Passengers on a Delta flight from Las Vegas to Atlanta experienced a disruption when an unauthorized Wi-Fi network prompted the crew to temporarily disable onboard Wi-Fi.
Delta is now investigating the incident, which occurred on Flight 591 carrying passengers returning from the DEF CON 34 cybersecurity conference.
“Incidents like this are a reminder that convenience can create trust very quickly. Public Wi-Fi depends on users recognizing the right network,” said Ross Filipek, CISO at Corsica Technologies, in an email to eSecurityPlanet.
He added, “Attackers can take advantage when that trust gets misplaced.”
Key takeaways of the Delta Airlines Wi-Fi hacking incident
- Delta is investigating an unauthorized Wi-Fi network detected aboard Flight 591 from Las Vegas to Atlanta carrying DEF CON attendees.
- A suspected Wi-Fi deauthentication attack disrupted connectivity, prompting the crew to disable onboard Wi-Fi for approximately 30 minutes.
- A rogue network named “Delta WiFi Fast” was reportedly broadcast, creating the potential for an evil twin attack and credential theft.
- Organizations can reduce rogue Wi-Fi risk through stronger wireless security, managed device configurations, phishing-resistant MFA, monitoring, employee training, and tested incident response plans.
Delta investigates rogue Wi-Fi attack
Delta confirmed that an unauthorized wireless network appeared aboard the Boeing 757 but said the incident did not affect passenger safety or aircraft operating systems.
No emergency was declared with air traffic control.
After the unauthorized network was detected, the cabin crew disabled the aircraft’s Wi-Fi service for approximately 30 minutes, according to BleepingComputer.
Delta said it is investigating the incident and plans to work with federal law enforcement and aviation regulators to determine what occurred.
Reports point to a Wi-Fi deauthentication attack
Online reports alleged that passengers returning from the DEF CON cybersecurity conference conducted a Wi-Fi deauthentication attack that disrupted connections to the aircraft’s legitimate wireless network.
During the incident, a separate network named “Delta WiFi Fast” was also reportedly broadcast, potentially giving passengers the impression that it was an official Delta service.
How Wi-Fi deauthentication attacks work
Wi-Fi deauthentication attacks work by abusing management frames that wireless networks use to control connections between devices and access points.
An attacker can send forged deauthentication frames that appear to come from a legitimate access point, instructing connected devices to disconnect.
When these frames are transmitted repeatedly, users may be unable to maintain a connection to the legitimate network, effectively creating a wireless denial-of-service condition.
Rogue Wi-Fi can enable evil twin attacks
The disruption can also create an opportunity for an evil twin attack.
After users are disconnected from a legitimate network, an attacker can broadcast a rogue access point with a convincing or familiar name.
Users attempting to reconnect may mistakenly select the fraudulent network, allowing the attacker to present fake login pages, redirect traffic, or attempt to capture sensitive information.
In the Delta incident, third-party reports alleged that the unauthorized network displayed a phishing page designed to collect personal information and Google login credentials.
However, Delta has only confirmed the presence of an unauthorized wireless network and has not publicly confirmed the credential theft allegations or attributed the activity to specific individuals.
For security teams, the incident illustrates how attackers can combine wireless disruption with social engineering to exploit users’ trust in familiar network names.
A recognizable SSID alone does not establish that a network is legitimate, especially in public environments such as airports, hotels, conferences, and transportation hubs.
The investigation into this incident is ongoing at the time of publication.
How to reduce rogue Wi-Fi risks
This incident is a reminder that organizations should account for rogue wireless networks in both their security architecture and employee security training.
- Enable Protected Management Frames (PMF), WPA3-Enterprise, and certificate-based authentication to reduce spoofing and deauthentication risks.
- Use mobile device management (MDM) to deploy trusted network profiles, disable unnecessary wireless features, and prevent automatic connections to unknown networks.
- Use wireless intrusion detection and prevention tools to identify unauthorized access points and networks impersonating legitimate infrastructure.
- Require approved VPNs or managed cellular connections when employees access sensitive resources from public or untrusted networks.
- Use phishing-resistant MFA and monitor authentication systems for suspicious logins, new devices, and abnormal session activity.
- Teach users to recognize evil twin networks, suspicious captive portals, unexpected login requests, and other signs of wireless phishing.
- Test incident response plans and use attack simulation tools, with scenarios around rogue Wi-Fi and credential theft.
Collectively, these steps can help organizations reduce overall risk.
Bottom line
Rogue Wi-Fi scenarios can expose gaps across endpoint policy, identity controls, telemetry, and incident response that may not surface during conventional phishing exercises.
The Delta incident highlights the importance of validating how well existing controls can detect and respond to credential theft originating from rogue or compromised wireless connections.
Adopting zero trust principles can help organizations reduce overall exposure by requiring continuous verification of users, devices, and access requests regardless of the network they use.





