Delta Airlines is investigating an incident in which a passenger allegedly used a device to spoof the airline's in-flight Wi-Fi network on a flight from Las Vegas to Atlanta, prompting the crew to shut down the network and federal authorities to meet the plane on arrival.

 

What happened

A passenger on Delta flight 591 from Las Vegas to Atlanta allegedly used an unidentified device to create a rogue Wi-Fi network that could steal other passengers' sensitive data or personal information. The flight departed Monday, after being delayed from its original Sunday schedule until 8:30 a.m. Aircraft Communications Addressing and Reporting System (ACARS) messages show the crew told ground personnel that a passenger set up a network named "Delta WiFi Fast" and was attempting to scam other passengers. Delta's cabin crew deactivated the aircraft's Wi-Fi for approximately 30 minutes. The airline says the flight's safety was never in question and no aircraft operating systems were affected. Federal agents met the plane once it landed in Atlanta.

 

Going deeper

The incident happened after the annual DEF CON cybersecurity conference wrapped up in Las Vegas on Sunday, and the delayed flight put a plane full of passengers, likely including conference attendees, in the air on Monday morning. The FBI's Atlanta office and the Federal Aviation Administration both confirmed awareness of the incident.

 

What was said

Delta spokesperson Morgan Durrant told CyberScoop, "We are fully investigating to gather a complete set of facts, which will take time." Durrant added, "We will partner with federal law enforcement and aviation regulators to ensure the incident is thoroughly investigated. We thank our crew for their professionalism and our customers for their understanding."

Monika Hathaway, head of press for DEF CON, told CyberScoop, "Our conference this year also suffered from multiple similar 'deauthorization' Wi-Fi attacks and it impacted some of our operations." She added, "If we had caught them doing this at DEF CON we would have removed and banned them from the conference."

 

In the know

Security researchers describe this type of incident as an "evil twin attack." In this attack, someone deploys a rogue Wi-Fi access point that clones the name and settings of a legitimate, trusted network, tricking nearby devices into connecting to it automatically instead of the real one. Attackers often pair this with deauthentication attacks, which forcibly disconnect devices from the legitimate network so they reconnect to the fake one instead. Once a device connects to the rogue access point, the attacker can monitor unencrypted internet traffic, run man-in-the-middle attacks, or serve fake login pages designed to harvest usernames, passwords, and other personal data.

 

Why it matters

Healthcare workers travel for conferences, site visits, and patient care, and many rely on in-flight Wi-Fi to check email, access records, or handle other work tied to protected health information (PHI) while in transit. This incident shows how that connection can be hijacked. Anyone on that flight who logged into a work email account, an EHR portal, or any other system carrying PHI over that rogue network could have had their credentials or data intercepted, a scenario that would trigger HIPAA breach obligations for any covered entity or business associate whose data was exposed. Since passengers cannot leave a shared cabin network the way they could step away from a public Wi-Fi hotspot on the ground, air travel creates a captive setting for this kind of attack. The incident is a reminder that healthcare organizations need policies covering how staff access PHI while traveling, including guidance against using unsecured or unverified Wi-Fi networks, whether in an airport, a hotel, or 30,000 feet in the air.

Read also: Is in-flight Wi-Fi HIPAA compliant?

 

FAQs

What is public Wi-Fi spoofing?

Public Wi-Fi spoofing is when someone sets up a fake wireless network that mimics a legitimate one to trick devices into connecting to it.

 

How can someone tell if a Wi-Fi network is fake?

Unexpected login prompts, a network name that's slightly different from the official one, or a sudden loss of connection followed by a new network appearing are all warning signs.

 

Is it illegal to spoof a Wi-Fi network?

Yes, creating a fraudulent network to intercept data or deceive users without authorization can violate computer fraud and wiretapping laws in the United States.

 

How can travelers protect themselves on public or in-flight Wi-Fi?

Using a VPN, avoiding logins to sensitive accounts, and confirming the exact network name with staff before connecting can all reduce risk on any public network.