Fake “Delta WiFi Fast” Hit Passengers After DEF CON

IT Pro Security · Medium sophistication
Last updated August 12, 2026

A passenger on a Delta flight allegedly set up a look‑alike in‑flight Wi‑Fi network (“Delta WiFi Fast”) to trick other passengers into connecting. Reports say the fake hotspot led to a phishing page intended to steal personal credentials, including Google login data. Delta confirmed the incident occurred and said flight safety was not affected.

Key findings

  • An attacker broadcast a rogue Wi‑Fi network named “Delta WiFi Fast” that resembled Delta’s in‑flight service.
  • Crew detected the suspicious network and alerted corporate security via ACARS messages.
  • A witness claimed the rogue hotspot displayed a phishing page intended to harvest passengers’ credentials and Google login data.
  • Reports say authorities boarded the aircraft after landing to question suspects and seize the broadcasting hardware.
  • The attacker may have used a portable device capable of broadcasting fake networks and sending deauthentication frames, forcing devices off the legitimate network.
  • Delta said aircraft operating systems were not affected and the incident is under investigation.

Who’s being targeted

  • Commonly targeted roles: All employees who travel, Executives, Sales, Field staff, IT/security awareness audiences.
  • Affected industries: Airlines / Aviation, Travel and Hospitality.
  • Attack channels: physical, website.
  • Impersonated: Delta in‑flight Wi‑Fi service.

Awareness takeaways

  • Treat public/in‑flight Wi‑Fi names as untrusted; confirm the exact official network name with crew/official instructions before connecting.
  • Never enter corporate passwords (or personal Google credentials) into unexpected Wi‑Fi login pages; use cellular/VPN and sign in only through known apps/sites.
  • Remember the risk may be personal credential theft even if transportation systems are unaffected, report suspicious Wi‑Fi and avoid re-trying logins during outages.

Red flags to watch for

  • A slightly different or unfamiliar Wi‑Fi name that looks like the official network
  • A Wi‑Fi login page asking for personal or Google credentials
  • Connectivity issues consistent with devices being forced off the legitimate network
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

On a real Delta flight after DEF CON, passengers saw a Wi‑Fi called “Delta WiFi Fast”… and some people actually joined it. It wasn’t Delta. A portable device was broadcasting that fake network, kicking people off the real Wi‑Fi and pushing a phishing page to steal logins, including Google accounts. Here’s the trap: you’re mid‑flight, Wi‑Fi keeps dropping, a similar‑looking network pops up, and its login page suddenly wants your personal or Google password. That’s your red flag. On planes, trains, anywhere: if a Wi‑Fi login page asks for your work or Google password, stop, disconnect and use your own connection or VPN instead.

Similar attacks

Freight Scammers Hijack Trucking Identities for AI Gear

Freight Scammers Hijack Trucking Identities for AI Gear

The article describes real cargo theft operations targeting high-value AI data center equipment, including cases where escort vehicles were deliberately disabled so shipments could disappear. It also explains a repeatable fraud workflow where criminals use phishing/social engineering to take over a…

August 12, 2026
UNC6671 Rebrands, Runs IT Helpdesk Vishing

UNC6671 Rebrands, Runs IT Helpdesk Vishing

Google Threat Intelligence reports that extortion group UNC6671 (formerly branded “BlackFile”) is calling employees while posing as IT helpdesk staff and pushing “urgent security migrations.” Victims are lured to spoofed login pages to capture passwords and MFA tokens, enabling Microsoft 365/Okta…

August 7, 2026
Hijacked Hotel Wi‑Fi Tricks Travelers Into Logins

Hijacked Hotel Wi‑Fi Tricks Travelers Into Logins

Microsoft says a Russian-linked group is abusing hotel and conference Wi‑Fi “captive portals” to trick travelers into entering corporate credentials or installing malware. Victims see what looks like a normal Wi‑Fi login flow, but attackers manipulate DNS/website traffic to redirect them to fake…

August 4, 2026
QR-PDF Phishing Hits M365, MFA Bypass Surges

QR-PDF Phishing Hits M365, MFA Bypass Surges

Cisco Talos Incident Response reports that phishing drove initial access in over half of Q2 2026 cases, often using QR codes in PDF attachments and trusted cloud hosting to evade email defenses. Attackers frequently bypassed multi-factor authentication using adversary-in-the-middle proxies,…

July 28, 2026
Fake CoD Points Giveaway Steals Accounts

Fake CoD Points Giveaway Steals Accounts

A phishing campaign targets Call of Duty Mobile players by promising free Call of Duty Points (CP). Victims are tricked into entering their email, password, and then their 2FA code on a fake site that impersonates an official promotion. The attackers use the captured credentials to take over…

July 24, 2026
Kratos PhaaS Fueled MFA-Bypass Phishing

Kratos PhaaS Fueled MFA-Bypass Phishing

Authorities dismantled “Kratos,” a phishing-as-a-service platform used at scale to steal Microsoft account credentials and even bypass MFA by stealing session cookies. The article also describes a real campaign using tax-season lures and personalized QR codes to trick users into visiting fake…

July 24, 2026