Evil Twin Attack: Fake Wi-Fi Threat on Delta Flight

Technology Travel

Aug 15, 2026 · 6 min read

Evil Twin Attack: Fake Wi-Fi Threat on Delta Flight

**Evil Twin attacks trick users onto fake Wi-Fi networks, posing a significant risk to cybersecurity, especially on airplanes. This type of attack lures victims by mimicking legitimate networks, such as those found on flights, and can lead to severe breaches if users aren't cautious.

Source

Watch the Reel

Fake Wi-Fi Networks on Airplanes: The Evil Twin Attack

A fake Wi-Fi network appeared on a Delta flight from Las Vegas to Atlanta shortly after DEF CON attendees boarded the plane. This incident highlights the risks of Evil Twin attacks on airplanes and the potential for serious cybersecurity breaches. Here, we'll delve into the specifics of this attack and provide practical tips for staying safe on public Wi-Fi networks.

Context / Why this matters

Wifi-connected smartphones are vital in our digital age. However, public Wi-Fi networks, especially those in transit, can be a breeding ground for cyber threats. The Evil Twin attack is a classic example of this. The goal is to deceive users into connecting to a fake hotspot that mimics a legitimate network, such as 'Delta Wi-Fi' or 'Delta Wi-Fi Fast'. It’s crucial to understand how these attacks work and how to protect yourself.

What is an Evil Twin Attack?

An Evil Twin attack involves creating a fake Wi-Fi network that mimics a legitimate one. In the case of the Delta flight, hackers disrupted the legitimate Wi-Fi network, making it unusable. They then broadcasted a fake network with similar names, such as 'Delta Wi-Fi' or 'Delta Wi-Fi Fast', to trick passengers into connecting.

How the Attack Unfolds

The attack typically involves several steps:

  1. Disruption of the Legitimate Network: Hackers use an authentication attack to disconnect devices from the real Wi-Fi network, making it unstable and unusable. They accomplish this by repeatedly "kicking" devices off the network.

  2. Broadcasting the Fake Network: Once the legitimate network is disrupted, the attackers broadcast a fake network with a similar name. This fake hotspot, known as an 'Evil Twin,’ is designed to look almost identical to the real one.

  3. Phishing for Credentials: When passengers try to connect to the internet, they are presented with a captive portal that looks like a legitimate login page. This phishing page is designed to collect sensitive information, such as Google account credentials, which are then sent to the attacker.

The Delta Flight Incident

During a recent incident on a Delta flight from Las Vegas to Atlanta, a fake Wi-Fi network impersonated the airline's onboard service. While the legitimate Wi-Fi was unavailable for roughly 30 minutes, the fake network appeared, tricking passengers into connecting. The cabin crew noticed something was amiss, and the pilots reported the incident to ground control. Delta later confirmed the presence of an unauthorized Wi-Fi network and is currently investigating the matter.

Key Points to Keep in Mind

There are several key points to consider when trying to protect yourself from Evil Twin attacks:

Disruption and Unavailability

The disruption of the legitimate Wi-Fi network is a key component of the attack. Passengers are frustrated when the official onboard Wi-Fi either doesn't work or keeps dropping. When this happens, they are more likely to look for alternative networks, making them vulnerable to the Evil Twin attack.

The Fake Network

When a fake network is broadcasted, it often closely mimics the legitimate network. Passengers may see options like 'Delta Wi-Fi' and 'Delta Wi-Fi Fast' and click on whichever seems to work. This is exactly what the attacker wants, as it allows them to capture sensitive information.

The Role of the Captive Portal

Once connected to the fake network, passengers are presented with a captive portal designed to look like a legitimate login page. This portal is actually a phishing page, designed to collect sensitive information such as Google account credentials. The information is then sent to the attacker running the evil access point.

How the Attack was Detected

In the Delta flight incident, the cabin crew noticed something wasn’t right and the pilots reported an alert back to the ground during the flight. Delta later confirmed that a fake Wi-Fi network was present on board. The last time this happened, the passenger received a seven-year prison sentence. This highlights the serious consequences of attempting such an attack.

Lessons from Australia

This particular incident happened in Australia, where the consequences of such an attack are severe. Being on an airplane means that everyone on board is identified, and the airport has cameras. This makes it easier to trace the attacker. Additionally, the flight originated from a cybersecurity hacking conference, which adds an extra layer of scrutiny.

Practical Tips

Trust but Verify

Do not trust a Wi-Fi network just because you believe it should be there. Always verify the legitimacy of the network before connecting. Look for official announcements or ask the crew for confirmation.

Use a VPN

A Virtual Private Network (VPN) can provide an extra layer of security by encrypting your data and masking your IP address. This makes it much harder for attackers to intercept your information.

Be Cautious with Public Wi-Fi

Public Wi-Fi networks, especially in transit, are often targets for cyber attacks. Be cautious when using these networks, and avoid accessing sensitive information while connected.

Use Strong, Unique Passwords

Ensure that your accounts are protected with strong, unique passwords. This makes it harder for attackers to gain access to your information even if they manage to intercept your login credentials.

Enable Two-Factor Authentication

Two-factor authentication adds an extra layer of security to your accounts. Even if an attacker manages to get your login credentials, they will still need access to your second factor, such as a physical security key or a code sent to your mobile device.

Be Aware of Your Surroundings

When traveling, be aware of your surroundings and who is around you. If you notice any suspicious activity, report it to the authorities or airline staff immediately.

Important Takeaways

The Importance of Awareness

Awareness is key to protecting yourself from Evil Twin attacks. Stay informed about the latest threats and take the necessary precautions to protect your personal information.

The Role of the Airline

Airlines play a crucial role in ensuring the safety of their passengers. They should implement robust security measures to prevent unauthorized Wi-Fi networks from being broadcasted on their flights.

The Consequences of Such Attacks

Attempting an Evil Twin attack can have serious consequences, as seen in the Australian incident. It’s important to understand the legal and personal ramifications of such actions.

The Role of Technology

Technology can both be a tool for attackers and a means of protection. Ensure that you are using the latest security measures, such as VPNs and two-factor authentication, to protect your personal information.

Conclusion

The incident on the Delta flight highlights the risks associated with public Wi-Fi networks and the potential for Evil Twin attacks. By understanding how these attacks work and taking the necessary precautions, you can protect yourself and your personal information. Always be cautious when connecting to public Wi-Fi networks, and remember that trust but verify is the key to staying safe.

Summary

Key points

  • The fake Wi-Fi network on the Delta flight from Las Vegas to Atlanta is an example of an Evil Twin attack.
  • Evil Twin attacks involve creating a fake Wi-Fi network that mimics a legitimate one, such as 'Delta Wi-Fi' or 'Delta Wi-Fi Fast'.
  • The hackers disrupted the legitimate Wi-Fi network on the Delta flight by repeatedly kicking devices off the network.
  • The hackers then broadcasted a fake network with a similar name to trick passengers into connecting.
  • The fake network presented a phishing page to collect sensitive information, such as Google account credentials.
Mentioned

Products

smartphone
Discussion

Comments

Be the first to comment.

Similar reads based on topic and creator.

Recent articles

Fresh deep dives from the latest Reels we unpacked.

View all