General

Public Wi-Fi Lets State-Backed Hackers Hijack Driver Logins

Russian intelligence group used DNS poisoning on hotel and truck-stop Wi-Fi to steal credentials and install malware. Fleets with BYOD policies and driver tablets are exposed.

Laptop computer connected to public Wi-Fi network at truck stop or hotel
Photo: Internet Archive Book Images · No restrictions (Wikimedia Commons)

How does public Wi-Fi let hackers steal driver credentials?

Russian intelligence operatives used DNS poisoning on public Wi-Fi networks in hotels, convention centers, and hospitals to redirect internet traffic through infrastructure they controlled, according to a July 2026 report from cybersecurity firm ReliaQuest. The campaign targeted travelers, including truck drivers connecting to public networks at truck stops and hotels. The attackers exploited vulnerabilities in captive portals (the login pages that pop up when you connect to public Wi-Fi) to intercept login credentials and install malware on connected devices.

The threat group, known as Storm-2945, is associated with Russia's Main Intelligence Directorate. DNS poisoning works by quietly changing the directions your device follows when it tries to reach a website. Instead of connecting to your fleet's dispatch system or load board, the device connects to a server the attackers control. The user sees what looks like a legitimate login page, enters their credentials, and the attackers capture everything.

What this means for fleets running driver tablets and BYOD policies

Fleets that issue tablets or allow drivers to use personal devices for dispatch, ELD compliance, or load-board access are exposed. If a driver connects to compromised Wi-Fi and logs into a fleet TMS, the attacker gains access to the corporate network. From there, the threat is the same as any ransomware or phishing attack that shuts down dispatch systems: locked load boards, encrypted customer data, spoiled refrigerated freight.

The attack doesn't require the driver to click a phishing link or download a suspicious file. Connecting to the Wi-Fi network is enough. The captive portal itself is the entry point.

How to protect driver devices on public networks

Fleets can block this attack vector with three steps. First, require VPN use on all driver devices before they connect to any public Wi-Fi. A VPN encrypts all traffic between the device and the fleet's network, so even if DNS is poisoned, the attacker can't read the data or redirect the connection. Second, disable auto-connect to open Wi-Fi networks on all fleet-issued tablets and laptops. Drivers should manually approve each connection. Third, restrict which networks drivers can use for fleet business. If your dispatch system or TMS doesn't need to be accessed from the road, disable remote login entirely.

For fleets that allow drivers to use personal phones or laptops (BYOD policies), the risk is higher because you don't control the device configuration. In that case, the VPN requirement is non-negotiable. Issue credentials for a fleet VPN and make it a condition of using personal devices for work. If a driver won't run the VPN, they don't get remote access.

What traditional cybersecurity training misses

The ReliaQuest report notes that traditional cybersecurity training doesn't stop social engineering attacks like this one. Training teaches drivers to spot phishing emails and suspicious links, but DNS poisoning happens at the network level. The driver sees a legitimate-looking login page because the attacker is serving a fake page that mimics the real one. There's no typo in the URL, no suspicious sender address, no red flag for the driver to catch.

This is why technical controls (VPNs, network restrictions, device management) matter more than user training for this threat. A driver can follow every rule in the cybersecurity handbook and still hand over credentials if the network itself is compromised.

Why truck stops and hotels are high-value targets

Truck stops, hotels, and convention centers are high-value targets because they serve transient users who need internet access and are less likely to question the legitimacy of the Wi-Fi network. A driver at a TA or Pilot doesn't have time to verify whether the network is secure. They connect, log in, and get back on the road. That's exactly what the attackers count on.

The Storm-2945 campaign specifically targeted travelers, not just trucking. But the operational pattern (connect to unfamiliar Wi-Fi, access work systems remotely, move on) makes drivers ideal victims. Fleets that run AI tools with no record of what data leaves the shop are doubly exposed, because compromised credentials can give attackers access to customer data, route information, and load details stored in cloud-based systems.

The cost of a compromised driver login

A single compromised driver login can cost a small fleet tens of thousands of dollars. If the attacker uses the credentials to install ransomware, the fleet faces downtime, ransom demands, and potential data-breach notification costs if customer information is exposed. If the attacker uses the login to access dispatch systems, they can redirect loads, cancel shipments, or lock the fleet out of its own TMS. Recovery time for a ransomware attack on a small fleet averages three to five days, during which trucks sit idle and loads go unfulfilled.

The fix (VPN service, device management software, network restrictions) costs $5 to $15 per driver per month. The alternative is a single compromised login that shuts down the fleet for a week.

More from Hank Rivers