A hijacked captive portal can do more than annoy travelers. It can steer their device to attacker-chosen update pages or a real Microsoft sign-in flow, which turns hotel Wi‑Fi into a path to surveillance malware or an MFA-satisfied session.
Microsoft says the campaign has run since early May across hospitality networks in several countries. On compromised gateways, the portal also served as DNS, letting attackers forge answers, redirect update checks, and since July 16 push some victims into Microsoft's device-code flow; CornFlake then captured webcam, microphone, keystrokes, cookies, and cloud tokens.
The risk is broader than one infected laptop. A traveler's corporate identity can be handed over through a legitimate login page, and the session can survive the usual password-reset style response.