Microsoft is urging users to think twice before joining public Wi‑Fi, especially in hotels, airports, and conference centers. The company says a new campaign called CaptiveCrunch is taking advantage of familiar captive portal screens to trick travelers into sharing credentials or installing harmful software.
How the attack works
According to Microsoft Threat Intelligence, attackers are exploiting the login prompts that appear when devices connect to guest networks. Because these pop-ups are common, users may not notice when a fake page is trying to collect account details, device codes, or other sensitive information.
Security researchers note that the method can also redirect traffic, imitate system update alerts, and present misleading download requests. In some cases, users may see prompts that look like software updates, security checks, or utility installations, all designed to make the connection feel routine.
Safer ways to connect while traveling
Microsoft recommends using a private connection whenever possible, such as mobile data or a personal hotspot. For work devices, an enterprise-managed travel router or hotspot can add an encrypted layer between the device and company systems.
If public Wi‑Fi is unavoidable, a VPN with a kill switch can help reduce exposure if the connection drops. Travelers should also avoid downloading tools, certificates, or browser updates from portal pages and should never enter information beyond what is normally required to access the network.
Keeping devices, apps, and operating systems updated before a trip is another practical step, since current software helps close security gaps and reduces the need for on-the-road downloads.
As travel becomes more connected, stronger digital habits will likely shape safer and smarter mobility in the future.