Cookie Consent by Free Privacy Policy Generator

Hotel Wi-Fi Networks Compromised in DNS Poisoning Campaign Targeting Corporate Credentials

Researchers at ReliaQuest have identified a widespread DNS poisoning campaign targeting hotel Wi-Fi networks to steal corporate login credentials from business travellers. Attackers have compromised hotel routers to redirect guests attempting to access legitimate corporate services to malicious pages designed to harvest usernames, passwords and multi-factor authentication tokens. The campaign appears to be part of a sustained cyber espionage operation targeting the hospitality sector, with attackers exploiting weak or default router credentials and unpatched vulnerabilities to gain persistent access to hotel network infrastructure. The attacks are designed to intercept credentials from guests connecting to what they believe is legitimate hotel Wi-Fi.

Why this matters for UK organisations

This represents a significant operational risk for UK businesses with mobile workforces. Hotel Wi-Fi networks are commonly used by employees travelling domestically or internationally for work, attending conferences or meeting clients, and many organisations rely on VPNs and endpoint security to protect corporate access in these environments. However, DNS poisoning at the router level can intercept traffic before VPN connections are established, and credential harvesting pages can be convincing enough to bypass user awareness training. The systematic targeting of hospitality infrastructure suggests attackers understand where corporate users are most likely to connect from less secure networks and are exploiting those environments to intercept access credentials. For organisations where employees regularly travel, this creates a direct pathway for attackers to compromise corporate accounts, access sensitive systems and move laterally within networks. The risk is particularly acute for organisations in sectors such as legal, finance, consulting and professional services, where travel is frequent and access to sensitive client data is common.

What to review

Organisations should review travel security guidance to ensure it clearly instructs employees to establish VPN connections before accessing any corporate systems or services when using hotel or public Wi-Fi. Endpoint security policies should be reviewed to ensure they enforce VPN use and prevent corporate access from untrusted networks. Multi-factor authentication should be reviewed to ensure it is resistant to real-time phishing and credential harvesting, with consideration given to phishing-resistant methods such as hardware tokens or certificate-based authentication. User awareness training should include specific guidance on the risks of entering credentials on unfamiliar login pages, even when connected to what appears to be legitimate hotel Wi-Fi. Organisations should also consider whether they have visibility into where corporate credentials are being used, and whether anomaly detection is tuned to flag authentication attempts from unexpected locations or networks. Finally, IT teams should clarify who is responsible for reviewing and updating travel security guidance, and ensure that mobile workers understand the risks and know how to escalate concerns if they suspect their credentials may have been compromised.

Source: Infosecurity Magazine

News and blog posts
Today's stories reflect a shift in how organisations need to think about both...
An autonomous AI agent developed by OpenAI has successfully compromised Hugging...
Researchers at ReliaQuest have identified a widespread DNS poisoning campaign...
Despite multiple coordinated law enforcement takedowns, residential proxy...