Delta is investigating an alleged passenger created, rogue Wi-Fi network aboard Flight 591 from Las Vegas to Atlanta on August 10, one day after the DEF CON cybersecurity conference concluded in Las Vegas.
The unauthorized network, named “Delta WiFi Fast,” impersonated the airline’s legitimate Wi-Fi and was reportedly intended to scam other passengers. The crew disabled the aircraft’s Wi-Fi for approximately 30 minutes after discovering the network.
Delta said no aircraft operating systems were affected and flight safety was never in question.
“Our conference this year also suffered from multiple similar ‘deauthorization’ Wi-Fi attacks and it impacted some of our operations,” Monika Hathaway, head of press for DEF CON said.
Seemant Sehgal, Founder & CEO, BreachLock:
“Flying out of Vegas after Black Hat myself just a few days before this incident, I can tell you the security conference crowd that passes through that airport is unlike any other, and the crew on Flight 591 made the right call with the information they had in front of them.
“Rogue access points impersonating a legitimate network are one of the oldest tricks in the book, and doing it on an aircraft to scam passengers is a federal crime regardless of the sophistication involved. The people most likely to pull something like this on a DEF CON departure flight are the ones who know exactly where that line is, which makes crossing it a choice rather than a mistake. Disabling the Wi-Fi and investigating was exactly the right instinct.”
Denis Calderone, CTO, Suzu Labs:
“Hackers will hack. I go to DEF CON most years, and it’s pretty common to have a terrible wifi experience on those flights because everyone is playing with their WiFi Pineapples and whatnot. That said, my flight home this year had no rogue SSIDs that I could see, and although, as usual, the wifi was shoddy, I never took the time to analyze the radio signals in the cabin, but if a few deauths were flying around, I wouldn’t have been too surprised. It is concerning to hear about attempted credential harvesting on the flight though, and I feel that that’s taking the expected hijinks way too far.
“The deauthentication and evil twin combination used on Flight 591 is a well-documented attack that the security community has been demonstrating for a good two decades. These sorts of wifi threats are very common. DEF CON still displays their famed Wall of Sheep which displays the sniffing clear text credentials on the conference network, and every year the WiFi Pineapples have been selling out at the Hak5 booth. But there’s a significant difference between demonstrating a technique at a conference and deploying it against 199 unsuspecting passengers on a commercial aircraft. Last November, an Australian man was sentenced to seven years and four months in prison for running the exact same attack on domestic flights using a WiFi Pineapple and now the FBI is already involved in this case. There is definitely a legal exposure here.
“For anyone who travels for work, in-flight WiFi should be treated as an untrusted network, period. The enterprise advice is encrypted DNS through your MDM and always-on VPN with captive portal remediation configured. But honestly, a VPN is something every traveler should be using, not just corporate road warriors. I make sure mine is on whenever I travel, and my family does the same. Beyond that, if a WiFi network on a plane doesn’t match what the crew announced or what’s printed on the seat card, don’t connect to it. If a network asks you to log in with your Google account or email credentials to get WiFi access, that’s not how airline WiFi works. Airline captive portals ask for a credit card or a loyalty account, not your personal email password. If you’re being asked for something that doesn’t make sense for the context, you’re probably not on the real network.”
Jacob Warner, Director of IT, Xcape, Inc.:
“While a rogue Wi-Fi access point on a commercial airliner poses zero direct risk to air-gapped flight safety controls, it creates a serious enterprise security hazard for business travelers relying on inflight networks. Dismissing an onboard network impersonation as a harmless prank ignores the reality of man-in-the-middle attacks, credential harvesting, and fake authentication portals targeting captive passengers connecting to the Internet. Given that the flight departed Las Vegas immediately following DEF CON, it requires little imagination to conclude an attendee deployed the unauthorized access point.
“This juvenile behavior is precisely why hackers suffer such a poor reputation among non-technical audiences and why security professionals struggle to build mainstream trust. Enterprise security teams must mandate always-on virtual private networks or zero-trust network access, disable automatic connections to open SSIDs on corporate endpoints, and instruct travelers to treat cabin wireless environments as untrusted networks.
“Critical Takeaways
- “Reputational damage: Pulling wireless hijinks on commercial flights damages industry credibility with non-technical audiences and disrupts legitimate travel.
- “Transit vulnerability: Unencrypted inflight Wi-Fi exposes business travelers to man-in-the-middle credential harvesting and session hijacking.
- “Endpoint hardening: Security leaders must enforce always-on virtual private networks and disable automatic SSID connections on all corporate devices.
“Setting up an evil twin at 30,000 feet does not make you a clever researcher; it just proves why we cannot have nice things.”
John Strand, Owner, Black Hills Information Security, Inc.:
“This one hits differently because this is my community. These are my people. When security professionals engage in this kind of behavior, they’re betraying the very community they’re claim to represent.
“There’s nothing impressive about it. It doesn’t make you look clever, and it certainly doesn’t make you an elite hacker. In most cases, these attacks aren’t even technically sophisticated. They’re simply people with enough technical knowledge taking advantage of others who don’t have the experience to recognize what’s happening. That isn’t skill. It’s bullying.
