A New Twist on an Old Public Wi-Fi Risk

Security researchers have identified a threat actor hacking into public Wi-Fi gateways, the hardware behind captive Wi-Fi portals you see at airports, hotels, cafes, and conference centers, in order to harvest corporate Microsoft 365 credentials. Rather than setting up a fake hotspot or spoofing a login page from scratch, the attacker is compromising the legitimate infrastructure that businesses and venues already rely on to authenticate guests before granting internet access.

This matters because captive portals are one of the most trusted, and least scrutinized, parts of the public Wi-Fi experience. Millions of travelers click through these "agree to terms and connect" pages every day without a second thought. If the gateway itself has been hijacked, the credential-harvesting page a user sees can look completely authentic, because in a sense, it is the real infrastructure, just repurposed for theft.

How the Attack Works

Captive Wi-Fi gateways are the appliances that sit between a public network and the open internet, typically prompting users to log in, accept terms, or enter an email address before browsing begins. According to reporting on this campaign, the threat actor has been compromising these appliances directly and using them to target the Microsoft 365 accounts of corporate employees while they travel.

Because Microsoft 365 is the backbone of email, file storage, and collaboration for a huge share of businesses worldwide, a single set of stolen credentials can open the door to inboxes, shared documents, internal communications, and potentially deeper network access if multi-factor authentication isn't properly enforced. For attackers, targeting business travelers at the gateway level is efficient: instead of chasing individual victims, they compromise the choke point that many different travelers are forced to pass through.

This approach also sidesteps some of the usual advice about spotting fake hotspots. Users aren't necessarily connecting to a rogue network name or an obviously suspicious page. They're using the Wi-Fi the venue actually provides, which has simply been turned against them at the infrastructure level.

Why This Is a Privacy and Security Problem for Everyone

The implications here go beyond a single company's IT department. Public Wi-Fi has long been understood as a weak link in personal privacy, but this campaign highlights how that weakness scales when it hits business travelers carrying credentials to corporate systems. A compromised Microsoft 365 login isn't just an inconvenience, it can lead to business email compromise, data exposure, and further phishing campaigns launched from a trusted internal account.

It's a useful reminder that the tools people rely on for privacy and security have real, specific limits. As we've covered in our breakdown of what a VPN actually protects against, a VPN encrypts your traffic between your device and the VPN server, which is genuinely valuable on public Wi-Fi. But it doesn't stop you from typing your real credentials into a login screen that a captive portal itself has already compromised before your VPN connection even starts. Understanding that distinction is key to using these tools effectively rather than assuming they're a cure-all.

It's also worth noting that privacy tools like VPNs are increasingly part of broader policy conversations, including regulatory scrutiny such as the one discussed in our coverage of the UK's proposed VPN age verification rules. As these tools face more attention from regulators, understanding exactly what they do and don't protect against becomes even more important for everyday users and businesses alike.

What This Means For You

If you or your employees travel for work and routinely connect to public Wi-Fi in airports, hotels, or conference venues, this campaign is a signal to tighten habits around how corporate accounts are accessed outside the office. It doesn't mean public Wi-Fi should be avoided entirely, but it does mean the login moment, that captive portal screen, deserves more scrutiny than most people give it.

For IT and security teams, this is a strong argument for enforcing multi-factor authentication on all Microsoft 365 accounts without exception, since MFA can blunt the impact even if a password is stolen. It's also a reason to consider mobile hotspot use or a trusted VPN connection established before any sensitive login occurs, rather than relying on whatever network a venue provides by default.

Actionable Takeaways

  • Enable multi-factor authentication on all Microsoft 365 and other business accounts, so a stolen password alone isn't enough to grant access.
  • Avoid logging into corporate accounts immediately after connecting to a public Wi-Fi captive portal; where possible, use a cellular hotspot or connect through a VPN first.
  • Treat captive portal login pages with the same caution as any unfamiliar login screen, and never enter more information than a network truly requires to grant access.
  • Encourage traveling employees to report anything unusual about a Wi-Fi login experience, such as unexpected credential prompts, to their IT or security team.
  • Remember that a VPN is a valuable layer of protection on public Wi-Fi, but it isn't a substitute for caution at the login stage, understanding its real scope of protection helps you use it correctly.

As threat actors continue finding new ways to exploit the infrastructure travelers already trust, staying informed about how these attacks actually work, rather than relying on outdated assumptions about public Wi-Fi risk, is one of the most effective defenses available.