A passenger on a Delta flight allegedly set up a look‑alike in‑flight Wi‑Fi network (“Delta WiFi Fast”) to trick other passengers into connecting. Reports say the fake hotspot led to a phishing page intended to steal personal credentials, including Google login data. Delta confirmed the incident occurred and said flight safety was not affected.
Key findings
- An attacker broadcast a rogue Wi‑Fi network named “Delta WiFi Fast” that resembled Delta’s in‑flight service.
- Crew detected the suspicious network and alerted corporate security via ACARS messages.
- A witness claimed the rogue hotspot displayed a phishing page intended to harvest passengers’ credentials and Google login data.
- Reports say authorities boarded the aircraft after landing to question suspects and seize the broadcasting hardware.
- The attacker may have used a portable device capable of broadcasting fake networks and sending deauthentication frames, forcing devices off the legitimate network.
- Delta said aircraft operating systems were not affected and the incident is under investigation.
Who’s being targeted
- Commonly targeted roles: All employees who travel, Executives, Sales, Field staff, IT/security awareness audiences.
- Affected industries: Airlines / Aviation, Travel and Hospitality.
- Attack channels: physical, website.
- Impersonated: Delta in‑flight Wi‑Fi service.
Awareness takeaways
- Treat public/in‑flight Wi‑Fi names as untrusted; confirm the exact official network name with crew/official instructions before connecting.
- Never enter corporate passwords (or personal Google credentials) into unexpected Wi‑Fi login pages; use cellular/VPN and sign in only through known apps/sites.
- Remember the risk may be personal credential theft even if transportation systems are unaffected, report suspicious Wi‑Fi and avoid re-trying logins during outages.
Red flags to watch for
- A slightly different or unfamiliar Wi‑Fi name that looks like the official network
- A Wi‑Fi login page asking for personal or Google credentials
- Connectivity issues consistent with devices being forced off the legitimate network
Read the video transcript
On a real Delta flight after DEF CON, passengers saw a Wi‑Fi called “Delta WiFi Fast”… and some people actually joined it. It wasn’t Delta. A portable device was broadcasting that fake network, kicking people off the real Wi‑Fi and pushing a phishing page to steal logins, including Google accounts. Here’s the trap: you’re mid‑flight, Wi‑Fi keeps dropping, a similar‑looking network pops up, and its login page suddenly wants your personal or Google password. That’s your red flag. On planes, trains, anywhere: if a Wi‑Fi login page asks for your work or Google password, stop, disconnect and use your own connection or VPN instead.