Hackers Hijacked the Wi-Fi on a Delta Flight

By  
Gigabit Systems
August 13, 2026
20 min read
Share this post

Hackers Hijacked the Wi-Fi on a Delta Flight

The plane was real. The Wi-Fi network wasn’t.

A bizarre cybersecurity incident reportedly unfolded aboard Delta Flight 591 from Las Vegas to Atlanta after passengers returning from DEF CON 34, one of the world’s largest cybersecurity conferences, created a rogue Wi-Fi network while the aircraft was in flight.

According to reports, passengers aboard the flight suddenly lost access to Delta’s normal in-flight Wi-Fi.

Then another network appeared:

“DELTA WIFI FAST.”

It wasn’t Delta.

The situation became serious enough that the pilots contacted Delta’s operations center through ACARS, the aircraft’s text-based communications system, and asked that corporate security be alerted.

One cockpit message reportedly warned that passengers returning from a cybersecurity conference had been able to interfere with the Wi-Fi and broadcast their own signal.

A second was even more explicit:

“WE HAVE A PAX ON THAT HAS CREATED A SCAM WIFI CALLED DELTA WIFI FAST.”

The crew ultimately shut down passenger Wi-Fi for approximately 30 minutes while the situation was investigated.

When Flight 591 landed in Atlanta, law enforcement reportedly boarded the aircraft and questioned several passengers.

Welcome home from DEF CON.

What May Have Happened at 35,000 Feet

The reported attack resembles what’s known as an evil twin attack.

Instead of breaking into the legitimate network, an attacker creates another wireless network designed to look like it.

Imagine opening your phone’s Wi-Fi menu aboard a Delta aircraft and seeing:

DeltaWiFi

and

DELTA WIFI FAST

Which one do you choose?

To an exhausted traveler trying to get online, the second one might even sound better.

Connect to the attacker’s network and you can potentially be redirected to a fake captive portal designed to resemble the legitimate airline internet page.

From there, the attacker could attempt to collect information users voluntarily enter—such as email addresses, passwords or other credentials.

That’s why evil-twin attacks are so effective.

The attacker doesn’t necessarily hack your device. They convince you to connect to theirs.

Reports Suggest Something Even More Aggressive

Some accounts of the incident allege the passengers didn’t simply broadcast a competing hotspot.

They may have used portable wireless security-testing equipment—devices in the same general category as tools used by legitimate penetration testers—to interfere with connections to the legitimate network.

One technique capable of disrupting Wi-Fi clients is commonly called a deauthentication attack.

Conceptually, the attack repeatedly tells connected devices:

“You’ve been disconnected.”

The victim’s phone or laptop begins searching for Wi-Fi again.

And conveniently, another convincing network is waiting nearby.

DELTA WIFI FAST.

That combination would make an evil-twin attack substantially more effective: disrupt the legitimate connection, then offer the victim an attractive replacement.

However, the currently available reporting does not conclusively establish the specific equipment or exact wireless technique used, so those details should be treated as allegations rather than confirmed forensic findings.

The Airplane Was Never Hacked

This distinction is extremely important.

Despite how frightening “hackers jam Wi-Fi aboard an airplane” sounds, Delta says:

No aircraft operating systems were affected.

Delta also says there wasn’t an actual compromise of its in-flight Wi-Fi system itself.

The aircraft remained safe.

The alleged attack concerned the passenger internet environment, not flight controls, navigation or avionics.

That’s reassuring.

But from a cybersecurity perspective, the passenger threat remains very real.

You Don’t Need to Hack Delta

This incident demonstrates something cybersecurity professionals have understood for years.

Sometimes attacking the trusted organization is unnecessarily difficult.

It’s easier to attack the customer’s trust in the organization.

Don’t hack Delta.

Create something that looks like Delta.

Don’t hack Microsoft.

Create a Microsoft login page.

Don’t hack the hotel.

Create the hotel’s Wi-Fi portal.

Don’t hack Google.

Send someone to a page that looks like Google.

The victim completes the attack for you.

Your VPN Doesn’t Solve This

This is where travelers frequently misunderstand VPNs.

A VPN can provide valuable protection when you’re using an untrusted network.

But a VPN cannot protect you from voluntarily entering your password into a phishing page.

If “DELTA WIFI FAST” presents you with a fake login page and you willingly enter your credentials, the encrypted tunnel isn’t the problem.

You handed the attacker the password.

HTTPS doesn’t automatically save you either.

A phishing website can have a valid HTTPS certificate.

The padlock means your connection to that website is encrypted.

It does not mean the website belongs to Delta, Google, Microsoft or your employer.

How to Protect Yourself From Evil-Twin Wi-Fi

Before connecting to Wi-Fi on an airplane, hotel, airport or conference center, verify the official network name.

If you’re unsure aboard an aircraft, ask a flight attendant.

If you’re at a hotel, check the instructions provided by the hotel rather than simply selecting the strongest network.

Be particularly suspicious if public Wi-Fi asks you to:

  • Install software

  • Download a certificate

  • Install a browser update

  • Enter corporate Microsoft 365 credentials

  • Enter Google credentials unexpectedly

  • Disable security software

  • Download a “network repair” utility

Whenever practical, use cellular data or your personal hotspot instead.

And enable strong MFA—preferably phishing-resistant passkeys—on important accounts.

Businesses Should Be Paying Attention

Now imagine the person connecting isn’t simply watching Netflix.

It’s your CFO.

Your attorney.

Your physician.

Your school administrator.

Your employee traveling with a laptop containing access to:

Microsoft 365.

SharePoint.

OneDrive.

QuickBooks.

Customer records.

Patient information.

Legal documents.

Corporate VPNs.

Suddenly an airplane Wi-Fi prank becomes a serious SMB cybersecurity incident.

Businesses should train employees to treat public Wi-Fi as hostile infrastructure.

Managed IT environments should also use MFA, EDR/XDR, conditional-access policies, DNS protection, least privilege and strong identity monitoring so one stolen credential doesn’t immediately become a company-wide breach.

This Technique Has Already Put Someone in Prison

The uploaded report points to a remarkably similar Australian case from 2024.

Authorities accused a man of using a portable wireless access device aboard a commercial flight to mimic legitimate onboard Wi-Fi.

A flight attendant became suspicious.

Police investigated.

And authorities ultimately uncovered what was described as a much larger criminal operation.

The man was eventually sentenced to seven years in prison.

So while the Delta incident may sound like hackers fooling around after DEF CON, the underlying technique isn’t a harmless party trick.

Evil-twin networks can be credential-stealing infrastructure.

The Most Dangerous Part Is How Normal It Looks

No ransomware screen.

No flashing warning.

No hacker wearing a hoodie.

Your phone simply says:

Wi-Fi available.

You tap it.

A familiar-looking page appears.

You sign in.

And you continue your flight.

That’s why this attack is so effective.

We’re conditioned to trust network names because they’re familiar.

But your phone can’t tell you that the Wi-Fi network called “Delta” actually belongs to Delta.

The same applies to your hotel tomorrow night.

And the airport the next morning.

The name appearing under the Wi-Fi icon is ultimately just a name someone configured.

The airplane might be real.

The hotel might be real.

The airport might be real.

The Wi-Fi might not be.

70% of all cyber attacks target small businesses, I can help protect yours.

#Cybersecurity #WiFiSecurity #Phishing #DataProtection #ManagedIT


Share this post
See some more of our most recent posts...