Nor'easter Hits Boston: 4 Airline Waivers Compared
On August 10, pilots flying Delta Flight 591 from Las Vegas to Atlanta radioed ground crews about a WiFi network nobody on the plane had turned on. The Boeing 757 was carrying 199 passengers and six crew members, many of them headed home from DEF CON 34, the hacking conference that had wrapped in Las Vegas days earlier. Somewhere over the flight, a second network showed up in the cabin’s WiFi list: “Delta WiFi Fast.” Same look, same vibe as the real thing. It wasn’t the real thing.
We’ve written before about the FBI’s warning on 19,000 fake FIFA ticket sites and about what Google actually got when it bought Spirit Airlines’ internal data. This one’s different. It’s not a scam site you have to go looking for. It’s a scam network broadcast directly into a sealed metal tube at 35,000 feet, and there was no way to just close the tab and walk away.
Quick Verdict
What happened An unauthorized “Delta WiFi Fast” network appeared aboard Delta Flight 591 (LAS–ATL), mimicking the plane’s real in-flight WiFi Suspected method Evil twin attack, likely paired with a deauthentication tool to force devices off the legitimate network Who’s suspected Passengers reportedly returning from DEF CON 34 — unconfirmed, no arrests as of publication Aircraft response Crew disabled the plane’s WiFi for roughly 30 minutes after detecting the rogue network Flight safety Delta says aircraft operating systems and flight safety were never affected Data risk Some reporting says a phishing page harvested Google logins — Delta hasn’t confirmed passenger data was actually stolen Why it matters It’s a live demonstration of how an evil twin attack works in the one place you can’t just unplug and leave
Here’s the sequence multiple outlets have corroborated. Delta 591 pushed back from Las Vegas on August 10 and somewhere during the flight, crew noticed a second, unauthorized WiFi network broadcasting alongside the aircraft’s real one, according to CyberScoop’s reporting on the incident and confirmed by Fox 5 Atlanta. The network’s name, “Delta WiFi Fast,” was close enough to the real thing that a distracted passenger scrolling their phone list wouldn’t think twice.
Pilots flagged it to air traffic control and Delta’s ground team. Cabin crew shut the aircraft’s WiFi down entirely for close to 30 minutes while they sorted out what was going on — no small inconvenience on a cross-country flight, but the right call. No emergency was declared. The plane landed in Atlanta on schedule, more or less. Delta’s spokesperson, Morgan Durrant, told reporters the airline was “fully investigating to gather a complete set of facts, which will take time,” and has been consistent on one point across every statement: “Safety of flight was never in question, and no aircraft operating systems were affected.” That part isn’t in dispute. The in-flight entertainment and connectivity system is walled off from anything that actually flies the plane, and nothing here suggests otherwise.
What’s genuinely notable is the timing and the crowd. DEF CON 34 had ended in Las Vegas days before this flight, and pilots reportedly told ground crews that some of the passengers were conference attendees, per ViewFromTheWing’s writeup. DEF CON draws tens of thousands of security researchers, penetration testers, and — inevitably — a smaller number of people who think “because I can” is a good enough reason. A commercial flight full of people just off a hacking conference, discovering a rogue access point mid-air, is close to the platonic ideal of a story that writes itself.
An evil twin attack is a fake WiFi network built to look identical to a real one — same or nearly identical name, sometimes a stronger signal — designed to pull your device away from the legitimate connection. Attackers frequently pair it with deauthentication, a technique that forcibly disconnects devices from the real network so they’re pushed to reconnect through the fake one instead, often landing on a phishing page that asks for login credentials.
That deauth step is the part that matters here. Reporting from Tom’s Hardware and CyberNews both point to a Wi-Fi Pineapple, a pocket-sized penetration-testing device that’s cheap, legal to own, and built for exactly this kind of network impersonation — sold openly to security professionals for authorized testing, and just as capable in the wrong hands on a commercial flight where nobody’s authorizing anything. If someone onboard used one to knock passengers off the legitimate in-flight network and onto “Delta WiFi Fast,” that’s not a hypothetical vulnerability. That’s the textbook attack, live, on a plane with nowhere to disconnect to.
Here’s where the story gets messier than the headlines suggest, and it’s worth sitting with the mess instead of smoothing it over.
Several outlets, including CyberNews and ViewFromTheWing, reported that the fake network’s phishing page harvested Google login credentials and other personal details, based on details relayed through pilot radio messages. That’s a specific, alarming claim. It’s also one Delta hasn’t confirmed. TechCrunch’s original reporting and CBS Atlanta both note that Delta’s preliminary findings, as of publication, don’t establish who created the network or whether any passenger data was actually compromised. Those two things — “a phishing page reportedly asked for Google logins” and “we’ve confirmed data was stolen” — aren’t the same claim, and a lot of coverage has blurred them together.