“I hope the people responsible are held accountable. This isn’t funny, it isn’t clever, and it doesn’t demonstrate technical excellence. It’s just people abusing their knowledge to prey on those who are at a disadvantage. That’s not what this profession should stand for.”
This is basically dumb. I hope that the people are found and punished accordingly. But at the same time Delta and other airlines need to make sure that this sort of exploit isn’t possible. Use an VPN every time to protect yourself from this exploit as the next time it might be someone bad behind it.
$300M Senate bill to target cyber threats to U.S. water systems
Posted in Commentary with tags US on August 12, 2026 by itnerdSenators Adam Schiff and Amy Klobuchar introduced the Water Cyber Shield Act, which would give the EPA explicit authority to conduct cybersecurity assessments, require corrective actions and establish security standards for water systems alongside CISA and NIST.
The bill would also authorize $300 million annually for water infrastructure upgrades, require risk assessments for large systems and expand mandatory cyber incident reporting.
The legislation follows coordinated cyberattacks against dozens of community water systems across at least 12 states. Separately, DEF CON Franklin and the National Rural Water Association launched the Water Watch Center to provide cybersecurity services to utilities serving fewer than 10,000 people, a group representing 91% of the roughly 50,000 community water systems nationwide. Five cybersecurity firms will provide managed detection and response services, building on a two-year pilot involving nearly 450 volunteer cybersecurity experts across seven states.
Damon Small, Board of Directors, Xcape, Inc.:
“The Water Cyber Shield Act attempts to address a major regulatory gap by granting the Environmental Protection Agency explicit authority to enforce baseline security standards and allocate $300 million annually for utility upgrades, but federal dollars alone cannot fix this sector’s systemic fragility. Spread across roughly 50,000 community water systems nationwide, that funding yields a negligible $6,000 per facility, an amount that barely covers an initial architecture audit, let alone operational technology overhauls.
“The industry already possesses robust reference architectures and standards for protecting control systems, so the primary barrier is execution rather than a lack of guidance. Furthermore, claiming that capital injections will solve the threat ignores the reality that maintenance windows are rare in continuous operational technology environments. Rather than waiting on Congressional appropriations, security leaders and asset owners must immediately execute foundational controls: strictly isolate industrial control networks from corporate IT, eliminate publicly exposed management interfaces to the Internet, enforce multi-factor authentication, and replace default device credentials.
“Critical Takeaways
“Operational security standards already exist; what utilities lack is not awareness, but the uptime flexibility to actually apply patches.”
Dahvid Schloss, OSCP, Chief Operating Officer, Suzu Labs:
“While it’s always exciting to see Congress attempt to get some good cybersecurity hygiene laws in place, it’s likely a far reach from what will actually happen. The Water Cyber Shield Act feels a lot like a round two attempt from when this was attempted back in 2023 under the existing Safe Drinking Water Act authority as a rule, but that got shut down when water industry groups and a coalition of GOP states argued that it would increase costs on ratepayers, and then the EPA folded and pulled the rule. (More info can be found here https://www.epa.gov/cyberwater/cybersecurity-sanitary-surveys)
“I hate to say it, but historically speaking, this is likely to fail before making it to a vote, just like all other bills that have been attempted to improve water cybersecurity in the past. If we look at just the 118th and 119th Congress, we have had 9 bills introduced, as far as I’m aware, that pushed language that would have focused on either providing monetary assistance for, directly enforcing industry standards, and/or regulation around cybersecurity for water systems and CI, each varying in degree of what they would have provided and who they would have protected (rural vs non), but of those 9, all from within the 118th congress died within committees and without comments or markup, meaning no one even bothered to fight for them to get a vote across. Technically, the 4 from this congress (119) are still “pending’ but considering no movement has occurred on them, they will likely reach the same fate.
“Ultimately, Congress has been unreliable in pushing forward regulation and standards towards CI for quite some time, and the mantle thankfully has been picked up by private organizations and security practitioners who wish to have a safer and more secure water source. Even though it shouldn’t be dependent on the goodwill of private citizens to protect public infrastructure. Hopefully, in light of recent attacks, this will push Senators and House Representatives to actually move the needle forward, but this isn’t the first time we have had this situation happen before. So, my fingers are crossed, but I’m not holding my breath.”
John Strand, Owner, Black Hills Information Security, Inc.:
“I think this type of legislation is important, but it’s also long overdue. People have known about the security weaknesses in critical infrastructure, especially within municipalities, for well over a decade. Unfortunately, this is another example of a reactive approach to cybersecurity. Too often, meaningful action doesn’t happen until the damage has already been done.
“My concern is that by the time these programs are fully implemented and organizations begin benefiting from them, many of the municipalities with the same vulnerabilities that enabled recent attacks will have already been compromised. It’s a positive step, but it’s arriving years after the underlying risks were widely understood. This is the kind of investment that should have been made more than a decade ago, not after the attacks have already demonstrated the consequences of inaction.”
While addressing critical infrastructure is long overdue, the time to act is now as the threat is real and present. Will lawmakers act on that threat is the real question.
Leave a comment »