skip to main content

Scammers Are Cloning Airport and Coffee Shop Wi-Fi Networks

Know the risks and get tips for staying safe

We’ve all heard that public Wi-Fi can be risky, but a lot of people don’t think twice about connecting to a network that matches the name of their local cafe, airline, or airport.

Don’t let that familiarity fool you—evil twin networks can look just like legit networks, but they sidestep typical security procedures like password protection and antivirus software.

The risk is real, and every device that connects to public Wi-Fi is at risk. In August 2026, a passenger on a Delta flight out of Las Vegas allegedly broadcast a fake “Delta WiFi Fast” network mid-flight. Someone on the crew noticed, and they had to shut down the plane’s real Wi-Fi for half an hour. Ironically, the flight was full of hackers leaving an industry conference.

In Australia, one man set up evil twin attacks at airports in Perth, Melbourne, and Adelaide, stealing login credentials from travelers in all three. It took investigators more than a year to build the case, and he was ultimately sentenced to more than seven years in prison.

We’ll walk through the threat landscape, give you clues for spotting a fake network before you connect, and give you tips for staying safe any time you’re on public Wi-Fi.

Shopping for Wi-Fi at home?

Enter your zip for a complete list of internet providers in your area.

Understanding the evil twin Wi-Fi scam

An evil twin Wi-Fi network is an access point set up to look legitimate. It’s a type of man-in-the-middle attack where a scammer inserts themselves between you and the internet. It’s most common on public Wi-Fi, but technically it can happen anywhere.

Here’s how they trick you:

  • The network name can be identical to the real one, or close enough you won’t notice
  • The signal is often stronger than the legitimate network’s
  • In some cases, hackers jam or attack the real network first, so theirs the only one you can connect to

Once you’re connected, the attacker doesn’t need much cooperation from you. According to LastPass, an evil twin can deploy a keylogger on your device to capture everything you type.

They can also throw up a fake splash page that asks you to gain access to the network by entering login credentials from your internet service provider, Google account, or social media accounts. Sometimes, they get real sneaky and sit on stolen usernames and passwords for a long time.

You hop on your flight, tip your barista, and go about your life. A few weeks or months later, bam! You’re hit with fraud—or even identity theft—out of the clear blue sky.

The scope of the scam

Hijacking Wi-Fi is more than just an airport nuisance—the same trust gap gets exploited at the highest levels.

In 2022, Russian state-linked hackers breached a U.S. organization working on Ukraine policy by hijacking Wi-Fi from a nearby building, sidestepping internet-facing defenses entirely.

It’s hard to know exactly how common the problem is, but an academic census from 2021 scanned 19 million Wi-Fi access points in China and detected scammer activity on roughly 4% (including ad injection, spoofing, and hijacked sessions).

Wi-Fi hotspot security, by the numbers

Keeping your information secure on public Wi-Fi starts with knowing the risks. We surveyed 1,000 people about their habits. Here’s what we found:

  • 96% know their information could be stolen on public Wi-Fi, but only 29.13% know what an evil twin network is.
  • When faced with multiple public Wi-Fi networks with similar names, only 25% ask staff which one is legitimate before logging on (and 15.43% just guess)
  • More than half (50.25%) rarely or never use a VPN when connecting to public Wi-Fi
  • Only 12.02% say they always use a VPN when connected to public Wi-Fi

How to spot an evil twin Wi-Fi network

While half of our survey respondents are confident they can spot a fake network, identifying them is often harder than it seems. Here’s what to look for:

Network names with spelling errors or extra characters

Evil twin network names could be identical to legit ones, or they might have minor variations like an added space, hyphen, or number. If you see two networks with the same name, or one that’s almost—but not quite—right, treat both as suspect until staff confirms which one is legitimate.

Fake login pages

A convincing evil twin often serves up a login or captive portal page that mimics the real splash page. Beware of pages asking for info like a full mailing address or credit card number, and don’t use login credentials from other accounts to log in.

Pro tip: Use your provider’s app to log into their hotspots around town

Providers like Xfinity and Spectrum Mobile offer millions of free hotspots to subscribers, but the secure way to connect is through the provider’s mobile app, not your phone’s Wi-Fi settings.

Technically, you can select the network name manually instead. But then you’ll need to enter your account credentials to get past the splash page. If that network happens to be an evil twin, you’ll have no way of knowing until it’s too late. Scammers could steal your login and even get into your home network. Just don’t do it.

