A passenger on a Delta flight allegedly set up a look‑alike Wi‑Fi network (“Delta WiFi FAST”) and tried to disrupt the real onboard Wi‑Fi so other passengers would join the fake hotspot. The goal was likely to push users to a login page and capture credentials (e.g., Google or Facebook). This is a realistic, repeatable social‑engineering pattern for traveler awareness training: “evil twin” Wi‑Fi plus a captive portal.
How the attack worked
On a Delta flight, a passenger allegedly stood up a rogue Wi-Fi hotspot named “Delta WiFi FAST,” a name close enough to the real in-flight network to look legitimate at a glance. To increase the odds that other passengers would connect, the attacker reportedly tried to disrupt the legitimate onboard Wi-Fi so it appeared broken. With the real network rendered useless, passengers were more likely to pick the fake one instead, believing it was simply another access point or a faster alternative.
Once connected, the fake network would likely have presented a captive portal login page. Instead of asking for booking details, this portal probably prompted users to sign in with credentials for another site, such as Google or Facebook, a classic credential harvesting move disguised as a routine Wi-Fi login step.
Why it succeeded
This attack works because open, public Wi-Fi networks cannot be authenticated by the end user. There is no cryptographic way for a passenger's device to verify that “Delta WiFi FAST” is actually operated by the airline, which makes creating a convincing look-alike network technically easy. Travelers are also conditioned by years of hotel, airport, and airline hotspots to expect a login or click-through portal before getting online, so an unexpected credential prompt does not necessarily raise suspicion in the moment.
What to watch for
- A Wi-Fi network name that is similar to, but not exactly, the official network provided by staff or signage.
- The legitimate network suddenly failing to connect or dropping out, pressuring travelers to try an alternative.
- A login page asking for personal account credentials, such as Google or Facebook, just to access what should be a simple internet connection.
How to build resistance
- Only join the exact Wi-Fi network name confirmed by airline staff or official signage, and avoid similarly named “fast” or “free” variants.
- Treat any captive portal as untrusted and avoid entering real account passwords to get online.
- Be suspicious if the official network suddenly stops working right as an alternative network appears.
- When possible, use cellular data or a trusted VPN instead of joining unfamiliar open hotspots, especially in high-traffic travel settings like airports, hotels, and airlines.
Key findings
- A fake onboard Wi‑Fi SSID (“Delta WiFi FAST”) was reportedly used to trick passengers into connecting.
- The attacker allegedly attempted to disrupt the legitimate Wi‑Fi so the fake network looked like the only working option.
- The likely end goal was credential harvesting via a web login prompt (e.g., prompting for Google or Facebook credentials).
- Open/public hotspot models (airlines, hotels) are especially vulnerable because users are conditioned to click through captive portals and enter booking/room details.
Who’s being targeted
- Commonly targeted roles: Executives, Sales, Traveling employees, Conference attendees, All staff who use public Wi‑Fi (airports/hotels/airlines).
- Affected industries: Airlines / air travel, Hospitality (hotels and public hotspots), Consumer e-commerce (order-data-driven phishing risk).
- Attack channels: physical, website.
- Impersonated: Delta in‑flight Wi‑Fi.
Red flags to watch for
- Look‑alike Wi‑Fi name that’s slightly different from the official network
- Connectivity problems on the real network that pressure users to “try another network”
- Unexpected request to sign in with personal accounts (e.g., Google/Facebook) just to get Wi‑Fi
Frequently asked questions
What was the “Delta WiFi FAST” attack?
A passenger on a Delta flight allegedly set up a fake Wi-Fi hotspot named “Delta WiFi FAST” to trick other passengers into connecting, likely to steer them to a fake login page.
How did the attacker get people to join the fake network?
The attacker reportedly tried to disrupt the legitimate in-flight Wi-Fi so it looked broken, pushing passengers toward the fake network as the only working option.
What was the attacker after?
The likely goal was credential harvesting, with the fake network prompting users to log in with accounts such as Google or Facebook to get online.
Why are public hotspots like airline or hotel Wi-Fi easy to spoof?
Open Wi-Fi networks can't be authenticated, so creating a look-alike network is easy, and users are already conditioned to click through captive portals without questioning them.
Read the video transcript
You’re on a Delta flight, hunting for Wi‑Fi, and you see a network called “Delta WiFi FAST.” Looks legit, right? On a real flight, someone reportedly spun up that exact fake hotspot and tried to break the real Delta Wi‑Fi, so everyone would join their “Delta WiFi FAST” instead. That’s an evil twin hotspot. Once you’re on it, a captive portal pops up: “Sign in with Google or Facebook to get free in‑flight internet.” That’s where they grab your credentials, your email, your social, maybe even company access. On planes, in hotels, anywhere: only join the exact Wi‑Fi name on the official sign, and never type your Google, Facebook, or work password just to get public Wi‑Fi.