logo

Widespread DNS Poisoning Campaign Targets Hospitality Sector

ID: b15e2e27-0579-578b-878c-233cf77c1974

STIX ID: report--b15e2e27-0579-578b-878c-233cf77c1974

Feed Name: ThreatCluster

Threat Score
70/100

Date Published: 2026-07-24

Date Updated: 2026-07-24

...
...

Researchers identified an active DNS poisoning campaign targeting public Wi-Fi gateways in hotels and conference centers to harvest corporate credentials from traveling employees by compromising routers via weak admin credentials and exposed management interfaces; the campaign has been active since at least June 2026 across multiple US cities, India, and Saudi Arabia, impacting financial services, healthcare, and retail, and defenders are advised to enforce always-on, full-tunnel VPNs for corporate devices.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.