Fake Wi-Fi on Delta flight triggers federal investigation

Delta Flight 591 was targeted by a mid-air Wi-Fi phishing attack that kicked passengers offline and broadcasted a rogue hotspot

Delta confirmed aircraft operating systems were never at risk, but the federal investigation into signal jamming remains ongoing. ©Image Credit: Unsplash / Trac Vu
Delta confirmed aircraft operating systems were never at risk, but the federal investigation into signal jamming remains ongoing. ©Image Credit: Unsplash / Trac Vu

It’s always a wild ride when DEF CON wraps up in Sin City, and this year’s “hacker summer camp” was no exception. What started as a standard flight home turned into an airborne cybersecurity incident when a Delta Air Lines flight from Las Vegas to Atlanta was hit by a mid-air Wi-Fi phishing attack.

The “evil twin” attack

Delta Flight 591, packed with passengers fresh out of the famous cybersecurity convention, was targeted by what experts call a Wi-Fi deauthentication attack. What this means in plain English is that a bad actor (or actors) essentially hijacked the plane’s Wi-Fi signal.

Using a portable hacking tool (think along the lines of a Wi-Fi Pineapple), they managed to forcibly kick devices like laptops and smartphones off the plane’s legitimate Wi-Fi network.

According to passengers onboard the Boeing 757, things quickly took a dark turn once everyone was booted offline. The attacker broadcasted what you can call an “evil twin” network, sneakily naming it “Delta WiFi Fast.” This rogue hotspot reportedly served up a fake landing page designed to phish passengers and steal their personal credentials, including logins and sensitive bank details.

Flight crew alerts and emergency response

The situation prompted the flight crew to take action, deactivating the aircraft’s Wi-Fi functionality for about 30 minutes while still in the air.

Intercepted ACARS (Aircraft Communications Addressing and Reporting System) messages showed the pilots alerting ground operations to the unfolding drama.

“We have a bunch of pax that were at a cyber conference in Las [Vegas],” one pilot wrote to ground control. “They were able to jam our WiFi and broadcast their signal.”

A follow-up message escalated the issue to Delta corporate security, noting that they believed the culprit was trying to scam other passengers with the fake hotspot.

Federal authorities meet the gate

When the plane finally touched down at Atlanta’s Hartsfield-Jackson International Airport, federal authorities and airport police weren’t taking any chances. Eyewitnesses described a wild scene where law enforcement immediately boarded the aircraft, held the cabin, questioned suspects, and seized the broadcasting hardware.

What was compromised

So, were any airline systems actually compromised? Delta Air Lines spokesperson Taylor Dahl confirmed that an unauthorized network was indeed operating onboard for a short time. Dahl, however, noted that the August 10th incident did not pose any risk to the flight’s operating systems.

“Safety of flight was never in question and no aircraft operating systems were affected,” Dahl said in a statement. “We are fully investigating to gather a complete set of facts, which will take time. We will partner with federal law enforcement and aviation regulators to ensure the incident is thoroughly investigated.”

Why the feds stepped in

It’s worth noting that deliberately interfering with authorized radio signals, which includes jamming an aircraft’s Wi-Fi, is a major federal offense. The FCC warns that such violations can lead to hefty fines and seized equipment.

The ironic cherry on top

Monika Hathaway, head of press for DEF CON, noted that the conference itself suffered from multiple similar deauthorization attacks this year, which impacted their operations.

“If we had caught them doing this at DEF CON we would have removed and banned them from the conference,” Hathaway said.

It’s also not the first time this has happened. In 2024, attendees at DEF CON and Black Hat—another hacker conference—were suspected of the same antics.

Safety precautions around public Wi-Fi

Right now, Delta is working alongside federal authorities and aviation regulators to thoroughly investigate the incident. But for travelers everywhere, this mid-flight chaos serves as a stark reminder. As Ross Filipek at Corsica Technologies puts it, “Incidents like this are a reminder that convenience can create trust very quickly.”

Filipek, a cyber security expert, warned that public Wi-Fi safety depends on users recognizing the right network. Hackers set up and name their network in similar fashion to the one you trust. And if you don’t look closely, you might end up connecting to a rogue network intent on stealing your details.

“Once users are kicked offline, some may reconnect to a rogue network that looks legitimate. That creates an opening for credential theft or phishing,” Filipek said.

Source: Cybernews, Fox5 Atlanta