Malicious Captive Portal
In plain terms
The 'log in to access Wi-Fi' page that asks for far more than Wi-Fi access: your email address with its password, a bank card, or the installation of a file.
Definition
A captive portal is the access page that opens automatically when joining certain public networks. Its malicious version reuses that appearance to obtain credentials, a payment, or the installation of a component. It's the point where a fake access point most often produces its effect, and the mechanism is that of phishing — in a context where you specifically expect to see a login page.
How it works
The context does all the work. You've just chosen a network, a page opens on its own, it carries the venue's name: the sequence is the one you expect, and that expectation disarms scrutiny. The pretext for the request is then calibrated to that expectation — 'log in with your email address,' 'verify your identity,' 'a one-euro deposit will be charged then refunded,' 'install this profile to secure your connection.' Each of these requests aims at something other than access: an email-and-password pair reusable elsewhere, a card number, or a certificate that will allow connections that were previously protected to be observed. The rule that settles it is simple and fits in one sentence: Wi-Fi access needs neither your email password, nor your bank card, nor the installation of anything on your device.
Warning signs
- Page asking for an email address along with its password
- Request for a bank card for access advertised as free, or for a 'deposit' to be refunded
- Invitation to install a profile, certificate, or app to access the network
- 'Log in with' button for a social media or email account
- Poorly translated page, address unrelated to the venue, or absence of a secure connection
- Portal that reappears in a loop and asks again for information already entered
How to verify
Weigh the request against what it's supposed to serve: granting access to a network needs neither an email password, nor a means of payment, nor any installation. Check the page's address and whether the connection is secure. If in doubt, ask staff how access works there — that's the decisive check, and it's instant.
What to do
Never enter a credential you use elsewhere into a captive portal. Don't pay anything there and don't install anything. If access requires any of these three things, give up on the network and use your phone's mobile hotspot instead.
If it already happened
From another network, immediately change the password entered and that of every account reusing it, starting with your email, then close open sessions. If you shared a bank card, contact your bank and block the card — a 'one-euro deposit' is used to validate the number for later charges. If you installed a profile or certificate, remove it in the device's settings. Report the incident to the relevant authority.
Frequently asked questions
- Some real networks do ask for an email address. How do I tell the difference?
- An address alone, yes, that does happen. The password that goes with it, never: a venue has no use for your email credentials, and no Wi-Fi access technically needs them. It's the presence of the password, not of the address, that settles it.
- What about the one-euro deposit that's supposed to be refunded?
- That's a classic pretext for obtaining a valid card number. The small amount makes the request seem acceptable; what's actually sought is the number, usable afterward for entirely different amounts. Free Wi-Fi access doesn't ask for a bank card.
Related attacks
Official sources
Also known as: captive portal, fraudulent Wi-Fi login page, captive portal attack, fake Wi-Fi access page.
This article is part of the Network and Wi-Fi attacks family. Last updated: 2026-09-03.