An unauthorised cabin wi-fi network named ‘Delta WiFi Fast’ appeared during Delta Air Lines flight 591 from Las Vegas to Atlanta on 10th August, on which many passengers were returning from the Def Con 34 cybersecurity and hacker conference. The crew were concerned about a security risk known as an ‘evil twin attack’ and acted quickly, temporarily disabling the aircraft’s wi-fi system.
So what risks do fake wi-fi networks pose? And what is an evil twin attack?
An evil twin attack is when hackers create fake wi-fi networks with the goal of stealing sensitive information from people, or exploiting known vulnerabilities present on victims’ devices. The fake networks often have a very similar (or identical) name to the legitimate network, which was the case on Delta flight 591.
Once a person connects their device to the hacker’s wi-fi network, the hacker may be able to see what the victim is doing online and what data they transfer. However, since most websites have HTTPS/TLS encryption, much of what the user does, even on the rogue network, is private.
The risk here is that the hacker may attempt to redirect the victim to a phishing website – for instance, in this case, it may have been a fake Delta login page asking for personal data such as name, email, address, etc. Or the hacker may even go further and provide fake login pages for banks or social media, and try to extract login details from the victims.
Are the people who connected to the network at risk?
Connecting to such a network comes with some risk in itself. Connecting to a network controlled by a threat actor allows them to probe your device for potential vulnerabilities and maliciously redirect your internet traffic to their own servers.
If a person entered credentials into a wi-fi login page, noticed security warnings popping up after visiting a website, downloaded something, or entered payment information into an unfamiliar page, then they may have had their data stolen.
In that case, the victim should immediately change any passwords that were transmitted, do a thorough scan of their device for malware, and if bank details were transmitted, freeze their bank account until new credentials are received.
However, if a user just connected and disconnected to the wi-fi without entering any details or clicking suspicious links, they should be fine.
About Aras Nazarovas:
Aras Nazarovas is a senior information security researcher at Cybernews, specialising in cybersecurity and threat analysis. He investigates online services, malicious campaigns, and hardware security while compiling data on the most prevalent cybersecurity threats. Aras has uncovered significant privacy and security issues affecting organisations and consumer platforms, including NASA, PayPal, and popular apps available on the Google Play Store and Apple App Store.



