A fake WiFi network discovered on a Delta flight has exposed a much bigger problem across the airline industry: connected aircraft are becoming easier targets for a well-known scam called an “evil twin” attack. According to Cyviation CEO Eliran Almog, this kind of attack has been a known risk in aviation for years, and the Delta incident shows just how easily it can play out in the air.

This breakdown sits at the intersection of two beats we cover closely at TechyKnow: broader cybersecurity threats and the technology shaping how connected systems, from aircraft to consumer gadgets, are built and defended. Here’s what actually happened on that flight, how evil twin attacks work, and why cybersecurity experts say aviation is struggling to keep pace with how fast these threats evolve.

Key Takeaways

  • Delta Flight DL591 had an unauthorized WiFi network called “Delta WiFi Fast” appear onboard while flying from Las Vegas to Atlanta.
  • Crew members disabled the aircraft’s passenger WiFi for about 30 minutes as a precaution, and Delta confirmed no aircraft systems were hacked.
  • Cyviation CEO Eliran Almog says the incident is consistent with an “evil twin” attack, a technique that creates a fake network mimicking a legitimate one to steal credentials.
  • Cyviation has demonstrated in lab conditions that a phone alone, without specialized computer equipment, can transmit a signal strong enough to overpower an aircraft’s WiFi.
  • Experts warn that aviation’s certification cycles move far slower than cyber threats evolve, creating a widening gap airlines need to close.

What Happened on Delta Flight DL591?

On August 10, Delta Flight DL591 was traveling from Las Vegas to Atlanta when an unauthorized wireless network named “Delta WiFi Fast” appeared onboard. Delta confirmed the network was not provided, operated, or supplied by the airline itself.

As a precaution, the crew disabled the Boeing 757’s passenger WiFi for roughly 30 minutes. Delta has stated there was no hack of its own systems and that flight safety was never in question. The airline is now investigating the incident alongside federal law enforcement and the Federal Aviation Administration.

Notably, the flight was returning from Las Vegas shortly after the DEF CON cybersecurity conference wrapped up, adding an ironic twist to how the incident came to public attention. According to the original reporting from Aerospace Global News, who created the network and exactly how it operated haven’t been publicly confirmed, but the pattern matches a well-documented attack method.

What Is an “Evil Twin” WiFi Attack?

An evil twin attack works by creating a wireless network designed to look identical to one a passenger already expects to see. The attacker can name the network convincingly and even recreate the login page a real airline WiFi portal would show, complete with matching branding.

Once a passenger connects and enters their information, that data goes straight to the attacker instead of the airline. This is exactly why the technique is so effective: there’s no reliable way for an average passenger to tell a legitimate network apart from a fake one just by looking at the name on their device.

This type of attack isn’t new to aviation either. Similar incidents have previously occurred at Australian airports and on domestic flights, in at least one case leading to a prosecution. Cyviation’s CEO also suspects other incidents may have gone undetected or simply unreported over the years.

Why Aircraft Cabins Make Evil Twin Attacks More Effective

Aircraft create a particular set of conditions that make this attack more likely to succeed:

  • Passengers already expect inflight connectivity to be spotty or drop unexpectedly due to coverage gaps.
  • When a connection drops, people instinctively look for the next available network without much scrutiny.
  • Frustration and urgency, especially when someone is mid-task on a document or email, push people to reconnect quickly rather than carefully.

That combination of expected disruption and urgency is exactly the environment an evil twin attack is designed to exploit.

How Easy Is It to Set Up a Fake Network on a Plane?

Cyviation has been researching how difficult it actually is to create a rogue wireless network in an aircraft-like environment, and the results are more concerning than most passengers would assume. In laboratory testing, the company demonstrated that sophisticated computing equipment isn’t even necessary. A smartphone alone was capable of transmitting a signal powerful enough to overpower an aircraft’s WiFi system.

It’s worth being clear about the limits of that finding. Cyviation’s experiment was conducted in a controlled lab setting, not aboard an actual aircraft, and shouldn’t be treated as direct evidence of what happened on DL591 specifically. Several details of the real incident, including whether any credentials were actually collected, remain unconfirmed.

Could an Attack Move Beyond Passenger WiFi?

This is the more serious question hovering over the whole incident. Delta has been clear that no aircraft systems were compromised, and Cyviation’s CEO has stressed that passengers shouldn’t interpret this event as proof that someone could take control of an aircraft through its WiFi.

That said, Cyviation’s broader research points to a few areas worth watching closely:

  • Electronic Flight Bags (EFBs): These are the tablets pilots use for operational information. Lab testing showed that a malicious wireless network could potentially trick a pilot into connecting, which could open the door to malicious pop-up messages or other interference.
  • Cabin management systems: Cyviation has identified vulnerabilities that could theoretically provide WiFi access to systems controlling cabin functions like lighting and temperature. These systems are generally kept separate from cockpit controls, so compromising one wouldn’t hand an attacker control of the aircraft.
  • Indirect safety risks: Even without touching flight-critical systems, a disruptive event, like cabin displays suddenly showing a ransomware-style message, could create panic or distract pilots during an already demanding phase of flight.

