- › Microsoft detailed CaptiveCrunch, an operation by a Midnight Blizzard sub-cluster that has compromised the real sign-in portals of hotels since May 2026 to deliver malware and steal credentials from travelers.
- › The captive portal is one of the few pages people are taught to accept without examining, because scrutinizing it has never once been rewarded.
- › Travel strips away the conditions that make careful judgment possible: unfamiliar surroundings, fatigue, time pressure, and a task that stands between the person and everything else they need to do.
- › Telling travelers to be more careful at the moment they have the least capacity for care is a plan that fails quietly.
- › Give people a route that avoids the decision, like a cellular hotspot and phishing-resistant authentication, and make the awkward call easy when something looks wrong.
I want to talk about a page nobody reads.
You know the one. You land somewhere after a long flight, you open your laptop in the room, and the browser throws up a sign-in screen with the hotel’s name on it. Maybe it wants your room number. Maybe your last name. Maybe just a click on a button that says Connect. You fill it in without thinking, the internet appears, and you get on with the evening. That page has passed in front of you a hundred times and I would guess you have never once looked at it closely.
Microsoft published research this week on an operation it calls CaptiveCrunch. A sub-cluster of the Russian actor Midnight Blizzard has been compromising the actual sign-in portals of hotels and other hospitality organizations since May, using them to deliver malware to travelers and take their credentials. Not a fake network with a lookalike name. The real portal, at the real hotel, serving something extra.
I find this one genuinely interesting, and not for the technical reason. It is interesting because of what it says about how we have trained people.
We Taught Them Not to Look
Think about what a captive portal has meant to a traveler for the last fifteen years. It is friction. It is the thing standing between you and the work you flew here to do. Every time you have encountered one, the correct move has been to get through it as fast as possible with the minimum amount of attention, and every time you have done that, it worked out fine.
That is a lesson, delivered a hundred times, with a consistent reward. Nobody wrote it in a policy. Nobody ran a training module on it. We built it into people by repetition, and we built it well.
Now consider what we ask of that same person in a security awareness session. Slow down. Read the URL. Check the certificate. Ask whether this page should be asking you for this. Those instructions are fine in a conference room. They are asking someone to reverse a deeply grooved habit at the exact moment the habit is strongest, in a hotel room at eleven at night, on the one page they have learned carries no information worth reading.
When I look at an attack like this, the question I care about is not why the traveler did not catch it. The question is what we would have had to build differently for catching it to be a realistic thing to expect.
Travel Takes Away Everything Careful Judgment Needs
Here is the part I think gets underweighted in most programs. Attention is not a personality trait. It is a resource, and travel drains it in every way at once.
The person is somewhere unfamiliar, so the ordinary background cues they use to notice that something is off are gone. They are tired, often across time zones. They are usually behind on something, because people travel for work in order to do work, and the laptop is opening at the end of a day rather than the start of one. And the task in front of them, connecting to the internet, sits between them and the thing they actually came to do, which is the category of task human beings are worst at attending to.
Every one of those conditions is baked into the situation. None of them is a character flaw. If you designed a scenario specifically to make a careful decision unlikely, it would look a lot like a business traveler on hotel wifi.
Attackers do not have to understand any of this in psychological terms to exploit it. They only have to notice which moments produce compliant, fast, unexamined behavior, and go stand in those moments. That is what this operation did.
What the Blame Reflex Costs You
There is a version of the response to this story that I would like to head off, because I have watched it happen and it does real damage.
Someone in a security team reads the Microsoft writeup, then sends a company-wide email that says, in effect, be careful on hotel wifi and do not enter your credentials into untrusted pages. The email feels like action. It documents that the organization warned people. And when a traveler gets caught anyway, the warning becomes the evidence that the traveler is the one who failed.
What that does to the traveler is bad. What it does to the next traveler is worse. Because the person who suspects something went sideways in a hotel room on a Tuesday now has to weigh reporting it against the certainty that the first question will be why they did the thing they were told not to do. Plenty of them will decide to wait and see. Some will decide it was probably nothing.
That delay is the actual cost. Credential theft is time-sensitive in both directions, and the hours between an incident and the report are the hours you would most want back. An organization that makes reporting feel like a confession is buying itself slower detection in exchange for the satisfaction of having been right in an email. This is the same dynamic underneath why punishment kills incident reporting, and it shows up here in a specific and expensive form.
Design the Decision Out
The useful move is to stop asking travelers to win a judgment call they are poorly positioned to win, and change what they are standing in.
Give them a network that skips the portal entirely. A cellular hotspot, or a phone tethered on a corporate plan, removes the captive portal from the trip. This is the single highest-value change available to you, and it gets made in procurement, on a purchase order, with nobody’s judgment tested at eleven at night. If your people travel regularly and you have not costed this out, that is the conversation worth having this week.
Make corporate credentials unusable on a page like this. Phishing-resistant authentication, passkeys and hardware keys rather than a password and a code, means that a traveler who does enter something into a compromised portal has handed over far less than they think. The mistake still happens. It just stops being expensive, which is a far more achievable goal than preventing it.
Tell people what to do instead of what to avoid. “Do not use untrusted wifi” gives a tired person nothing to act on, because the hotel network does not feel untrusted, it feels like the hotel. “Connect through your hotspot, and if you have to use hotel wifi, do not sign in to anything work-related until you are on the VPN” is a specific instruction someone can follow at eleven at night without deliberating.
Make the awkward call easy. Say plainly, in advance, that a traveler who thinks something odd happened should call regardless of how sure they are and regardless of whether they followed the guidance. Then make sure the first response to that call is thank you. The organizations that find out fast are the ones where calling did not cost anybody anything the last time somebody did it.
The Habit Was Not a Mistake
The thing I keep coming back to with CaptiveCrunch is that the traveler’s behavior was correct for almost every instance they had ever encountered. Clicking through a captive portal without reading it has been the right call thousands of times. It stopped being the right call when someone got inside the real one, and there was no signal available to that person telling them the world had changed.
We do this a lot in security. We build an environment that teaches a behavior through relentless repetition, then we discover an attack that turns the behavior against people, and we describe the resulting incidents as human error. The error was ours, upstream, in a design that made the safe path and the fast path different paths.
Give your travelers a route where the fast path is also the safe one. They will take it every time, without a single training module, for the same reason they learned to click through the portal in the first place.
If you want to understand which of your habits, defaults, and travel practices an adversary could stand in front of, that is the work we do. Start with our free Human Attack Surface Score, or contact Grab The Axe and we will map the human side of your exposure the way an adversary reads it.
With a dual background in I/O Psychology (PhD Candidate) and Business Management (MBA), Marie bridges the gap between clinical rigor and operational strategy. She oversees B2B relations, compliance, and the 'business' of risk management.
View Author Page →