Passenger Sets Up Rogue Wi-Fi Network on Delta Flight, Prompting Mid-Air ATC Alerts

An unidentified passenger allegedly created a fake Wi-Fi network aboard a Delta Air Lines flight from Las Vegas to Atlanta on Monday, prompting pilots to alert air traffic control twice during the flight. TechCrunch
The rogue access point was designed to impersonate the aircraft's legitimate in-flight wireless network, according to the pilots' messages to ATC. In response, the flight crew shut down the plane's real Wi-Fi service for approximately 30 minutes.
Delta spokesperson Morgan Durrant confirmed that the safety of flight was never in question, no aircraft operating systems were affected, and the in-flight network itself was not compromised. The airline said it is fully investigating the incident and will coordinate with federal law enforcement and aviation regulators.
The pilots noted in their ATC messages that some passengers on the flight had attended cybersecurity conferences held in Las Vegas the prior week, which contextualizes the technical sophistication of the spoof but does not itself identify a suspect. No individual has been publicly identified.
Law enforcement and regulatory response remains uneven. The Atlanta Police Department referred questions about the incident to federal authorities. FAA spokesperson Steve Kulm said the agency had not received a report about the incident. The FBI did not immediately respond to TechCrunch's request for comment.
The incident fits a well-known attack pattern. Deploying a rogue access point with a matching or deceptively similar SSID is a textbook evil-twin attack, effective against devices configured to auto-join known networks. On a commercial flight, where passengers are a captive audience and many will connect to whatever open or familiar-looking network appears, the attack surface is unusually favorable for an attacker. The goal is typically credential interception, session hijacking, or traffic capture through a man-in-the-middle position, not disruption of avionics or aircraft systems.
That last distinction matters and is worth drawing out. Commercial aircraft networks are architecturally segregated. Passenger Wi-Fi runs over satellite backhaul to a ground station and is walled off from the avionics bus. Delta's confirmation that no operating systems were affected is consistent with that design boundary. The threat here was to passenger data, not to flight safety.
But the data risk is real. A passenger who joins a spoofed network could expose login credentials, payment information, or session tokens to the operator of the rogue AP. On a flight full of cybersecurity professionals, many of those passengers would likely recognize the risk. On a typical flight, most would not.
Delta's broader connectivity roadmap adds context. The airline has been expanding free in-flight Wi-Fi across its fleet, with dual-network connectivity retrofits planned to begin in Q4 of 2025 and its entire 717 fleet expected to be complete by early 2026, according to a Delta announcement from April 2025. As in-flight connectivity becomes more pervasive and more passengers connect by default, the attack surface for this type of impersonation grows proportionally. More connected devices in a confined space means more potential victims per rogue AP deployment.
The operational response on this flight, disabling the legitimate network for 30 minutes, is a blunt but reasonable containment measure. It removes the legitimate SSID that the rogue AP was impersonating, reducing the likelihood that additional passengers auto-join the spoofed network. It does not, however, address the rogue AP itself, which would continue broadcasting regardless.
What remains unclear is the identity of the individual, whether any passenger data was actually intercepted, and what charges, if any, federal authorities will pursue. Creating a rogue access point on a commercial aircraft could implicate several federal statutes, particularly given post-9/11 regulatory frameworks around interference with airline operations, even when no avionics systems are touched. The gap between Delta's referral to federal law enforcement and the FAA's reported lack of awareness of the incident suggests the investigative picture is still forming.
For security teams thinking about this scenario, the takeaways are straightforward. Evil-twin attacks in confined, high-density environments like aircraft are not new, but they are underreported and difficult for flight crews to mitigate in real time. Enterprise device policies that enforce certificate-based network authentication rather than SSID-matching would render these attacks ineffective, though consumer devices on in-flight networks rarely have that protection. As airlines push toward universal free Wi-Fi, the incentive structure for this kind of attack only improves.


