Rogue “Delta WiFi Fast” Network Disrupts Flight

eSecurity Planet · Medium sophistication
Last updated August 11, 2026

Delta is investigating an onboard incident where an unauthorized Wi‑Fi network appeared on a flight and the crew shut off Wi‑Fi for about 30 minutes. Reports say a rogue network named “Delta WiFi Fast” may have been used to trick passengers into connecting and potentially entering credentials into a phishing-style login page.

Key findings

  • An unauthorized Wi‑Fi network was detected onboard Delta Flight 591 (Las Vegas to Atlanta), and the crew disabled Wi‑Fi for about 30 minutes.
  • Reports alleged a Wi‑Fi deauthentication attack disrupted access to the legitimate onboard network.
  • A rogue SSID “Delta WiFi Fast” was reportedly broadcast, creating the potential for an evil-twin-style credential harvesting attempt.
  • Third-party reports claimed a phishing page attempted to collect personal information and Google login credentials, but Delta has not confirmed credential theft.

Who’s being targeted

  • Commonly targeted roles: All employees, Frequent travelers, Executives, Sales and customer-facing teams.
  • Affected industries: Airlines / Transportation, Travel / Hospitality (public Wi‑Fi environments).
  • Attack channels: physical, website.
  • Impersonated: Delta onboard Wi‑Fi service.

Awareness takeaways

  • Teach travelers not to trust Wi‑Fi names alone; verify the correct network with staff or official instructions before connecting.
  • Warn users that captive portals asking for corporate or Google credentials can be a phishing attempt, use safer alternatives (cellular/VPN) for sensitive work.
  • Prepare staff for “pressure moments” (outages/disruptions) where attackers rely on urgency to get clicks, connections, or logins.

Red flags to watch for

  • A new/unknown Wi‑Fi name appears during an outage and looks “more official” or “faster”
  • Unexpected login request (especially for Google credentials) just to use onboard Wi‑Fi
  • Connectivity disruption that pressures users to pick any available network quickly
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You’re on a Delta flight, Wi‑Fi dies, and suddenly a new network pops up: “Delta WiFi Fast.” Looks legit, right? On Delta Flight 591, reports say someone broadcast that exact rogue network and may have used an evil‑twin setup to show a fake login page and grab Google credentials. Here’s the trick: Wi‑Fi cuts out, pressure goes up, and a new network name appears that sounds more official and faster. You tap it, see a portal, and it suddenly wants your personal info or Google login just to get online. When Wi‑Fi flakes out in public places, don’t trust the name. Before you connect, confirm the exact network with staff, or skip it and use cellular or VPN for anything sensitive.

Similar attacks

Vishing “Help Desk” Scams and Lookalike Phish Surge

Vishing “Help Desk” Scams and Lookalike Phish Surge

This weekly roundup highlights multiple real-world social engineering threats, including fake IT help-desk phone calls that push employees to phishing sites to steal passwords and one-time authentication codes. It also describes credential-phishing sites impersonating WhatsApp and Instagram that…

August 14, 2026
ChatGPT Billing Phish and Fake Snap Support Scams

ChatGPT Billing Phish and Fake Snap Support Scams

This roundup describes real-world social engineering, including phishing emails that impersonate ChatGPT billing to steal payment card data and a convicted attacker who posed as Snapchat support to trick people into handing over login codes. The common theme is impersonation of trusted brands to…

July 31, 2026
Gambling Goblin Hijacks Gov Sites for Phishing

Gambling Goblin Hijacks Gov Sites for Phishing

Researchers say a Chinese-speaking cybercrime group compromised Brazilian government and education websites and used them as “trusted” entry points to quietly redirect visitors to attacker-run phishing pages. The fake pages impersonated well-known app stores (Google Play, Microsoft Store, Amazon)…

September 2, 2026
Scammers Shift Lures to Email, Text, and Social

Scammers Shift Lures to Email, Text, and Social

Malwarebytes reports that scammers are increasingly tailoring different scams to the platforms where they work best, like unpaid-toll lures via email/SMS, romance scams via social media, and IRS scams via phone calls. The report highlights heavy brand and celebrity impersonation (including MrBeast)…

September 2, 2026
FBI: OAuth Consent Phishing Targets Prominent People

FBI: OAuth Consent Phishing Targets Prominent People

The FBI warns attackers are impersonating public figures on messaging apps and email to trick targets into approving a malicious OAuth app. Victims are sent links that lead to real Microsoft or Google login/consent screens, where approving access grants attackers ongoing access to emails and files.…

September 2, 2026
Gov Websites Hijacked to Push Fake App Stores

Gov Websites Hijacked to Push Fake App Stores

Check Point Research reports a real campaign where a Chinese-speaking actor compromised Brazilian government and education websites and used them as stealthy “front doors” to redirect visitors to attacker-controlled phishing pages. The fake pages impersonate trusted app stores (Google Play,…

September 2, 2026