The takeaway isn’t that aircraft are wide open to attack. It’s that airlines need much better visibility into what’s happening across their aircraft’s growing digital footprint before something more serious slips through.

Why Airline Cybersecurity Struggles to Keep Pace

Part of the core problem is a mismatch in how fast each side of this equation moves. Aircraft and avionics systems are developed and certified over years, sometimes over a decade or more, because failures can have catastrophic consequences. Cyber threats, on the other hand, can shift dramatically in a matter of months.

Aircraft flying today were often designed well before today’s threat landscape existed, long before anyone anticipated what modern hacking tools, or AI-assisted techniques, would be capable of. Replacing legacy systems isn’t a simple software patch either. A system like the Instrument Landing System can’t just receive a quick update, since changes ripple out across global ground infrastructure and thousands of certified aircraft at once.

This same tension, where fast-moving digital threats collide with slower-moving legacy infrastructure, shows up across other critical industries too. Industrial control systems face a similar challenge, which is worth understanding if you want a broader picture of how outdated infrastructure becomes a target, as covered in our breakdown of Siemens S7 PLC cyberattacks.

What Airlines Can Do to Reduce the Risk

According to Cyviation’s CEO, part of the solution starts with crew training and earlier detection. His recommendations include:

  1. Give crews clear protocols, rather than leaving decisions purely to individual judgment when a suspicious network appears.
  2. Detect suspicious networks earlier, potentially flagging problematic device names or networks at the gate or even at check-in.
  3. Improve visibility into the aircraft’s digital environment as a whole, not just the passenger WiFi system in isolation.

The Delta crew’s response, disabling the WiFi system entirely once the rogue network was spotted, was praised as the right call. But the broader point is that not every crew may recognize the warning signs as quickly, which is why formal procedures matter more as connected aircraft become the norm rather than the exception.

Should Passengers Be Worried About Inflight WiFi?

Despite everything above, the message from cybersecurity experts isn’t to avoid inflight WiFi altogether. Evil twin attacks aren’t unique to aircraft. The same risk exists in hotels, coffee shops, and airports, anywhere a passenger might connect to a network they can’t fully verify.

A few practical habits reduce the risk significantly:

  • Double-check the exact WiFi network name before connecting, rather than picking the first familiar-looking option.
  • Be cautious of unexpected login pages, especially ones asking for payment details or account credentials.
  • Avoid entering sensitive information if anything about the page looks slightly off.

This kind of vigilance matters everywhere connected devices are involved, not just onboard a plane. Even everyday gadgets carry similar exposure, which is worth keeping in mind if you’re weighing accuracy and data handling on something like our Pixel Watch 5 review, since any connected device that talks to WiFi or Bluetooth networks carries some version of the same risk.

The likelihood of an ordinary attacker progressing from a fake WiFi network to actually interfering with aircraft operations remains extremely low, and experts note that level of capability would typically require resources closer to a state actor than an individual scammer. For most people, the real risk mirrors what it would be anywhere else: stolen credentials, not a hijacked flight.

Frequently Asked Questions

What happened with Delta’s fake WiFi incident?

An unauthorized wireless network called “Delta WiFi Fast” appeared on Delta Flight DL591 traveling from Las Vegas to Atlanta on August 10. The crew disabled the aircraft’s passenger WiFi for about 30 minutes as a precaution while Delta investigated alongside federal authorities.

What is an evil twin WiFi attack?

An evil twin attack creates a fake wireless network designed to look identical to a legitimate one, often including a matching login page, in order to trick users into entering personal information or credentials that go directly to the attacker.

Was the Delta aircraft actually hacked?

No. Delta confirmed that no aircraft operating systems were compromised and that the safety of the flight was never in question. The concern was limited to the passenger WiFi network.

Can a fake WiFi network really take over an aircraft?

No. Cybersecurity experts have stressed that the ability of an ordinary attacker to progress from a fake WiFi network to controlling an aircraft is extremely limited and would likely require far more advanced capabilities than a typical scammer has access to.

Why are aircraft vulnerable to evil twin attacks?

Passengers already expect inflight connectivity to be inconsistent, so when a connection drops, they’re more likely to reconnect to any plausible-looking network without carefully checking its authenticity.

How can passengers protect themselves on inflight WiFi?

Verify the exact network name before connecting, be cautious of unexpected login pages, and avoid entering sensitive information like passwords or payment details if anything looks unusual.

Is this the first evil twin attack in aviation?

No. Similar attacks have previously been reported at Australian airports and on domestic flights, with at least one case resulting in prosecution.

Why is airline cybersecurity struggling to keep up with threats?

Aircraft and avionics systems take years to design and certify, while cyber threats can evolve within months. That mismatch means aircraft flying today were often designed before current cyber threats even existed.