logo

Warning: Compromised Hotel Routers Send Users to Phishing Sites

ID: 01a27586-50fe-5f5b-9807-f6d362fc3838

STIX ID: report--01a27586-50fe-5f5b-9807-f6d362fc3838

Feed Name: KnowBe4 Blog

Threat Score
75/100

Date Published: 2026-08-14

Date Updated: 2026-08-15

Author: KnowBe4 Team

...
...

ReliaQuest observed a campaign where compromised hotel Wi‑Fi routers are used for DNS poisoning to redirect travelers to Microsoft 365 phishing/authorization pages that capture OAuth tokens (via the device-code flow), allowing attackers to gain MFA-satisfied access to accounts; activity has been seen across the U.S., India, and Saudi Arabia and affects multiple industries.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.