DNS Poisoning Tactics Expand to Hospitality Wi-Fi

Jul 28, 2026

Headline image Photo by Misha Feshchak on Unsplash

Adversaries have been compromising public Wi-Fi gateways at hotels, conference centers, and other shared venues to hijack the accounts of traveling corporate employees. Once they control the Wi-Fi gateway, they quietly redirect users to attacker-controlled infrastructure to steal credentials, in activity ongoing since at least June 2026.ReliaQuest assesses this tradecraft is similar to that of “APT28” (also known as “Fancy Bear” and “Forest Blizzard”), a Russian military intelligence group that was previously linked to similar router-based campaigns compromising Microsoft 365 accounts.Organizations can close the primary exposure with one control: enforce always-on, full-tunnel VPN on corporate devices. This routes all traffic—including DNS—through the corporate network before it ever reaches the hotel gateway, effectively stopping the attack.

Source: reliaquest.com