Microsoft Threat Intelligence has reported an active campaign it calls CaptiveCrunch, associated with a sub-cluster of Midnight Blizzard. The campaign has manipulated DNS and HTTP traffic on networks served by captive portals, including travel and hospitality environments, to redirect users toward attacker-controlled infrastructure.
Why this matters
Travellers often expect airport, hotel and venue Wi-Fi to redirect them to a sign-in page. That normal behaviour can make a malicious redirect harder to spot. Microsoft says the campaign has also used lookalike Microsoft domains and adversary-in-the-middle phishing techniques, including abuse of Microsoft Entra device-code authentication.
Recommended response
- Prefer a trusted mobile hotspot or known network for sensitive sign-ins when travelling.
- Be cautious if a public Wi-Fi portal suddenly asks you to authenticate to Microsoft 365.
- Use phishing-resistant MFA where practical, such as passkeys or FIDO2 security keys.
- Review unexpected Entra device registrations and revoke suspicious sessions promptly.
- Keep endpoint protection and browsers up to date.
If you think a staff member has entered credentials into a suspicious page, change the password, revoke active sessions and have the account reviewed as soon as possible.
Phishing continues to evolve beyond the obvious fake-email link. Microsoft’s Q2 2026 threat review highlights QR-code lures, CAPTCHA-gated phishing pages, business email compromise and increasing use of Microsoft Teams for social engineering.
What businesses should watch for
- QR codes in invoices, delivery notices or account-security messages.
- CAPTCHA pages that appear before an unexpected Microsoft sign-in.
- External Teams chats claiming to be IT support, a supplier or a senior manager.
- Urgent requests to change bank details, buy gift cards or approve unusual payments.
Recommended response
Train staff to verify unusual requests through a second channel, protect Microsoft 365 with MFA, review external Teams access, and use modern email security controls. Payment and bank-detail changes should always be independently verified using a known phone number.
Microsoft Threat Intelligence is tracking DeadLock as an emerging financially motivated ransomware operation. The group uses a Rust-based encryptor and combines file encryption with data theft and extortion pressure.
The practical lesson
The ransomware name may change, but the defensive priorities remain consistent: reduce the chance of initial access, limit how far an attacker can move, and make recovery possible without relying on the attacker.
Recommended response
- Apply security updates promptly, especially to internet-facing systems.
- Use MFA and remove unnecessary administrator privileges.
- Maintain monitored endpoint detection and response.
- Keep tested backups with at least one protected or immutable copy.
- Segment important systems where practical.
- Have a documented incident-response and recovery process.
Backups are particularly important, but they should be tested. A backup that has never been restored is only an assumption.
Many successful cyberattacks do not begin with a mysterious new zero-day. They begin with an internet-facing firewall, VPN, server or application that is running a vulnerability already known to be exploited in the real world.
CISA maintains a Known Exploited Vulnerabilities catalogue specifically to identify vulnerabilities with evidence of active exploitation.
Recommended response
- Know which systems are exposed to the internet.
- Maintain an accurate device and software inventory.
- Prioritise patches for actively exploited vulnerabilities.
- Replace or isolate products that are no longer supported.
- Monitor firewalls, VPNs and remote-access systems for suspicious activity.
For small businesses, good patch management is one of the highest-value security controls because it removes known paths attackers are already using.