Infosecurity-Magazine
Widespread DNS Poisoning Campaign Targets Hospitality Sector
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A DNS poisoning campaign has been identified, targeting public Wi-Fi gateways in hotels and conference centers to harvest corporate login credentials from traveling employees. Researchers at ReliaQuest noted that the attackers compromise Wi-Fi routers by exploiting weak admin credentials and exposed management interfaces, allowing them to redirect legitimate web traffic through attacker-controlled servers. This method enables credential theft without phishing emails or malware. The campaign has been active since at least June 2026 and spans multiple US cities, India, and Saudi Arabia. Affected organizations include those in financial services, healthcare, and retail, indicating a broad impact across various sectors. To mitigate risks, organizations are advised to enforce always-on, full-tunnel VPNs for corporate devices.
Key Points: • Attackers compromise hotel Wi-Fi gateways to steal corporate credentials. • The campaign exploits weak admin credentials and exposed interfaces on routers. • Always-on, full-tunnel VPNs are recommended for protection against these attacks.