Technology

Someone Created a Fake Wi-Fi Network on a Plane. What Happened?

Martin HollowayPublished 3d ago4 min readBased on 2 sources
Reading level
Someone Created a Fake Wi-Fi Network on a Plane. What Happened?
source:delta.com

An unidentified passenger allegedly created a fake Wi-Fi network aboard a Delta Air Lines flight from Las Vegas to Atlanta on Monday, prompting pilots to alert air traffic control twice during the flight. TechCrunch

The fake network was set up to look like the plane's real in-flight Wi-Fi, according to the pilots' messages to air traffic control. In response, the flight crew shut down the plane's actual Wi-Fi service for about 30 minutes.

Here's how this kind of trick works. When you connect to Wi-Fi, your phone or laptop often remembers network names and automatically reconnects the next time it sees one with the same name. An attacker can bring their own wireless device — like a portable router — and give it the same name as the real network. Your phone sees the familiar name and connects to the fake one without asking you. Once you're on the attacker's network, they can intercept information passing between your device and the internet — things like passwords, payment details, or the digital keys that keep you logged into websites. Security professionals call this an "evil-twin" attack, and it is a well-known technique.

On a commercial flight, passengers are a captive audience. Many will connect to whatever open or familiar-looking network appears, which makes the setup unusually easy for an attacker.

Delta spokesperson Morgan Durrant confirmed that the safety of the flight was never in question, no aircraft operating systems were affected, and the in-flight network itself was not compromised. The airline said it is fully investigating the incident and will coordinate with federal law enforcement and aviation regulators.

The pilots noted in their messages that some passengers on the flight had attended cybersecurity conferences held in Las Vegas the prior week, which helps explain the technical know-how involved but does not itself identify a suspect. No individual has been publicly identified.

Law enforcement and regulatory response remains uneven. The Atlanta Police Department referred questions about the incident to federal authorities. FAA spokesperson Steve Kulm said the agency had not received a report about the incident. The FBI did not immediately respond to TechCrunch's request for comment.

One point matters and is worth drawing out. The Wi-Fi that passengers use on a plane is completely separate from the systems that fly the aircraft. Passenger internet runs through a satellite link to a ground station, and it is walled off from the plane's flight controls. Delta's confirmation that no operating systems were affected is consistent with that design. The threat here was to passenger data, not to flight safety.

The data risk, though, is real. A passenger who joined the fake network could have exposed login credentials, payment information, or other sensitive data to whoever was running it. On a flight full of cybersecurity professionals, many passengers would likely have noticed the danger. On a typical flight, most would not.

Delta's broader plans add context. The airline has been expanding free in-flight Wi-Fi across its fleet, with dual-network connectivity retrofits planned to begin in Q4 of 2025 and its entire 717 fleet expected to be complete by early 2026, according to a Delta announcement from April 2025. As in-flight Wi-Fi becomes more common and more passengers connect by default, the opportunity for this kind of trick grows. More connected devices in a small space means more potential victims.

The response on this flight — shutting down the real Wi-Fi for 30 minutes — is a blunt but reasonable way to limit the damage. It removes the real network name that the fake one was copying, making it less likely that more passengers connect to the fake one. It does not stop the fake network itself, which would keep broadcasting regardless.

What remains unclear is the identity of the individual, whether any passenger data was actually intercepted, and what charges, if any, federal authorities will pursue. Creating a fake network on a commercial aircraft could violate several federal laws, particularly given regulations around interference with airline operations put in place after 9/11, even when no flight systems are affected. The gap between Delta's referral to federal law enforcement and the FAA's reported lack of awareness of the incident suggests the investigation is still getting organized.

The broader context here is that this type of attack is not new, but it is underreported and difficult for flight crews to stop in the moment. Large organizations can protect their devices using stronger security checks that verify a network's identity through encryption rather than just its name, but personal phones and laptops on in-flight networks rarely have that kind of protection. As airlines push toward universal free Wi-Fi, the appeal of this kind of attack only grows.