Threats · 52 days ago
Compromising a captive Wi‑Fi gateway gives the attacker a place to sit between travelers and the sites they trust. The standard response of fixing the router misses the real loss: corporate usernames and passwords can be captured during normal logins and reused later against the visitor’s employer.
ReliaQuest says the ongoing DNS poisoning campaign targets hotel and conference Wi‑Fi gateways worldwide, with sightings across multiple US cities, India, and Saudi Arabia. The access path is exposed management interfaces and weak or reused admin credentials, which lets the attacker rewrite DNS and send visitors through attacker-controlled infrastructure when they reach legitimate domains.
The blast radius reaches any place that runs captive Wi‑Fi for visiting staff, including airports, co-working spaces, universities, healthcare facilities, and event venues. Even after the gateway is cleaned up, the stolen credentials remain useful for later intrusions because the attacker’s prize is a reusable login set, not the router itself.
2 sources covering this story
Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts
Hackers are changing the DNS settings on Wi-Fi devices at hotels and conference centers to redirect users to fake Microsoft 365 login pages.
Hotel Wi-Fi Routers Compromised to Steal Corporate Login Credentials
Researchers at ReliaQuest warned of widespread DNS poisoning attacks targeting the hospitality sector as part of a cyber espionage campaign
Part of the PlainSec briefing for 2026-07-25