Rogue “Delta WiFi Fast” Network Disrupts Flight

eSecurity Planet · Medium sophistication
Last updated August 11, 2026

Delta is investigating an onboard incident where an unauthorized Wi‑Fi network appeared on a flight and the crew shut off Wi‑Fi for about 30 minutes. Reports say a rogue network named “Delta WiFi Fast” may have been used to trick passengers into connecting and potentially entering credentials into a phishing-style login page.

Key findings

  • An unauthorized Wi‑Fi network was detected onboard Delta Flight 591 (Las Vegas to Atlanta), and the crew disabled Wi‑Fi for about 30 minutes.
  • Reports alleged a Wi‑Fi deauthentication attack disrupted access to the legitimate onboard network.
  • A rogue SSID “Delta WiFi Fast” was reportedly broadcast, creating the potential for an evil-twin-style credential harvesting attempt.
  • Third-party reports claimed a phishing page attempted to collect personal information and Google login credentials, but Delta has not confirmed credential theft.

Who’s being targeted

  • Commonly targeted roles: All employees, Frequent travelers, Executives, Sales and customer-facing teams.
  • Affected industries: Airlines / Transportation, Travel / Hospitality (public Wi‑Fi environments).
  • Attack channels: physical, website.
  • Impersonated: Delta onboard Wi‑Fi service.

Awareness takeaways

  • Teach travelers not to trust Wi‑Fi names alone; verify the correct network with staff or official instructions before connecting.
  • Warn users that captive portals asking for corporate or Google credentials can be a phishing attempt, use safer alternatives (cellular/VPN) for sensitive work.
  • Prepare staff for “pressure moments” (outages/disruptions) where attackers rely on urgency to get clicks, connections, or logins.

Red flags to watch for

  • A new/unknown Wi‑Fi name appears during an outage and looks “more official” or “faster”
  • Unexpected login request (especially for Google credentials) just to use onboard Wi‑Fi
  • Connectivity disruption that pressures users to pick any available network quickly
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You’re on a Delta flight, Wi‑Fi dies, and suddenly a new network pops up: “Delta WiFi Fast.” Looks legit, right? On Delta Flight 591, reports say someone broadcast that exact rogue network and may have used an evil‑twin setup to show a fake login page and grab Google credentials. Here’s the trick: Wi‑Fi cuts out, pressure goes up, and a new network name appears that sounds more official and faster. You tap it, see a portal, and it suddenly wants your personal info or Google login just to get online. When Wi‑Fi flakes out in public places, don’t trust the name. Before you connect, confirm the exact network with staff, or skip it and use cellular or VPN for anything sensitive.

Similar attacks

Vishing “Help Desk” Scams and Lookalike Phish Surge

Vishing “Help Desk” Scams and Lookalike Phish Surge

This weekly roundup highlights multiple real-world social engineering threats, including fake IT help-desk phone calls that push employees to phishing sites to steal passwords and one-time authentication codes. It also describes credential-phishing sites impersonating WhatsApp and Instagram that…

August 14, 2026
ChatGPT Billing Phish and Fake Snap Support Scams

ChatGPT Billing Phish and Fake Snap Support Scams

This roundup describes real-world social engineering, including phishing emails that impersonate ChatGPT billing to steal payment card data and a convicted attacker who posed as Snapchat support to trick people into handing over login codes. The common theme is impersonation of trusted brands to…

July 31, 2026
AI Search Results Turn Into Phishing Traps

AI Search Results Turn Into Phishing Traps

This bulletin describes multiple real-world scams where attackers make fake pages and messages look like routine, trusted experiences (search answers, Google login pop-ups, “giveaways,” and official-sounding calls). Examples include a fake Claude Max giveaway using a convincing fake Google sign-in…

September 24, 2026
Fake Claude Max Promo Steals Google Logins

Fake Claude Max Promo Steals Google Logins

Researchers found a real phishing campaign offering a “free” Claude Max upgrade to trick people into signing in with Google. The site uses a fake, draggable Google login pop-up (“browser-in-the-browser”) that looks legitimate and captures credentials. A stolen Google account can expose email and…

September 23, 2026
Fake Claude Max Promo Steals Google Logins

Fake Claude Max Promo Steals Google Logins

Researchers found a phishing campaign offering a “free” upgrade to Claude Max to trick people into signing in with Google. The page uses a convincing fake, draggable Google login window (“browser-in-the-browser”) to capture credentials, potentially giving criminals access to email, documents, and…

September 23, 2026
Fake AI Subscription Sites Push $2,000 Plans

Fake AI Subscription Sites Push $2,000 Plans

Researchers found a network of 100+ polished look‑alike subscription websites that impersonate real products (and invent new ones) to sell expensive “AI” plans. The sites rely on professional landing pages and a real Google sign-in flow to appear legitimate, then steer visitors into paid…

September 21, 2026