Rogue “Delta WiFi Fast” Network Disrupts Flight

eSecurity Planet · Medium sophistication
Last updated August 11, 2026

Delta is investigating an onboard incident where an unauthorized Wi‑Fi network appeared on a flight and the crew shut off Wi‑Fi for about 30 minutes. Reports say a rogue network named “Delta WiFi Fast” may have been used to trick passengers into connecting and potentially entering credentials into a phishing-style login page.

Key findings

  • An unauthorized Wi‑Fi network was detected onboard Delta Flight 591 (Las Vegas to Atlanta), and the crew disabled Wi‑Fi for about 30 minutes.
  • Reports alleged a Wi‑Fi deauthentication attack disrupted access to the legitimate onboard network.
  • A rogue SSID “Delta WiFi Fast” was reportedly broadcast, creating the potential for an evil-twin-style credential harvesting attempt.
  • Third-party reports claimed a phishing page attempted to collect personal information and Google login credentials, but Delta has not confirmed credential theft.

Who’s being targeted

  • Commonly targeted roles: All employees, Frequent travelers, Executives, Sales and customer-facing teams.
  • Affected industries: Airlines / Transportation, Travel / Hospitality (public Wi‑Fi environments).
  • Attack channels: physical, website.
  • Impersonated: Delta onboard Wi‑Fi service.

Awareness takeaways

  • Teach travelers not to trust Wi‑Fi names alone; verify the correct network with staff or official instructions before connecting.
  • Warn users that captive portals asking for corporate or Google credentials can be a phishing attempt, use safer alternatives (cellular/VPN) for sensitive work.
  • Prepare staff for “pressure moments” (outages/disruptions) where attackers rely on urgency to get clicks, connections, or logins.

Red flags to watch for

  • A new/unknown Wi‑Fi name appears during an outage and looks “more official” or “faster”
  • Unexpected login request (especially for Google credentials) just to use onboard Wi‑Fi
  • Connectivity disruption that pressures users to pick any available network quickly
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

You’re on a Delta flight, Wi‑Fi dies, and suddenly a new network pops up: “Delta WiFi Fast.” Looks legit, right? On Delta Flight 591, reports say someone broadcast that exact rogue network and may have used an evil‑twin setup to show a fake login page and grab Google credentials. Here’s the trick: Wi‑Fi cuts out, pressure goes up, and a new network name appears that sounds more official and faster. You tap it, see a portal, and it suddenly wants your personal info or Google login just to get online. When Wi‑Fi flakes out in public places, don’t trust the name. Before you connect, confirm the exact network with staff, or skip it and use cellular or VPN for anything sensitive.

Similar attacks

ChatGPT Billing Phish and Fake Snap Support Scams

ChatGPT Billing Phish and Fake Snap Support Scams

This roundup describes real-world social engineering, including phishing emails that impersonate ChatGPT billing to steal payment card data and a convicted attacker who posed as Snapchat support to trick people into handing over login codes. The common theme is impersonation of trusted brands to…

July 31, 2026
Fake Voicemail Alert Steals Google Passwords

Fake Voicemail Alert Steals Google Passwords

A real phishing campaign is tricking employees with a “missed voicemail” message that claims they have a new audio message. Clicking “Play Audio” sends victims through multiple trusted-looking redirects and ends on a fake Google sign-in page that captures Google Workspace credentials, potentially…

August 12, 2026
Helix Extortion Hit Uber Freight via Helpdesk Vishing

Helix Extortion Hit Uber Freight via Helpdesk Vishing

Uber Freight is investigating unauthorized access after the Helix extortion group claimed it stole nearly one million files from company cloud and email repositories. Google-linked research says the broader cluster (UNC6671) commonly gets in by calling employees and posing as IT helpdesk staff…

August 12, 2026
Fake “Delta WiFi Fast” Hit Passengers After DEF CON

Fake “Delta WiFi Fast” Hit Passengers After DEF CON

A passenger on a Delta flight allegedly set up a look‑alike in‑flight Wi‑Fi network (“Delta WiFi Fast”) to trick other passengers into connecting. Reports say the fake hotspot led to a phishing page intended to steal personal credentials, including Google login data. Delta confirmed the incident…

August 12, 2026
Invitation Emails Used to Steal Logins & Install RATs

Invitation Emails Used to Steal Logins & Install RATs

Cofense reports a sustained rise in real phishing campaigns disguised as party/event invitations that trick people into clicking links. The same invitation lure is being used both to steal usernames/passwords via fake login pages and to install legitimate-but-abused remote access tools that give…

August 12, 2026
Levi’s Breach Started With IT Helpdesk Impersonation

Levi’s Breach Started With IT Helpdesk Impersonation

Levi Strauss reported that an unauthorized party used social-engineering to compromise three employees’ company-issued computers and steal corporate data. Reporting tied the incident to a wider campaign where attackers impersonated IT help desks using spoofed phone numbers and fraudulent websites…

August 10, 2026