The FBI angle got similarly overstated in early write-ups, several of which claimed agents met the plane at the gate in Atlanta, questioned suspects, and confiscated devices. When reporters actually got FBI Atlanta on the record, the picture was smaller. Spokesperson Tony Thomas confirmed the bureau is “aware of reports regarding a potential Wi-Fi-related incident involving Delta Flight 591” and is “in contact with our local and corporate partners on this matter” — but said no arrests were made and agents did not meet the flight at the gate, a detail reported by outlets tracking the FBI’s actual statement rather than the earlier viral version.
None of this means the incident wasn’t real. Delta disabling WiFi for 30 minutes mid-flight isn’t a response to nothing. It means the specific, scariest details — credentials confirmed stolen, suspects confirmed caught — are still unverified as of this writing. Treat the underlying threat as real and the dramatic ending as unconfirmed. Both things are true at once.
Recognizing a fake network is step one. The more durable fix is not depending on public or shared WiFi for anything that matters in the first place.
Use your phone’s cellular data or a personal hotspot for sensitive logins. If you need to check email or log into a financial account mid-flight or in an airport, your carrier’s data connection is safer than any shared network, fake or real. We’ve tested Airalo, Holafly, and Saily eSIMs across a dozen countries specifically because carrying your own data connection sidesteps this entire category of attack — you’re not relying on a network you can’t verify.
Turn on multi-factor authentication everywhere it’s offered, especially on your Google account, which is exactly what this attack reportedly targeted. A stolen password is far less useful to an attacker if it’s not enough to get in on its own.
Use a VPN on any network you don’t control, in-flight or otherwise. It won’t stop an evil twin from existing, but it encrypts your traffic before it leaves your device, so a captive portal or man-in-the-middle setup sitting between you and the internet has a lot less to work with. CISA’s guidance on securing wireless networks makes the same recommendation for any public hotspot, not just this one.
Don’t enter passwords into any WiFi login screen that isn’t a simple terms-acceptance click. Real in-flight and airport WiFi portals almost never ask for an external account login. If one does, that’s the tell, not the fine print.
If you connected to “Delta WiFi Fast” on this specific flight, or you’ve ever entered a password into a WiFi portal that felt off in hindsight, treat it like any other credential exposure. Change the password on whatever account you logged into, starting with Google if that’s what you entered. Check your account’s recent activity and connected-device list for anything unfamiliar. Turn on multi-factor authentication if you haven’t already — CISA’s technique writeup on evil twin attacks notes that once an attacker has a foothold via a captured credential, they can often monitor further activity or pivot to other accounts using the same password. If you reuse passwords across accounts (most people do, we’re not going to pretend otherwise), change those too.
This isn’t the first time we’ve flagged a scam that piggybacks on a moment when travelers are distracted and moving fast. The FBI’s warning about 19,000 fake FIFA ticket domains worked the same way — attackers didn’t need to fool everyone, just the fraction of people rushing to book before a deadline. An evil twin attack on a plane is the same math with worse odds stacked against you: you’re bored, your phone’s at 40%, and the network just showed up in your list looking exactly like it should. That’s the entire design.
It also lands right after Delta expanded Concierge AI to handle self-service cancellations across the Fly Delta app — a reminder that the same airline pushing more of your account access into a chat interface is also the airline whose in-flight network got spoofed weeks later. Neither story means Delta’s systems were breached; both are about how much trust travelers put in whatever network or interface is in front of them without a second thought.
An evil twin WiFi attack showed up on a commercial flight, most likely built with a device you can buy for under $200 and legally own, deployed by someone who — allegedly — had just spent four days at a hacking conference. Delta’s own systems were never at risk. Whether anyone’s actual Google account got compromised is still unconfirmed, and so is exactly who did it. What’s confirmed is simpler and more useful: the attack worked well enough that crew had to kill the plane’s WiFi for half an hour to shut it down.
You don’t need to wait for the FBI to close this case to change how you connect. Confirm network names before you join them. Skip any WiFi login page that wants an email-provider password. Carry your own data connection when you can, and put a VPN between yourself and any network you’re not sure about. None of that is complicated. It’s just not automatic yet, and this is exactly the kind of story that should make it automatic.
Details current as of August 19, 2026, based on reporting from TechCrunch, CyberScoop, Fox 5 Atlanta, CBS Atlanta, ViewFromTheWing, CyberNews, and Tom’s Hardware. The FBI investigation is ongoing and some details — including the extent of any data compromise — remain unconfirmed. Verify current guidance before relying on any single account of this incident.