Widespread DNS Poisoning Campaign Targets Hospitality Sector

Widespread DNS Poisoning Campaign Targets Hospitality Sector

First seen 24 Jul 2026, 15:52 UTC GbhackersCybersecuritynewsInfosecurity-Magazinereliaquest.com 75% similarity 78.0

Article Content

Browse articles
ThreatCluster

A DNS poisoning campaign has been identified, targeting public Wi-Fi gateways in hotels and conference centers to harvest corporate login credentials from traveling employees. Researchers at ReliaQuest noted that the attackers compromise Wi-Fi routers by exploiting weak admin credentials and exposed management interfaces, allowing them to redirect legitimate web traffic through attacker-controlled servers. This method enables credential theft without phishing emails or malware. The campaign has been active since at least June 2026 and spans multiple US cities, India, and Saudi Arabia. Affected organizations include those in financial services, healthcare, and retail, indicating a broad impact across various sectors. To mitigate risks, organizations are advised to enforce always-on, full-tunnel VPNs for corporate devices.

Key Points: • Attackers compromise hotel Wi-Fi gateways to steal corporate credentials. • The campaign exploits weak admin credentials and exposed interfaces on routers. • Always-on, full-tunnel VPNs are recommended for protection against these attacks.

ThreatCluster AI

Timeline

2026-06-01
Campaign began targeting hospitality sector
Threat actors started compromising public Wi-Fi gateways in hotels and conference centers to hijack corporate accounts.
ReliaQuest
2026-07-23
ReliaQuest publishes findings
ReliaQuest researchers released a report detailing the ongoing DNS poisoning campaign affecting corporate travelers.
Infosecurity-Magazine
2026-07-24
Public awareness raised
Multiple cybersecurity outlets report on the DNS poisoning campaign, emphasizing the need for VPNs to secure corporate devices.
Gbhackers

Community

Browse all →