Fake “Delta WiFi FAST” Tricked Flyers

Hackaday · Medium sophistication
Last updated August 17, 2026

A passenger on a Delta flight allegedly set up a look‑alike Wi‑Fi network (“Delta WiFi FAST”) and tried to disrupt the real onboard Wi‑Fi so other passengers would join the fake hotspot. The goal was likely to push users to a login page and capture credentials (e.g., Google or Facebook). This is a realistic, repeatable social‑engineering pattern for traveler awareness training: “evil twin” Wi‑Fi plus a captive portal.

How the attack worked

On a Delta flight, a passenger allegedly stood up a rogue Wi-Fi hotspot named “Delta WiFi FAST,” a name close enough to the real in-flight network to look legitimate at a glance. To increase the odds that other passengers would connect, the attacker reportedly tried to disrupt the legitimate onboard Wi-Fi so it appeared broken. With the real network rendered useless, passengers were more likely to pick the fake one instead, believing it was simply another access point or a faster alternative.

Once connected, the fake network would likely have presented a captive portal login page. Instead of asking for booking details, this portal probably prompted users to sign in with credentials for another site, such as Google or Facebook, a classic credential harvesting move disguised as a routine Wi-Fi login step.

Why it succeeded

This attack works because open, public Wi-Fi networks cannot be authenticated by the end user. There is no cryptographic way for a passenger's device to verify that “Delta WiFi FAST” is actually operated by the airline, which makes creating a convincing look-alike network technically easy. Travelers are also conditioned by years of hotel, airport, and airline hotspots to expect a login or click-through portal before getting online, so an unexpected credential prompt does not necessarily raise suspicion in the moment.

What to watch for

  • A Wi-Fi network name that is similar to, but not exactly, the official network provided by staff or signage.
  • The legitimate network suddenly failing to connect or dropping out, pressuring travelers to try an alternative.
  • A login page asking for personal account credentials, such as Google or Facebook, just to access what should be a simple internet connection.

How to build resistance

  • Only join the exact Wi-Fi network name confirmed by airline staff or official signage, and avoid similarly named “fast” or “free” variants.
  • Treat any captive portal as untrusted and avoid entering real account passwords to get online.
  • Be suspicious if the official network suddenly stops working right as an alternative network appears.
  • When possible, use cellular data or a trusted VPN instead of joining unfamiliar open hotspots, especially in high-traffic travel settings like airports, hotels, and airlines.

Key findings

  • A fake onboard Wi‑Fi SSID (“Delta WiFi FAST”) was reportedly used to trick passengers into connecting.
  • The attacker allegedly attempted to disrupt the legitimate Wi‑Fi so the fake network looked like the only working option.
  • The likely end goal was credential harvesting via a web login prompt (e.g., prompting for Google or Facebook credentials).
  • Open/public hotspot models (airlines, hotels) are especially vulnerable because users are conditioned to click through captive portals and enter booking/room details.

Who’s being targeted

  • Commonly targeted roles: Executives, Sales, Traveling employees, Conference attendees, All staff who use public Wi‑Fi (airports/hotels/airlines).
  • Affected industries: Airlines / air travel, Hospitality (hotels and public hotspots), Consumer e-commerce (order-data-driven phishing risk).
  • Attack channels: physical, website.
  • Impersonated: Delta in‑flight Wi‑Fi.

Red flags to watch for

  • Look‑alike Wi‑Fi name that’s slightly different from the official network
  • Connectivity problems on the real network that pressure users to “try another network”
  • Unexpected request to sign in with personal accounts (e.g., Google/Facebook) just to get Wi‑Fi
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What was the “Delta WiFi FAST” attack?

A passenger on a Delta flight allegedly set up a fake Wi-Fi hotspot named “Delta WiFi FAST” to trick other passengers into connecting, likely to steer them to a fake login page.

How did the attacker get people to join the fake network?

The attacker reportedly tried to disrupt the legitimate in-flight Wi-Fi so it looked broken, pushing passengers toward the fake network as the only working option.

What was the attacker after?

The likely goal was credential harvesting, with the fake network prompting users to log in with accounts such as Google or Facebook to get online.

Why are public hotspots like airline or hotel Wi-Fi easy to spoof?

Open Wi-Fi networks can't be authenticated, so creating a look-alike network is easy, and users are already conditioned to click through captive portals without questioning them.

Read the video transcript

You’re on a Delta flight, hunting for Wi‑Fi, and you see a network called “Delta WiFi FAST.” Looks legit, right? On a real flight, someone reportedly spun up that exact fake hotspot and tried to break the real Delta Wi‑Fi, so everyone would join their “Delta WiFi FAST” instead. That’s an evil twin hotspot. Once you’re on it, a captive portal pops up: “Sign in with Google or Facebook to get free in‑flight internet.” That’s where they grab your credentials, your email, your social, maybe even company access. On planes, in hotels, anywhere: only join the exact Wi‑Fi name on the official sign, and never type your Google, Facebook, or work password just to get public Wi‑Fi.

Similar attacks

Fake “Delta WiFi Fast” Hit Passengers After DEF CON

Fake “Delta WiFi Fast” Hit Passengers After DEF CON

A passenger on a Delta flight allegedly set up a look‑alike in‑flight Wi‑Fi network (“Delta WiFi Fast”) to trick other passengers into connecting. Reports say the fake hotspot led to a phishing page intended to steal personal credentials, including Google login data. Delta confirmed the incident…

August 12, 2026
Vishing “Help Desk” Scams and Lookalike Phish Surge

Vishing “Help Desk” Scams and Lookalike Phish Surge

This weekly roundup highlights multiple real-world social engineering threats, including fake IT help-desk phone calls that push employees to phishing sites to steal passwords and one-time authentication codes. It also describes credential-phishing sites impersonating WhatsApp and Instagram that…

August 14, 2026
Fake IRS Letters and BoA Emails Push Remote Access Scams

Fake IRS Letters and BoA Emails Push Remote Access Scams

This weekly roundup includes real-world social engineering campaigns, including scammers mailing fake IRS letters to cryptocurrency holders and a phishing campaign impersonating Bank of America. The lures are designed to pressure victims into visiting a bogus compliance portal or installing remote…

August 9, 2026
Phishers Abuse DocuSign, Rewards, and “Verification”

Phishers Abuse DocuSign, Rewards, and “Verification”

This weekly roundup describes multiple real-world campaigns where attackers trick people using familiar brands and “verification” prompts to steal credentials or install remote-control tools. The common theme is trust abuse: messages and web pages look legitimate, then push users to log in, click…

July 28, 2026
Fake Zoom/Teams Calls Used to Steal Crypto Wallets

Fake Zoom/Teams Calls Used to Steal Crypto Wallets

North Korea-linked BlueNoroff is using fake Zoom and Microsoft Teams meeting pages shared from hijacked trusted contacts (often via Telegram) to trick victims into “updating” Zoom/Teams and running malicious commands. The phishing kit also fingerprints the victim’s browser to identify installed…

July 24, 2026
Fake Advisors, ClickFix, and Chrome Sync Spying

Fake Advisors, ClickFix, and Chrome Sync Spying

This roundup describes several real-world social-engineering and human-abuse techniques, including trojanized “installer” lures (ClickFix), large-scale phone-based investment fraud, and stalkers misusing Chrome Sync after brief physical access. The items include clear workflows that can be turned…

July 16, 2026