Delta is investigating an alleged passenger created, rogue Wi-Fi network aboard Flight 591 from Las Vegas to Atlanta on August 10, one day after the DEF CON cybersecurity conference concluded in Las Vegas.
The unauthorized network, named “Delta WiFi Fast,” impersonated the airline’s legitimate Wi-Fi and was reportedly intended to scam other passengers. The crew disabled the aircraft’s Wi-Fi for approximately 30 minutes after discovering the network.
Delta said no aircraft operating systems were affected and flight safety was never in question.
“Our conference this year also suffered from multiple similar ‘deauthorization’ Wi-Fi attacks and it impacted some of our operations,” Monika Hathaway, head of press for DEF CON said.
Seemant Sehgal, Founder & CEO, BreachLock:
“Flying out of Vegas after Black Hat myself just a few days before this incident, I can tell you the security conference crowd that passes through that airport is unlike any other, and the crew on Flight 591 made the right call with the information they had in front of them.
“Rogue access points impersonating a legitimate network are one of the oldest tricks in the book, and doing it on an aircraft to scam passengers is a federal crime regardless of the sophistication involved. The people most likely to pull something like this on a DEF CON departure flight are the ones who know exactly where that line is, which makes crossing it a choice rather than a mistake. Disabling the Wi-Fi and investigating was exactly the right instinct.”
Denis Calderone, CTO, Suzu Labs:
“Hackers will hack. I go to DEF CON most years, and it’s pretty common to have a terrible wifi experience on those flights because everyone is playing with their WiFi Pineapples and whatnot. That said, my flight home this year had no rogue SSIDs that I could see, and although, as usual, the wifi was shoddy, I never took the time to analyze the radio signals in the cabin, but if a few deauths were flying around, I wouldn’t have been too surprised. It is concerning to hear about attempted credential harvesting on the flight though, and I feel that that’s taking the expected hijinks way too far.
“The deauthentication and evil twin combination used on Flight 591 is a well-documented attack that the security community has been demonstrating for a good two decades. These sorts of wifi threats are very common. DEF CON still displays their famed Wall of Sheep which displays the sniffing clear text credentials on the conference network, and every year the WiFi Pineapples have been selling out at the Hak5 booth. But there’s a significant difference between demonstrating a technique at a conference and deploying it against 199 unsuspecting passengers on a commercial aircraft. Last November, an Australian man was sentenced to seven years and four months in prison for running the exact same attack on domestic flights using a WiFi Pineapple and now the FBI is already involved in this case. There is definitely a legal exposure here.
“For anyone who travels for work, in-flight WiFi should be treated as an untrusted network, period. The enterprise advice is encrypted DNS through your MDM and always-on VPN with captive portal remediation configured. But honestly, a VPN is something every traveler should be using, not just corporate road warriors. I make sure mine is on whenever I travel, and my family does the same. Beyond that, if a WiFi network on a plane doesn’t match what the crew announced or what’s printed on the seat card, don’t connect to it. If a network asks you to log in with your Google account or email credentials to get WiFi access, that’s not how airline WiFi works. Airline captive portals ask for a credit card or a loyalty account, not your personal email password. If you’re being asked for something that doesn’t make sense for the context, you’re probably not on the real network.”
Jacob Warner, Director of IT, Xcape, Inc.:
“While a rogue Wi-Fi access point on a commercial airliner poses zero direct risk to air-gapped flight safety controls, it creates a serious enterprise security hazard for business travelers relying on inflight networks. Dismissing an onboard network impersonation as a harmless prank ignores the reality of man-in-the-middle attacks, credential harvesting, and fake authentication portals targeting captive passengers connecting to the Internet. Given that the flight departed Las Vegas immediately following DEF CON, it requires little imagination to conclude an attendee deployed the unauthorized access point.
“This juvenile behavior is precisely why hackers suffer such a poor reputation among non-technical audiences and why security professionals struggle to build mainstream trust. Enterprise security teams must mandate always-on virtual private networks or zero-trust network access, disable automatic connections to open SSIDs on corporate endpoints, and instruct travelers to treat cabin wireless environments as untrusted networks.
“Critical Takeaways
- “Reputational damage: Pulling wireless hijinks on commercial flights damages industry credibility with non-technical audiences and disrupts legitimate travel.
- “Transit vulnerability: Unencrypted inflight Wi-Fi exposes business travelers to man-in-the-middle credential harvesting and session hijacking.
- “Endpoint hardening: Security leaders must enforce always-on virtual private networks and disable automatic SSID connections on all corporate devices.
“Setting up an evil twin at 30,000 feet does not make you a clever researcher; it just proves why we cannot have nice things.”
John Strand, Owner, Black Hills Information Security, Inc.:
“This one hits differently because this is my community. These are my people. When security professionals engage in this kind of behavior, they’re betraying the very community they’re claim to represent.
“There’s nothing impressive about it. It doesn’t make you look clever, and it certainly doesn’t make you an elite hacker. In most cases, these attacks aren’t even technically sophisticated. They’re simply people with enough technical knowledge taking advantage of others who don’t have the experience to recognize what’s happening. That isn’t skill. It’s bullying.
“I hope the people responsible are held accountable. This isn’t funny, it isn’t clever, and it doesn’t demonstrate technical excellence. It’s just people abusing their knowledge to prey on those who are at a disadvantage. That’s not what this profession should stand for.”
This is basically dumb. I hope that the people are found and punished accordingly. But at the same time Delta and other airlines need to make sure that this sort of exploit isn’t possible. Use an VPN every time to protect yourself from this exploit as the next time it might be someone bad behind it.
SOCRadar Goes Inside the LiteLLM Supply Chain Attack That Exposed 2,500+ Companies
Posted in Commentary with tags SOCRadar on August 13, 2026 by itnerdToday, the SOCRadar research team published a new research report on the LiteLLM supply chain attack that exposed 2,500 companies. It includes full attack chain, TeamPCP profile, IOC table, five detection checks, rotation guidance andFAQ.
What’s different from general coverage:
SOCRadar Findings/Differentiators:
SOCRadar’s report is here: LiteLLM Supply Chain Attack: Inside the AI Breach That Exposed 2,500+ Companies
Leave a comment »