Executive Summary
In July 2026, cybersecurity researchers identified a campaign where threat actors compromised Wi-Fi gateways in hotels and conference centers to perform DNS hijacking attacks. By altering DNS settings, attackers redirected users attempting to access Microsoft 365 services to fraudulent login pages, thereby harvesting corporate credentials. This method allowed attackers to intercept sensitive information without directly compromising user devices. (computerworld.com)
This incident underscores the evolving tactics of cybercriminals targeting public Wi-Fi networks to exploit travelers and remote workers. The use of DNS hijacking in such environments highlights the need for enhanced security measures and user vigilance when connecting to public networks.
Why This Matters Now
The increasing reliance on public Wi-Fi by remote workers and travelers makes DNS hijacking attacks particularly concerning. Organizations must prioritize securing their employees' connections and educate them on the risks associated with public networks to prevent credential theft and potential data breaches.
Attack Path Analysis
Attackers compromised public Wi-Fi devices to alter DNS settings, redirecting users to malicious login pages to steal credentials. With stolen credentials, they accessed users' cloud services, escalating privileges to gain broader access. They moved laterally within the cloud environment, accessing sensitive data. Command and control were maintained through DNS-based channels, facilitating ongoing access. Exfiltration of sensitive data occurred via encrypted channels to attacker-controlled servers. The impact included unauthorized access to confidential information and potential financial loss.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers compromised public Wi-Fi devices to alter DNS settings, redirecting users to malicious login pages to steal credentials.
Related CVEs
CVE-2026-0625
CVSS 9.3An authentication bypass vulnerability in multiple D-Link DSL/DIR/DNS devices allows unauthenticated attackers to modify DNS settings via the dnscfg.cgi endpoint, enabling DNS hijacking attacks.
Affected Products:
D-Link DSL/DIR/DNS devices – Multiple versions
Exploit Status:
exploited in the wildReferences:
MITRE ATT&CK® Techniques
Adversary-in-the-Middle: LLMNR/NBT-NS Poisoning and SMB Relay
Application Layer Protocol: Web Protocols
Data Manipulation: Stored Data Manipulation
Valid Accounts
Drive-by Compromise
User Execution: Malicious Link
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure that all system components and software are protected from known vulnerabilities by installing applicable vendor-supplied security patches.
Control ID: 6.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Network and Environment Segmentation
Control ID: 3.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Hospitality
Hotels directly targeted in DNS hijacking attacks on public Wi-Fi infrastructure, exposing guest credentials through malicious login redirects and compromised network security.
Events Services
Conference centers and event venues face credential theft risks from compromised public Wi-Fi DNS settings, threatening attendee data and organizational security compliance.
Information Technology/IT
IT sectors must address DNS security gaps, encrypted traffic protection, and zero trust segmentation to prevent credential theft via public Wi-Fi infrastructure.
Financial Services
High-value credential targets face elevated risks from DNS hijacking attacks, requiring enhanced egress security and encrypted traffic monitoring for regulatory compliance.
Sources
- Hacking Public Wi-Fi DNS to Steal Credentialshttps://www.schneier.com/blog/archives/2026/08/hacking-public-wi-fi-dns-to-steal-credentials.htmlVerified
- Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accountshttps://www.bleepingcomputer.com/news/security/hackers-hijack-hotel-wi-fi-dns-to-steal-microsoft-365-accounts/Verified
- Hacked Hotel Wi-Fi Used to Steal Guests' Loginshttps://tech.yahoo.com/cybersecurity/articles/hacked-hotel-wi-fi-used-172704133.htmlVerified
- Hotel Wi-Fi Routers Compromised to Steal Corporate Login Credentialshttps://www.infosecurity-magazine.com/news/hotel-wifi-dns-poisoning/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF is pertinent to this incident as it would likely limit the attacker's ability to move laterally and exfiltrate data by enforcing strict segmentation and identity-based access controls.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: While Aviatrix CNSF primarily focuses on securing cloud environments, its principles of identity-based access and segmentation could indirectly reduce the risk of credential misuse by limiting unauthorized access within the cloud.
Control: Zero Trust Segmentation
Mitigation: Aviatrix Zero Trust Segmentation would likely constrain attackers' ability to escalate privileges by enforcing least-privilege access controls, thereby reducing the scope of accessible resources.
Control: East-West Traffic Security
Mitigation: Aviatrix East-West Traffic Security would likely limit lateral movement by enforcing strict segmentation between workloads, thereby reducing the attacker's ability to access sensitive data.
Control: Multicloud Visibility & Control
Mitigation: Aviatrix Multicloud Visibility & Control would likely detect and limit unauthorized command and control channels by providing comprehensive monitoring and control over DNS traffic across cloud environments.
Control: Egress Security & Policy Enforcement
Mitigation: Aviatrix Egress Security & Policy Enforcement would likely limit data exfiltration by enforcing strict egress policies and monitoring outbound traffic for anomalies.
Aviatrix CNSF would likely reduce the overall impact by containing breaches to individual workloads and preventing widespread access to confidential information.
Impact at a Glance
Affected Business Functions
- Guest Internet Services
- Corporate Network Access
- Email Communications
- Online Transactions
Estimated downtime: 3 days
Estimated loss: $50,000
Potential exposure of corporate login credentials, including Microsoft 365 accounts, leading to unauthorized access to sensitive business information.
Recommended Actions
Key Takeaways & Next Steps
- • Implement Encrypted Traffic (HPE) to secure data in transit and prevent packet sniffing.
- • Deploy Zero Trust Segmentation to enforce least privilege access and limit lateral movement.
- • Utilize Egress Security & Policy Enforcement to monitor and control outbound traffic, preventing unauthorized data exfiltration.
- • Establish Multicloud Visibility & Control to detect anomalous interactions and repeated malformed requests.
- • Apply Inline IPS (Suricata) to identify and block known exploit patterns and malicious payloads.



