Hero image for Delta's Fake WiFi Attack: Fly Safely From Now On
By Travel Tools Guide Team

Delta's Fake WiFi Attack: Fly Safely From Now On


On August 10, pilots flying Delta Flight 591 from Las Vegas to Atlanta radioed ground crews about a WiFi network nobody on the plane had turned on. The Boeing 757 was carrying 199 passengers and six crew members, many of them headed home from DEF CON 34, the hacking conference that had wrapped in Las Vegas days earlier. Somewhere over the flight, a second network showed up in the cabin’s WiFi list: “Delta WiFi Fast.” Same look, same vibe as the real thing. It wasn’t the real thing.

We’ve written before about the FBI’s warning on 19,000 fake FIFA ticket sites and about what Google actually got when it bought Spirit Airlines’ internal data. This one’s different. It’s not a scam site you have to go looking for. It’s a scam network broadcast directly into a sealed metal tube at 35,000 feet, and there was no way to just close the tab and walk away.

Quick Verdict

What happenedAn unauthorized “Delta WiFi Fast” network appeared aboard Delta Flight 591 (LAS–ATL), mimicking the plane’s real in-flight WiFi
Suspected methodEvil twin attack, likely paired with a deauthentication tool to force devices off the legitimate network
Who’s suspectedPassengers reportedly returning from DEF CON 34 — unconfirmed, no arrests as of publication
Aircraft responseCrew disabled the plane’s WiFi for roughly 30 minutes after detecting the rogue network
Flight safetyDelta says aircraft operating systems and flight safety were never affected
Data riskSome reporting says a phishing page harvested Google logins — Delta hasn’t confirmed passenger data was actually stolen
Why it mattersIt’s a live demonstration of how an evil twin attack works in the one place you can’t just unplug and leave

What Actually Happened on Flight 591

Here’s the sequence multiple outlets have corroborated. Delta 591 pushed back from Las Vegas on August 10 and somewhere during the flight, crew noticed a second, unauthorized WiFi network broadcasting alongside the aircraft’s real one, according to CyberScoop’s reporting on the incident and confirmed by Fox 5 Atlanta. The network’s name, “Delta WiFi Fast,” was close enough to the real thing that a distracted passenger scrolling their phone list wouldn’t think twice.

Pilots flagged it to air traffic control and Delta’s ground team. Cabin crew shut the aircraft’s WiFi down entirely for close to 30 minutes while they sorted out what was going on — no small inconvenience on a cross-country flight, but the right call. No emergency was declared. The plane landed in Atlanta on schedule, more or less. Delta’s spokesperson, Morgan Durrant, told reporters the airline was “fully investigating to gather a complete set of facts, which will take time,” and has been consistent on one point across every statement: “Safety of flight was never in question, and no aircraft operating systems were affected.” That part isn’t in dispute. The in-flight entertainment and connectivity system is walled off from anything that actually flies the plane, and nothing here suggests otherwise.

What’s genuinely notable is the timing and the crowd. DEF CON 34 had ended in Las Vegas days before this flight, and pilots reportedly told ground crews that some of the passengers were conference attendees, per ViewFromTheWing’s writeup. DEF CON draws tens of thousands of security researchers, penetration testers, and — inevitably — a smaller number of people who think “because I can” is a good enough reason. A commercial flight full of people just off a hacking conference, discovering a rogue access point mid-air, is close to the platonic ideal of a story that writes itself.

What Is an Evil Twin WiFi Attack?

An evil twin attack is a fake WiFi network built to look identical to a real one — same or nearly identical name, sometimes a stronger signal — designed to pull your device away from the legitimate connection. Attackers frequently pair it with deauthentication, a technique that forcibly disconnects devices from the real network so they’re pushed to reconnect through the fake one instead, often landing on a phishing page that asks for login credentials.

That deauth step is the part that matters here. Reporting from Tom’s Hardware and CyberNews both point to a Wi-Fi Pineapple, a pocket-sized penetration-testing device that’s cheap, legal to own, and built for exactly this kind of network impersonation — sold openly to security professionals for authorized testing, and just as capable in the wrong hands on a commercial flight where nobody’s authorizing anything. If someone onboard used one to knock passengers off the legitimate in-flight network and onto “Delta WiFi Fast,” that’s not a hypothetical vulnerability. That’s the textbook attack, live, on a plane with nowhere to disconnect to.

The Part Nobody Can Actually Confirm Yet

Here’s where the story gets messier than the headlines suggest, and it’s worth sitting with the mess instead of smoothing it over.

Several outlets, including CyberNews and ViewFromTheWing, reported that the fake network’s phishing page harvested Google login credentials and other personal details, based on details relayed through pilot radio messages. That’s a specific, alarming claim. It’s also one Delta hasn’t confirmed. TechCrunch’s original reporting and CBS Atlanta both note that Delta’s preliminary findings, as of publication, don’t establish who created the network or whether any passenger data was actually compromised. Those two things — “a phishing page reportedly asked for Google logins” and “we’ve confirmed data was stolen” — aren’t the same claim, and a lot of coverage has blurred them together.

