You'll likely be safer if you've got an Apple device. I've never had one that didn't have problems connecting to captive WiFi services - usually when I desperately needed to be connected and had no mobile signal.
Russian spies turn public Wi-Fi into malware delivery systems
Conference-goers may want to think twice about connecting to public Wi-Fi after Microsoft disclosed that Russian foreign intelligence operatives (SVR) are compromising captive portal networks to deliver infostealers, keyloggers, and other malware. With the help of ReliaQuest's earlier work, Redmond fingered Storm-2945, a …
COMMENTS
-
Tuesday 4th August 2026 22:25 GMT anothercynic
OpenRoaming?
This is something this OpenRoaming malarkey could resolve, given that authentication is done by WPA-Enterprise, not some captive portal page.
Although, now that I am looking at it, even that would have a problem if they use a feature called CapPort (which stands for Captive Portal).
-
Wednesday 5th August 2026 05:52 GMT Anonymous Coward
Nice deflection (as always)
The main takeaway, in Microsoft's book, is to stop trusting
public Wi-FiMicrosoft so much.There. Fixed it for you.
As for the issue at hand, use VPN and ensure your company has set geographic monitoring tight. If you're logged in via VPN you'll appear local, the stolen token will come from somewhere else which should normally produce an alarm and - if set up - protective measures.
That said, token theft is a swine to prevent. I once heard rumours that Microsoft is working on something that ties the token to the specific browser, but that was at least half a year ago if not longer so I'm guessing they didn't get it to work properly. Quelle surprise..