Find notable cyber news and cases, enriched with sources, timelines, and signals.

DNS poisoning campaign targeting captive Wi‑Fi routers to harvest corporate credentials

Campaign
First reported
Last updated
Happening score
H score 34
1 unique sources, 1 articles

Summary

Hide ▲

An ongoing DNS poisoning campaign is redirecting traffic from hotel and conference venue Wi‑Fi routers to harvest corporate login credentials, putting traveling employees and their accounts at risk. The operation uses exposed management interfaces and weak or reused admin credentials to take control of public Wi‑Fi gateways. Compromised gateways have been seen across multiple US cities, India and Saudi Arabia, showing a geographically broad operation. The attack can capture sensitive information without phishing links or malicious attachments by funneling legitimate domains through attacker-controlled infrastructure.

Related Happenings

Hotel Wi-Fi DNS hijacking Microsoft 365 phishing campaign

Campaign
H score34 First: 24.07.2026 20:50 Last: 24.07.2026 20:50 Sources 1

About this happening: Compromised Wi-Fi gateways at hotels and conference centers are redirecting travelers to fake Microsoft 365 login pages, creating a live credential-theft campaign that can...

ReliaQuest DNS poisoning mitigation guidance

Advisory/Mitigation
H score26 First: 24.07.2026 15:00 Last: 24.07.2026 15:00 Sources 1

How related: ReliaQuest has issued advice on how to prevent DNS poisoning from reaching endpoints, eliminating the attack surface and detecting credential-harvesting activity if it occurs.

About this happening: ReliaQuest issued mitigation advice for DNS poisoning that can redirect legitimate traffic and expose endpoints to credential-harvesting. The guidance targets operator...

Timeline

  1. 24.07.2026 15:00 2 articles · 7h ago

    ReliaQuest warns of DNS poisoning campaign targeting hotel Wi-Fi routers

    Initial Disclosure

    ReliaQuest warned that a DNS poisoning campaign is targeting hotel and conference venue Wi-Fi routers used for captive Wi-Fi services to steal corporate login credentials from visitors. The attackers are believed to gain access through exposed SSH, SNMP and web administration consoles or weak and reused admin credentials, then alter router configurations to redirect legitimate web traffic through attacker-controlled infrastructure.

    Show sources