The FBI angle got similarly overstated in early write-ups, several of which claimed agents met the plane at the gate in Atlanta, questioned suspects, and confiscated devices. When reporters actually got FBI Atlanta on the record, the picture was smaller. Spokesperson Tony Thomas confirmed the bureau is “aware of reports regarding a potential Wi-Fi-related incident involving Delta Flight 591” and is “in contact with our local and corporate partners on this matter” — but said no arrests were made and agents did not meet the flight at the gate, a detail reported by outlets tracking the FBI’s actual statement rather than the earlier viral version.

None of this means the incident wasn’t real. Delta disabling WiFi for 30 minutes mid-flight isn’t a response to nothing. It means the specific, scariest details — credentials confirmed stolen, suspects confirmed caught — are still unverified as of this writing. Treat the underlying threat as real and the dramatic ending as unconfirmed. Both things are true at once.

How Do You Spot a Fake Airport or In-Flight WiFi Network?

  1. Confirm the exact network name with staff before connecting. Ask a flight attendant or airport employee, or check the airline’s app — don’t trust your memory of what the network is “supposed” to be called.
  2. Be suspicious of near-duplicate names. “Delta WiFi Fast” next to “Delta WiFi” is the whole trick. Evil twins rely on a name close enough that you don’t look twice.
  3. Treat any login page asking for a Google, Microsoft, or social account as a red flag. Legitimate airport and in-flight WiFi portals ask you to accept terms or enter a confirmation code — not to sign in with an email provider.
  4. Turn off auto-join for open networks in your phone’s settings. Evil twins depend on devices that reconnect automatically without asking you first.
  5. Watch for the network dropping and reappearing. A sudden disconnect followed by a similarly-named network showing up is the signature of a deauth-and-clone attack, not normal WiFi flakiness.

Protect Yourself Beyond Just Spotting the Name

Recognizing a fake network is step one. The more durable fix is not depending on public or shared WiFi for anything that matters in the first place.

Use your phone’s cellular data or a personal hotspot for sensitive logins. If you need to check email or log into a financial account mid-flight or in an airport, your carrier’s data connection is safer than any shared network, fake or real. We’ve tested Airalo, Holafly, and Saily eSIMs across a dozen countries specifically because carrying your own data connection sidesteps this entire category of attack — you’re not relying on a network you can’t verify.

Turn on multi-factor authentication everywhere it’s offered, especially on your Google account, which is exactly what this attack reportedly targeted. A stolen password is far less useful to an attacker if it’s not enough to get in on its own.

Use a VPN on any network you don’t control, in-flight or otherwise. It won’t stop an evil twin from existing, but it encrypts your traffic before it leaves your device, so a captive portal or man-in-the-middle setup sitting between you and the internet has a lot less to work with. CISA’s guidance on securing wireless networks makes the same recommendation for any public hotspot, not just this one.

Don’t enter passwords into any WiFi login screen that isn’t a simple terms-acceptance click. Real in-flight and airport WiFi portals almost never ask for an external account login. If one does, that’s the tell, not the fine print.

If You Were on the Flight and Already Connected

If you connected to “Delta WiFi Fast” on this specific flight, or you’ve ever entered a password into a WiFi portal that felt off in hindsight, treat it like any other credential exposure. Change the password on whatever account you logged into, starting with Google if that’s what you entered. Check your account’s recent activity and connected-device list for anything unfamiliar. Turn on multi-factor authentication if you haven’t already — CISA’s technique writeup on evil twin attacks notes that once an attacker has a foothold via a captured credential, they can often monitor further activity or pivot to other accounts using the same password. If you reuse passwords across accounts (most people do, we’re not going to pretend otherwise), change those too.

How This Compares to Other Travel Phishing Scams

This isn’t the first time we’ve flagged a scam that piggybacks on a moment when travelers are distracted and moving fast. The FBI’s warning about 19,000 fake FIFA ticket domains worked the same way — attackers didn’t need to fool everyone, just the fraction of people rushing to book before a deadline. An evil twin attack on a plane is the same math with worse odds stacked against you: you’re bored, your phone’s at 40%, and the network just showed up in your list looking exactly like it should. That’s the entire design.

It also lands right after Delta expanded Concierge AI to handle self-service cancellations across the Fly Delta app — a reminder that the same airline pushing more of your account access into a chat interface is also the airline whose in-flight network got spoofed weeks later. Neither story means Delta’s systems were breached; both are about how much trust travelers put in whatever network or interface is in front of them without a second thought.

The Bottom Line

An evil twin WiFi attack showed up on a commercial flight, most likely built with a device you can buy for under $200 and legally own, deployed by someone who — allegedly — had just spent four days at a hacking conference. Delta’s own systems were never at risk. Whether anyone’s actual Google account got compromised is still unconfirmed, and so is exactly who did it. What’s confirmed is simpler and more useful: the attack worked well enough that crew had to kill the plane’s WiFi for half an hour to shut it down.

You don’t need to wait for the FBI to close this case to change how you connect. Confirm network names before you join them. Skip any WiFi login page that wants an email-provider password. Carry your own data connection when you can, and put a VPN between yourself and any network you’re not sure about. None of that is complicated. It’s just not automatic yet, and this is exactly the kind of story that should make it automatic.


Details current as of August 19, 2026, based on reporting from TechCrunch, CyberScoop, Fox 5 Atlanta, CBS Atlanta, ViewFromTheWing, CyberNews, and Tom’s Hardware. The FBI investigation is ongoing and some details — including the extent of any data compromise — remain unconfirmed. Verify current guidance before relying on any single account of this incident.