IT Starts with CareNeed support?
Talk to KPTech1300 303 173

Travel Wi-Fi warning: CaptiveCrunch targets Microsoft sign-ins

Microsoft Threat Intelligence has reported an active campaign it calls CaptiveCrunch, associated with a sub-cluster of Midnight Blizzard. The campaign has manipulated DNS and HTTP traffic on networks served by captive portals, including travel and hospitality environments, to redirect users toward attacker-controlled infrastructure.

Why this matters

Travellers often expect airport, hotel and venue Wi-Fi to redirect them to a sign-in page. That normal behaviour can make a malicious redirect harder to spot. Microsoft says the campaign has also used lookalike Microsoft domains and adversary-in-the-middle phishing techniques, including abuse of Microsoft Entra device-code authentication.

Recommended response

  • Prefer a trusted mobile hotspot or known network for sensitive sign-ins when travelling.
  • Be cautious if a public Wi-Fi portal suddenly asks you to authenticate to Microsoft 365.
  • Use phishing-resistant MFA where practical, such as passkeys or FIDO2 security keys.
  • Review unexpected Entra device registrations and revoke suspicious sessions promptly.
  • Keep endpoint protection and browsers up to date.

If you think a staff member has entered credentials into a suspicious page, change the password, revoke active sessions and have the account reviewed as soon as possible.

Source: Microsoft Threat Intelligence, 31 July 2026. This KPTech article is a plain-English summary with practical response guidance.