Sudden disconnections from a network you were already on

If you get kicked off a public network, be careful which network you reconnect to. Hackers can flood a legitimate access point with a denial-of-service (DoS) attack, forcing devices off it so they reconnect to the attacker’s look-alike network instead.

Security or certificate warnings your device wasn’t giving before

Your phone or laptop will often flag an unsecured network, and your browser will warn you about invalid SSL certificates on sites that are usually secure. Don’t dismiss these warnings just to get online faster. They’re one of the more reliable tells that something’s wrong.

There’s no easy way to know you’re on a legit network

Here’s the uncomfortable truth: Most people have no reliable way to tell they’re on an evil twin just by looking at their phone or laptop. The network name and even the login page can be identical to the real thing.

Of course, technically inclined users have ways to find out. Every access point has a unique hardware ID called a BSSID, similar to a MAC address. So, if a network shares a name with one you trust but has a different BSSID, that’s a sign something’s off.

Most people don’t have an easy way to check that, though. Here’s what you can do:

  • Ask staff to confirm the official network name before you connect.
  • Be wary of login portals asking for more than basic info like an email address or hotel room number.
  • If a network usually requires a password and suddenly doesn’t (or vice versa), don’t connect. That mismatch is a red flag.
  • Try entering the wrong password on purpose. If it lets you on anyway, it’s not a real, secured network.
  • Turn off auto-connect for public Wi-Fi. Letting your device automatically join known networks makes it easier to be fooled by a copycat name.

How to stay safe on public Wi-Fi

Cybersecurity experts have recommended these same simple best practices for years. Here is how to stay safe:

  • Look for HTTPS in the address bar before entering anything. No lock icon, no login.
  • Skip banking, tax sites, and anything else tied to your financial or personal accounts. Save it for a network you trust.
  • Don’t type passwords manually. Let a password manager autofill them, and don’t override it just because a site won’t cooperate.
  • Use a VPN. Every time.
  • Use a privacy-focused browser, like Brave or Zen Browser.

While we’re at it, here are some things you should avoid doing:

  • Don’t ignore browser warnings about invalid certificates.
  • Don’t send emails with private or sensitive information while you’re connected.
  • Don’t download unfamiliar files or open emails from people you don’t know.

Pro tip: Turn on two-factor authentication everywhere you can

If your password does get stolen on public Wi-Fi, multi-factor authentication stands guard between a scammer and your accounts. Set it up as a biometric authentication (finger print) or text message rather than an email. That way, a hacker won’t get access to your accounts, even if they were able to swipe your login credentials.

My Take: Invest in a multi-device VPN

You should always use a VPN on every device you’re connecting to public Wi-Fi (and sometimes even when you’re on private networks). Options like Surfshark support multiple devices, and plans start at just a few bucks a month.

Of course, a VPN doesn’t stop you from connecting to the evil twin in the first place, and it doesn’t protect anything that happens before the VPN tunnel is active. If you give away credential information on the fake login/splash screen, for instance, the hacker will still see it.  A VPN protects you while you’re online, but it’s not a shield against the initial phishing page itself.

If you don’t want to hassle with any of it, just buy a mobile phone plan with a generous data allowance and use mobile data while you’re out and about. Most premium plans now include huge buckets of high-speed hotspot data, so you can tether a laptop or tablet to your mobile hotspot without worrying about slowing everything down.

Ready for your own Wi-Fi network?

Enter your zip for a complete list of internet providers in your area.

Author -

Chili Palmer covers home tech services, with a special focus on understanding what families need and how they can stay connected on a budget. She handles internet access and affordability, breaking news, mobile services, and consumer trends. Chili’s work as a writer, reporter, and editor has appeared in publications including Telecompetitor, Utah Business, Idaho Business Review, Benton Institute for Broadband & Society, and Switchful.com.

Editor - Jessica Brooksby

Jessica loves bringing her passion for the written word and her love of tech into one space at HighSpeedInternet.com. She works with the team’s writers to revise strong, user-focused content so every reader can find the tech that works for them. Jessica has a bachelor’s degree in English from Utah Valley University and seven years of creative and editorial experience. Outside of work, she spends her time gaming, reading, painting, and buying an excessive amount of Legend of Zelda merchandise.