Fake “Delta WiFi FAST” Tricked Flyers

Hackaday · Medium sophistication
Last updated August 17, 2026

A passenger on a Delta flight allegedly set up a look‑alike Wi‑Fi network (“Delta WiFi FAST”) and tried to disrupt the real onboard Wi‑Fi so other passengers would join the fake hotspot. The goal was likely to push users to a login page and capture credentials (e.g., Google or Facebook). This is a realistic, repeatable social‑engineering pattern for traveler awareness training: “evil twin” Wi‑Fi plus a captive portal.

How the attack worked

On a Delta flight, a passenger allegedly stood up a rogue Wi-Fi hotspot named “Delta WiFi FAST,” a name close enough to the real in-flight network to look legitimate at a glance. To increase the odds that other passengers would connect, the attacker reportedly tried to disrupt the legitimate onboard Wi-Fi so it appeared broken. With the real network rendered useless, passengers were more likely to pick the fake one instead, believing it was simply another access point or a faster alternative.

Once connected, the fake network would likely have presented a captive portal login page. Instead of asking for booking details, this portal probably prompted users to sign in with credentials for another site, such as Google or Facebook, a classic credential harvesting move disguised as a routine Wi-Fi login step.

Why it succeeded

This attack works because open, public Wi-Fi networks cannot be authenticated by the end user. There is no cryptographic way for a passenger's device to verify that “Delta WiFi FAST” is actually operated by the airline, which makes creating a convincing look-alike network technically easy. Travelers are also conditioned by years of hotel, airport, and airline hotspots to expect a login or click-through portal before getting online, so an unexpected credential prompt does not necessarily raise suspicion in the moment.

What to watch for

  • A Wi-Fi network name that is similar to, but not exactly, the official network provided by staff or signage.
  • The legitimate network suddenly failing to connect or dropping out, pressuring travelers to try an alternative.
  • A login page asking for personal account credentials, such as Google or Facebook, just to access what should be a simple internet connection.

How to build resistance

  • Only join the exact Wi-Fi network name confirmed by airline staff or official signage, and avoid similarly named “fast” or “free” variants.
  • Treat any captive portal as untrusted and avoid entering real account passwords to get online.
  • Be suspicious if the official network suddenly stops working right as an alternative network appears.
  • When possible, use cellular data or a trusted VPN instead of joining unfamiliar open hotspots, especially in high-traffic travel settings like airports, hotels, and airlines.

Key findings

  • A fake onboard Wi‑Fi SSID (“Delta WiFi FAST”) was reportedly used to trick passengers into connecting.
  • The attacker allegedly attempted to disrupt the legitimate Wi‑Fi so the fake network looked like the only working option.
  • The likely end goal was credential harvesting via a web login prompt (e.g., prompting for Google or Facebook credentials).
  • Open/public hotspot models (airlines, hotels) are especially vulnerable because users are conditioned to click through captive portals and enter booking/room details.

Who’s being targeted

  • Commonly targeted roles: Executives, Sales, Traveling employees, Conference attendees, All staff who use public Wi‑Fi (airports/hotels/airlines).
  • Affected industries: Airlines / air travel, Hospitality (hotels and public hotspots), Consumer e-commerce (order-data-driven phishing risk).
  • Attack channels: physical, website.
  • Impersonated: Delta in‑flight Wi‑Fi.

Red flags to watch for

  • Look‑alike Wi‑Fi name that’s slightly different from the official network
  • Connectivity problems on the real network that pressure users to “try another network”
  • Unexpected request to sign in with personal accounts (e.g., Google/Facebook) just to get Wi‑Fi
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

What was the “Delta WiFi FAST” attack?

A passenger on a Delta flight allegedly set up a fake Wi-Fi hotspot named “Delta WiFi FAST” to trick other passengers into connecting, likely to steer them to a fake login page.

How did the attacker get people to join the fake network?

The attacker reportedly tried to disrupt the legitimate in-flight Wi-Fi so it looked broken, pushing passengers toward the fake network as the only working option.

What was the attacker after?

The likely goal was credential harvesting, with the fake network prompting users to log in with accounts such as Google or Facebook to get online.

Why are public hotspots like airline or hotel Wi-Fi easy to spoof?

Open Wi-Fi networks can't be authenticated, so creating a look-alike network is easy, and users are already conditioned to click through captive portals without questioning them.

Read the video transcript

You’re on a Delta flight, hunting for Wi‑Fi, and you see a network called “Delta WiFi FAST.” Looks legit, right? On a real flight, someone reportedly spun up that exact fake hotspot and tried to break the real Delta Wi‑Fi, so everyone would join their “Delta WiFi FAST” instead. That’s an evil twin hotspot. Once you’re on it, a captive portal pops up: “Sign in with Google or Facebook to get free in‑flight internet.” That’s where they grab your credentials, your email, your social, maybe even company access. On planes, in hotels, anywhere: only join the exact Wi‑Fi name on the official sign, and never type your Google, Facebook, or work password just to get public Wi‑Fi.

Similar attacks

Fake Google Play Pages Push Spyware at Logistics

Fake Google Play Pages Push Spyware at Logistics

A real campaign is targeting logistics firms with fake Google Play pages impersonating well-known logistics brands to trick employees into installing an Android spyware app. Once installed, the spyware can steal newly received SMS messages (including one-time passcodes) and enable call forwarding,…

September 24, 2026
Fake “Delta WiFi Fast” Hit Passengers After DEF CON

Fake “Delta WiFi Fast” Hit Passengers After DEF CON

A passenger on a Delta flight allegedly set up a look‑alike in‑flight Wi‑Fi network (“Delta WiFi Fast”) to trick other passengers into connecting. Reports say the fake hotspot led to a phishing page intended to steal personal credentials, including Google login data. Delta confirmed the incident…

August 12, 2026
Vishing Wave Hits Healthcare With MFA Reset Traps

Vishing Wave Hits Healthcare With MFA Reset Traps

Threat groups are actively targeting healthcare and pharma staff using phone-based social engineering (“vishing”) and look‑alike medical domains to steal employee login credentials. Researchers say attackers pressure employees to click password-reset or MFA-reset links, and multiple…

September 28, 2026
AI Search Results Turn Into Phishing Traps

AI Search Results Turn Into Phishing Traps

This bulletin describes multiple real-world scams where attackers make fake pages and messages look like routine, trusted experiences (search answers, Google login pop-ups, “giveaways,” and official-sounding calls). Examples include a fake Claude Max giveaway using a convincing fake Google sign-in…

September 24, 2026
ClickFix Lures Turn Trusted Sites Into Malware Traps

ClickFix Lures Turn Trusted Sites Into Malware Traps

A CTM360 report describes real-world “ClickFix” campaigns where attackers compromise legitimate websites and show fake error/verification messages that trick users into copying a command and pasting it into trusted system tools (Run box, PowerShell, Terminal). This approach avoids traditional…

September 24, 2026
Fake Helpdesk Passkey Setup Steals Cloud Access

Fake Helpdesk Passkey Setup Steals Cloud Access

The article describes real intrusions where attackers impersonate a company helpdesk and lure employees into "passkey, MFA, or SSO setup" steps. Victims are sent links via text (often to personal phones), leading to account takeover through adversary-in-the-middle phishing or device-code…

September 16, 2026