Rank 4Adversary-in-the-middle
CaptiveCrunch captive-portal hijacking
Attackers manipulate DNS and HTTP traffic on captive-portal networks to redirect travelers into phishing flows and malware delivery.
- Momentum score
- 87
- Impact
- High
- Confidence
- High
Why it is rising
Microsoft observed the campaign from May onward and reported Windows malware, credential theft, session-token theft, and signs of Android targeting.
Six-month trajectory
Normalized weekly momentum for prototype validation
+24 over 4 weeks
Six months agoCurrent week
Marketing implications
High-level suggestions for buyer education. These are not claims that a product would have prevented a reported incident.
- 01Show why network trust disappears when employees work through captive portals.
- 02Position phishing-resistant access and endpoint controls as complementary defenses.
- 03Create traveler-focused guidance for high-risk roles and mobile workforces.