A captive portal is no longer just a nuisance screen. When an attacker controls it, a short hotel or conference Wi‑Fi session can turn into reusable Microsoft 365 credentials or a malware foothold that still works after the user leaves the network.
Microsoft says Midnight Blizzard’s CaptiveCrunch campaign has done this since February 2026, with traffic manipulation seen since early May. The group redirected victims to fake Microsoft 365 sign-ins, Entra ID device-code prompts, or bogus update pages, and tied the activity to CornFlake and ChocoShell; Microsoft also warned the affected portal gear may be shared across venues, widening the blast radius beyond one hotel.
The practical break is persistence. Once the attacker captures credentials, tokens, or a device approval, the user can be reached again from elsewhere, so a travel login can become long-lived espionage access.