logo

Hotel Wi-Fi Routers Compromised to Steal Corporate Login Credentials From Visitors

ID: a1672051-231d-50e5-abab-b4a4b9f759fd

STIX ID: report--a1672051-231d-50e5-abab-b4a4b9f759fd

Feed Name: Infosecurity Magazine (News)

Threat Score
75/100

Date Published: 2026-07-24

Date Updated: 2026-07-24

...
...

ReliaQuest warns of a global DNS poisoning campaign targeting public Wi‑Fi routers at hotels, conference centers and other venues frequented by corporate travelers; attackers exploit exposed management interfaces and weak/reused admin credentials to modify router DNS and transparently harvest usernames, passwords and other sensitive data. The activity, observed across multiple US cities, India and Saudi Arabia, is ongoing and described as similar to TTPs attributed to APT28; mitigations recommended include enforcing always‑on full‑tunnel VPNs, auditing proxy authentication logs, disabling WPAD, validating sites before entering credentials, and blocking device‑code authentication flows.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.