Executive Summary
In July 2026, cybersecurity firm ReliaQuest identified a campaign where attackers compromised Wi-Fi devices in hotels and conference centers to hijack DNS settings. This manipulation redirected users attempting to access legitimate Microsoft 365 login pages to attacker-controlled phishing sites, leading to credential theft. The campaign, active since at least June 2026, affected various sectors, including financial services, healthcare, and retail, across multiple countries such as the U.S., India, and Saudi Arabia. The attackers exploited weakly protected management interfaces or unpatched vulnerabilities in Wi-Fi gateways to gain administrative access and alter DNS configurations. This method allowed them to intercept sensitive business information and communications without direct access to the victims' devices. (bleepingcomputer.com)
This incident underscores the evolving tactics of threat actors, who are increasingly targeting network infrastructure to bypass traditional endpoint security measures. The use of DNS hijacking to facilitate adversary-in-the-middle attacks highlights the need for organizations to secure all network devices, including those in transient environments like hotels and conference centers. Implementing robust security practices, such as using always-on, full-tunnel VPNs and encrypted DNS, is crucial to mitigate such threats. (bleepingcomputer.com)
Why This Matters Now
The recent DNS hijacking campaign targeting hotel Wi-Fi networks demonstrates a significant shift in cyberattack strategies, emphasizing the vulnerability of public and semi-public network infrastructures. As remote work and business travel continue to rise, employees frequently rely on such networks, increasing the risk of credential theft and unauthorized access to corporate resources. Organizations must prioritize securing network access points and educating employees on safe connectivity practices to prevent similar incidents.
Attack Path Analysis
Attackers exploited weakly protected management interfaces on hotel Wi-Fi devices to gain administrative access. They modified DNS settings to redirect users to malicious Microsoft 365 login pages, capturing credentials. The attackers then used these credentials to access sensitive corporate data. They established command and control channels to maintain access and exfiltrated data. The impact included unauthorized access to confidential information and potential data breaches.
Kill Chain Progression
Initial Compromise
Description
Attackers exploited weakly protected management interfaces on hotel Wi-Fi devices to gain administrative access.
Related CVEs
CVE-2023-50224
CVSS 9.8An unauthenticated HTTP GET request vulnerability in TP-Link WR841N routers allows remote attackers to retrieve router credentials.
Affected Products:
TP-Link WR841N – < 2023-12-01
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
DNS Hijacking
Application Layer Protocol: DNS
Compromise Infrastructure: Domains
Acquire Infrastructure: DNS Server
Dynamic Resolution: Fast Flux DNS
Gather Victim Network Information: DNS
Search Open Technical Databases: DNS/Passive DNS
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Change Control Processes
Control ID: 6.4.1
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Network and Environment Segmentation
Control ID: 3.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Hospitality
Hotels face direct credential harvesting exposure through compromised Wi-Fi DNS attacks targeting Microsoft 365 accounts of corporate guests attending conferences.
Financial Services
Banking sector vulnerable to OAuth token hijacking via hotel Wi-Fi DNS manipulation, bypassing MFA protections for Microsoft 365 business communications.
Legal Services
Law firms risk sensitive client data exposure when traveling attorneys connect to compromised hotel networks redirecting to fake Microsoft login portals.
Health Care / Life Sciences
Healthcare organizations face HIPAA compliance violations from credential theft targeting Microsoft 365 accounts containing protected patient information during travel.
Sources
- Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accountshttps://www.bleepingcomputer.com/news/security/hackers-hijack-hotel-wi-fi-dns-to-steal-microsoft-365-accounts/Verified
- APT28 exploit routers to enable DNS hijacking operationshttps://www.wired-gov.net/wg/news.nsf/articles/APT28%2Bexploit%2Brouters%2Bto%2Benable%2BDNS%2Bhijacking%2Boperations%2B08042026101500Verified
- Justice Department Conducts Court-Authorized Disruption of DNS Hijacking Network Controlled by a Russian Military Intelligence Unithttps://www.justice.gov/opa/pr/justice-department-conducts-court-authorized-disruption-dns-hijacking-network-controlledVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely limit the attacker's ability to exploit weak management interfaces, manipulate DNS settings, and access sensitive data by enforcing strict segmentation and identity-based policies.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Implementing Aviatrix CNSF would likely restrict unauthorized access to management interfaces, thereby reducing the risk of initial compromise.
Control: Zero Trust Segmentation
Mitigation: Aviatrix Zero Trust Segmentation would likely constrain unauthorized modifications to DNS settings, reducing the potential for privilege escalation.
Control: East-West Traffic Security
Mitigation: Aviatrix East-West Traffic Security would likely limit lateral movement within the network, reducing the attacker's ability to access sensitive data.
Control: Multicloud Visibility & Control
Mitigation: Aviatrix Multicloud Visibility & Control would likely detect and limit unauthorized command and control communications, reducing the attacker's ability to maintain access.
Control: Egress Security & Policy Enforcement
Mitigation: Aviatrix Egress Security & Policy Enforcement would likely restrict unauthorized data exfiltration, reducing the risk of data breaches.
Implementing Aviatrix Zero Trust CNSF would likely reduce the scope of unauthorized access, thereby limiting the potential impact of data breaches.
Impact at a Glance
Affected Business Functions
- Corporate Email Communications
- Document Management Systems
- Customer Relationship Management (CRM)
- Enterprise Resource Planning (ERP)
Estimated downtime: 7 days
Estimated loss: $500,000
Potential exposure of sensitive business information, including confidential communications, financial records, and client data.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Zero Trust Segmentation to restrict access and limit lateral movement.
- • Enforce Egress Security & Policy Enforcement to monitor and control outbound traffic.
- • Utilize Multicloud Visibility & Control to detect and respond to anomalous activities.
- • Deploy Inline IPS (Suricata) to identify and block known exploit patterns.
- • Apply Cloud Native Security Fabric (CNSF) for real-time inspection and enforcement.



