proved who they are. ChocoShell collects those tokens. An attacker replaying one is never asked to authenticate, because as far as Microsoft 365 is concerned, they already did. It is the difference between stealing the ticket and stealing the wristband after you are already inside.
Device code phishing. Since mid-July, some CaptiveCrunch pages have displayed a code and asked the traveller to enter it on a real Microsoft sign-in page. The page is genuine and the address bar is correct, so nothing looks off. But the sign-in the person completes authorizes the attacker's session, not their own. Microsoft has tracked Midnight Blizzard using this technique since 2024. Wrapping it inside a hotel Wi-Fi flow makes it feel routine.
📋 Nobody at Always Beyond, Microsoft, or any vendor will ever ask you to type a code into a Microsoft sign-in page to get onto Wi-Fi. If that happens, stop and contact us through the Always Beyond Support Portal.
The simplest way to remove this risk is to stop using venue Wi-Fi for work. Here is how the options compare.
✅ The cheapest control on this page is a data plan. Cellular on a managed device removes the captive portal from the picture entirely for most trips, and it costs less than one hour of incident response.
Traveller habits help. The controls that matter are the ones that hold when someone makes a tired decision at 11pm in a hotel room. These are the changes Always Beyond configures and manages inside your Microsoft 365 tenant:
⚠️ If your tenant still allows legacy authentication or unrestricted device code sign-in, none of the traveller advice above will save you. Fix the tenant first, then train the people.
If a laptop is compromised on a trip and client information leaves with it, this stops being only an IT problem. Alberta's Personal Information Protection Act requires an organization to notify the Office of the Information and Privacy Commissioner of Alberta without unreasonable delay where a breach creates a real risk of significant harm to an individual. Activity that falls under PIPEDA carries its own reporting obligation, plus a requirement to keep records of every breach of security safeguards, whether or not it meets the reporting threshold.
Token theft makes the timing awkward. A stolen session can be used weeks after the trip, and the first visible sign is often a mail forwarding rule or a redirected payment rather than a security alert. Being able to show when the token was taken and what it touched depends entirely on logging you already had switched on.
⚠️ Cyber insurance renewals increasingly ask whether you enforce phishing-resistant MFA and restrict older authentication flows. Answering yes when the tenant configuration says otherwise becomes a claims problem later.
Send this to the team before conference season. It is six lines and it covers most of the risk.
✅ Run this as a ten minute item at a team meeting rather than a policy document nobody opens. The prompts in this campaign are convincing, and people spot them far more reliably once they have seen a screenshot.
No. Microsoft and ReliaQuest have both seen the activity at conference centres and other shared venues. Anywhere a captive portal serves a steady flow of business travellers is worth an attacker's time, which includes airport lounges and co-working space.
Only partly. A VPN protects traffic once the tunnel is up, but this attack usually lands before that, in the window where the device is still talking to the portal page. It also does nothing about malware you installed yourself after a convincing prompt. A VPN is worth having and is not a substitute for the tenant controls above.
Not inherently. Microsoft saw the same landing pages offering Android installer files, and published separate research days later on a macOS campaign using the same ClickFix approach. The technique targets the person, and the person is the same on every platform.
This kind of portal poisoning is not selective. Whoever joins the network gets served the same page. The actor's interest is in corporate travellers generally, and IT service providers and their clients are squarely inside its historical targeting. Being small is not a control.
Tell us. We check the device against the published indicators, review sign-in and token activity for the account, look for unexpected app consents or new mail rules, and revoke active sessions if anything looks wrong. That is a same-day exercise, not a project.
No. Manage the connection instead. A data plan, a properly configured tenant and a six-line briefing handle this without changing how your team works.
Not sure how your tenant would hold up? Always Beyond reviews Conditional Access, sign-in flows and travel device posture as part of your security baseline, then handles the rollout and the monitoring that follows. Reach out to start the conversation.
See exactly how your current IT setup measures up to our Hack Free standards. Enter your business email to receive: