Widespread DNS Poisoning Campaign Targets Hospitality Sector
ID: b15e2e27-0579-578b-878c-233cf77c1974
STIX ID: report--b15e2e27-0579-578b-878c-233cf77c1974
Feed Name: ThreatCluster
Researchers identified an active DNS poisoning campaign targeting public Wi-Fi gateways in hotels and conference centers to harvest corporate credentials from traveling employees by compromising routers via weak admin credentials and exposed management interfaces; the campaign has been active since at least June 2026 across multiple US cities, India, and Saudi Arabia, impacting financial services, healthcare, and retail, and defenders are advised to enforce always-on, full-tunnel VPNs for corporate devices.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
