Skip to main content
Emerging ThreatsMalware & Ransomware

Hackers Exploit Public Wi-Fi DNS to Harvest Credentials

Public Wi-Fi access point in a hotel lobby with a blurred laptop screen nearby.

"Criminals are hacking into public Wi-Fi devices—at hotels, conference centers, and so on—around the world and changing their DNS settings." That is the blunt summary presented in the post about a simple but consequential attack vector: change a network device's DNS and send every connected user to a counterfeit login page to harvest credentials.

How the DNS-change attack works

The post describes a straightforward chain: attackers gain access to public Wi‑Fi devices, alter the device's Domain Name System (DNS) settings, and thereby redirect users' web traffic. The redirection is used to present fake login pages that ask for credentials. The stated goal is credential theft.

Where it is occurring: hotels, conference centers, and other public Wi‑Fi

The writing specifies locations that host public Wi‑Fi services—hotels and conference centers among them—as the environments being targeted. It further characterizes the activity as occurring "around the world," indicating a geographically distributed problem rather than an isolated incident.

The risk in plain terms: credential capture through counterfeit pages

By replacing legitimate DNS responses with attacker-controlled ones, the compromised Wi‑Fi device can make users' browsers and devices resolve familiar names to attacker-controlled addresses. The post explains the attack's payoff bluntly: users are presented with fake login pages and the criminals steal the credentials those pages collect.

What this means for technologists and security teams, end users, and affected enterprises

  • Technologists and security teams: The immediate worry is device configuration integrity—specifically DNS settings on access points, guest portals, and any appliance that terminates public Wi‑Fi sessions. Teams responsible for those devices will be watching configuration and management interfaces for unauthorized changes and considering how to protect or monitor them.
  • End users and the general public: The concrete risk is being redirected to a forged login page and entering credentials that are then harvested. Users who connect to public Wi‑Fi at hotels or conferences are the primary targets called out in the post.
  • Affected enterprises and venue operators: Organizations that provide public Wi‑Fi—hotels, conference centers, and similar venues—face the operational risk that an infected or misconfigured network device can turn their service into an attack surface for credential theft. They will have to consider how to secure devices and detect DNS tampering.

Conclusion: a low‑complexity attack with outsized consequences

The post sketches a threat that is technically simple but socially effective: change the DNS settings on a public Wi‑Fi device, redirect users to a fake login page, and collect credentials. The method relies less on zero‑day flaws than on access to devices that handle guest connectivity, and its victims are the people who expect convenience from public networks. The specific questions that follow are practical rather than theoretical: which devices are exposed, how often their DNS is altered, and what detection or configuration controls venues use to prevent tampering.

Source: Schneier on Security — Hacking Public Wi‑Fi DNS to Steal Credentials