Delta Investigates Rogue Wi-Fi Network on Flight Carrying DEF CON Attendees

Passengers returning from the Las Vegas hacker conference allegedly jammed the plane's Wi-Fi and stood up a fake 'Delta WiFi Fast' network that harvested Google logins.

ThreatVectr Newsdesk· 4 min read
Photoreal news-editorial style, 16:9 framing
Share

Key points

  • Delta Air Lines is investigating an unauthorised Wi-Fi network that briefly appeared on Flight 591 from Las Vegas to Atlanta, a Boeing 757 with 199 passengers and 6 crew.
  • Cabin crew turned off the aircraft's Wi-Fi for around 30 minutes after spotting a rogue network named "Delta WiFi Fast".
  • Onboard messages sent by the crew said passengers returning from DEF CON 34 had jammed the legitimate Wi-Fi and broadcast their own signal.
  • One passenger account says the fake network served a phishing page harvesting personal credentials and Google login data.
  • Federal authorities and airport police boarded the plane at the gate, questioned the suspects and seized their portable Wi-Fi hardware.

Delta Air Lines says it is working with federal law enforcement and aviation regulators after a fake Wi-Fi network appeared aboard a flight carrying attendees of the DEF CON 34 hacker conference in Las Vegas.

The incident, first reported by BleepingComputer, took place on Flight 591 from Las Vegas to Atlanta. The aircraft was a Boeing 757 with 6 crew and 199 passengers. Delta said the safety of the flight was never in question and no emergency was declared with air traffic control.

"One initial finding is an unauthorized WiFi network, which was not provided, operated, or supplied by Delta, was present onboard the aircraft for a short time during the flight," a company spokesperson said.

Cabin crew shut down the plane's real Wi-Fi for close to half an hour once they realised what was happening.

What actually happened on the plane?

Someone on board appears to have knocked other passengers off the legitimate in-flight Wi-Fi, then set up a lookalike network to trick them into logging in.

That first step is called a Wi-Fi deauthentication attack, where an attacker sends forged messages that pretend to come from the real wireless access point and tell everyone's phones and laptops to disconnect. Do it on a loop and nobody can stay online. Newer protections called Protected Management Frames can block this, but plenty of networks still do not use them.

Once people are kicked off the real network, they tend to reconnect to whatever looks familiar. That is where the fake network came in.

An aircraft technician who posts as Turbine Traveller published messages the crew sent through ACARS, the text system airlines use to talk to the ground. One read: "WE HAVE A PAX ON THIS HAS CREATED A SCAM WIFI CALLED DELTA WIFI FAST. WE BELIEVE THEY ARE TRYING TO SCAM THE OTHER PAX."

Mary Perrault, active in frequent-flyer groups and not affiliated with Delta, said the rogue network served a phishing page, a fake login screen, that collected "personal credentials and Google login data".

Who is behind it?

With medium confidence based on the crew's own messages and passenger accounts, this looks like opportunistic mischief by conference attendees rather than an organised criminal or state-linked operation. No CTI vendor tracks a cluster here. Deauth-and-evil-twin is one of the oldest tricks in the wireless playbook and a staple of DEF CON village demos. Capability is trivial with off-the-shelf hardware. Intent is the open question, and that is what the FBI will be trying to pin down.

Federal authorities and airport police met the aircraft at the gate, questioned the suspects and took their portable Wi-Fi gear, according to Perrault.

What should passengers do?

If you were on Flight 591 and logged in to anything through the plane's Wi-Fi, change your Google password, turn on two-factor authentication, and check recent sign-in activity on your account.

More broadly, treat any Wi-Fi network on a plane, in an airport or at a hotel with suspicion. Real airline Wi-Fi will not ask for your Google or Apple password. If a login screen wants social-media or email credentials to grant internet access, close it.

Detail Value
Flight Delta 591, Las Vegas to Atlanta
Aircraft Boeing 757
People on board 199 passengers, 6 crew
Rogue network name Delta WiFi Fast
Wi-Fi outage Around 30 minutes
Reported harvest Personal credentials, Google logins

Delta says the investigation is ongoing.

© 2026 Threat Vectr