Atlanta/ Crime & Emergencies

Fake Wi-Fi Network Rattles Delta Flight From Vegas to Atlanta After DEF CON

AI Assisted Icon
Published on August 11, 2026
Fake Wi-Fi Network Rattles Delta Flight From Vegas to Atlanta After DEF CONSource: Wikipedia/N509FZ, CC BY-SA 4.0, via Wikimedia Commons

A fake Wi-Fi network briefly popped up aboard a Delta Air Lines flight from Las Vegas to Atlanta on Monday, prompting cabin crew to shut down the plane's internet for about 30 minutes and drawing scrutiny from federal authorities. The flight landed safely at Hartsfield-Jackson Atlanta International Airport, and Delta says the aircraft itself was never at risk.

Delta Flight 591 was carrying passengers returning from DEF CON 34, the massive hacking convention that wrapped up in Las Vegas over the weekend, when the unauthorized network appeared, according to CBS Atlanta. An airline spokesperson told the outlet the network was not a hack of any system on the plane, and that flight safety was never in question because no aircraft operating systems were affected. Cabin crew deactivated the Boeing 757's Wi-Fi functionality for roughly 30 minutes as a precaution, and the flight did not declare an emergency to air traffic control.

What Investigators Believe Happened Onboard

According to cockpit messages sent by the flight's pilots to Delta operations through the Aircraft Communications Addressing and Reporting System, passengers returning from the cybersecurity conference had jammed the aircraft's Wi-Fi and broadcast an unauthorized network named “Delta WiFi Fast” in an apparent attempt to scam other passengers, per Paddle Your Own Kanoo. Flight 591 had already departed Las Vegas Harry Reid International Airport nearly 18 hours behind schedule before the in-flight incident occurred, according to View from the Wing. The outlet reports the flight landed in Atlanta around 3:05 p.m. Eastern Time, where law enforcement officers met the aircraft at Gate A18 to question passengers.

This kind of attack, commonly called an “evil twin,” involves hackers creating a fake public network access point that usually broadcasts a stronger signal than the legitimate one, luring devices to connect automatically. Once a victim connects, tools exist that let hackers read the victim's data, per CBS Atlanta's reporting. The technique is formally classified by the MITRE ATT&CK framework as an adversary-in-the-middle method in which an unauthorized access point impersonates a legitimate network name to capture credentials or manipulate traffic.

Delta Says It's Working With Federal Authorities

Delta is investigating the incident to gather a complete set of facts and says it will partner with federal law enforcement and aviation regulators as the review continues, the airline told CBS Atlanta. Federal authorities have previously issued warnings about this exact type of incident, the outlet notes. The Federal Bureau of Investigation's Internet Crime Complaint Center has repeatedly cautioned travelers that public wireless networks in travel hubs are prime targets for evil twin attacks designed to intercept traffic and steer victims toward credential-harvesting login pages, according to an FBI IC3 advisory.

It remains unclear whether the rogue network aboard Flight 591 was an intentional phishing attempt aimed at stealing passenger data or a reckless demonstration by attendees fresh off a hacking conference, and whether any passenger information was actually compromised. It is also unknown whether federal authorities will pursue charges. Interfering with the performance of a flight crew member's duties aboard an aircraft is a federal general-intent crime under 49 U.S.C. § 46504, punishable by civil fines and up to 20 years in federal prison, according to the U.S. Department of Justice, though the dossier does not indicate whether that statute applies to this case.

A Familiar Threat With Cheap, Portable Tools

Evil twin attacks don't require sophisticated equipment. Rogue access point attacks are frequently carried out with low-cost portable hardware such as the Wi-Fi Pineapple, a $100-to-$300 wireless penetration-testing router that passively monitors nearby device requests and automatically broadcasts matching network names to trick devices into connecting, according to Memcyco. Those devices were originally built for authorized network auditing.

The threat has already led to serious criminal consequences elsewhere. In December 2025, an Australian court sentenced a 44-year-old man to seven years and four months in prison for deploying evil twin Wi-Fi networks on commercial domestic flights and at major airports to steal passengers' login credentials and private data, per Infosecurity Magazine. Researchers note the attacks remain notoriously hard to catch in real time. An academic analysis published this month found that evil twin attacks are exceptionally difficult to detect because consumer devices automatically join familiar network names, leaving passengers dependent on vigilance or crew intervention to spot rogue signals, according to research published in MDPI.

DEF CON 34 drew more than 30,000 security researchers, ethical hackers and industry professionals to Las Vegas over the weekend, timing that put a large concentration of cybersecurity-savvy travelers on flights home just as the rogue network appeared. Delta offers free Wi-Fi to SkyMiles members across its domestic fleet and announced plans for satellite Wi-Fi upgrades earlier this year, part of the airline's broader push to expand in-flight connectivity even as incidents like this one underscore the security tradeoffs that come with it.