Delta Airlines flight Wi-Fi tampered with after DEF CON conference
A rogue network named 'Delta WiFi Fast' was created in an apparent in-flight phishing attack
The day after DEF CON 34 wound up in Las Vegas this week, a passenger on a Delta flight out of the city apparently jammed the in-flight Wi-Fi.
According to reports, on the on the Vegas-to-Atlanta flight on Monday, the scammer broadcast a rogue network named 'Delta WiFi Fast', designed to look like the airline’s service, in an apparent phishing attempt.
The incident was spotted by the crew, with one Instagram user posting Aircraft Communications Addressing and Reporting System (ACARS) messages from the plane's crew to ground staff.
“HEY ALERT CORP SECURITY WE HAVE A PAX [passenger] ON THAT HAS CREATED A SCAM WIFI CALLED DELTA WIFI FAST WE BELIEVE THEY ARE TRYING TO SCAM THE OTH PAX,” one message reads, with another highlighting the presence of “A BUNCH OF PAX THAT WERE AT A CYBER CONFERENCE IN LAS”.
According to one person who claims to have been present when the plane landed, the fake hotspot served up a phishing landing page designed to harvest passengers' personal credentials and Google login data.
"Upon docking at Gate A18, federal authorities and airport police immediately boarded the aircraft to hold the cabin, question the suspects, and seize the broadcasting hardware,” they said.
The attacker is believed to have used a portable wireless device that can broadcast fake networks and carry out deauthorization attacks – the Pineapple Wi-Fi module has been mentioned, but not confirmed.
Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.
This can be used to send fake management frames that tell devices to drop off a legitimate wireless network – making them then susceptible to joining the fake one.
"That creates an opening for credential theft or phishing. None of that means the aircraft itself was in danger. The risk is much more personal and quieter. Travelers may expose passwords or sensitive account information without realizing anything is wrong," said Ross Filipek, CISO at Corsica Technologies.
"Incidents like this are a reminder that convenience can create trust very quickly. Public Wi-Fi depends on users recognizing the right network. Attackers can take advantage when that trust gets misplaced.”
While the true motive of the attacker remains unclear, Wi-Fi blocking can be a federal crime which carries a potential jail sentence.
A spokesperson for Delta Airlines told ITPro it is working closely with law enforcement to ensure the incident is "thoroughly investigated".
“Safety of flight was never in question and no aircraft operating systems were affected. We are fully investigating to gather a complete set of facts, which will take time," the spokesperson said.
"We thank our crew for their professionalism and our customers for their understanding.”
FOLLOW US ON SOCIAL MEDIA
Follow ITPro on Google News and add us as a preferred source to keep tabs on all our latest news, analysis, views, and reviews.
You can also follow ITPro on LinkedIn, X, Facebook, and BlueSky.
Emma Woollacott is a freelance journalist writing for publications including the BBC, Private Eye, Forbes, Raconteur and specialist technology titles.
-
Analysts project bullish SASE industry growthNews SD-WAN and SSE investment growth is expected to drive broader SASE revenues
-
Data center markets are booming in these EMEA countriesNews Research from Savills shows Finland and Saudi Arabia are supercharging capacity, and smaller European cities are getting in on the act
-
NCSC issues alert over 'zero-click' phishing campaign hitting enterprisesNews Ukrainian organizations were used to test new zero-click techniques employed by Russian hackers
-
Multi-channel phishing attacks: How to manage the riskIn-depth Attackers are evolving beyond email towards phishing across multiple channels. Why is this, and what can be done to manage the risk?
-
Hackers are posing as Interpol to target small businesses – here's what you need to knowNews Small businesses are warned to think twice before clicking on links
-
‘Hacking groups have the transport network firmly in their sights’: Network Rail is battling a torrent of cyber threatsNews FoI requests have revealed that the rail operator is under increasing attack, as cyber criminals set their sights on the transport sector
-
‘They risk damaging confidence’: A Canadian health board outraged staff with phishing tests offering paid leave – experts say it shows why you need to be careful with cyber awareness campaignsNews Phishing tests require a delicate touch, emulating realism while not “exploiting goodwill”
-
Hackers are capitalizing on AI hype to ramp up social engineering attacks – and they're using big brands like Anthropic, OpenAI, and DeepSeek as ‘bait’ to lure victimsNews Microsoft says cyber criminals are impersonating popular AI platforms to deliver malware
-
Beware of emails threatening a code of conduct reviewNews A widespread phishing campaign has targeted tens of thousands of employees
-
‘The inbox is no longer the only frontline’: Phishing attacks are evolving as cyber criminals ramp up ‘multi-channel’ campaigns over email and Microsoft TeamsNews New research shows threat actors are ramping up “multi-channel” phishing attacks by combining lures via email and Microsoft Teams