Delta Investigates Rogue Wi-Fi Network on Flight Carrying DEF CON Attendees

Passengers returning from the Las Vegas hacker conference allegedly knocked others off the plane's Wi-Fi and stood up a fake 'Delta WiFi Fast' network that harvested Google logins.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 4 min read
An airplane cabin with passenger seats visible in background, foreground showing a smartphone screen displaying two overlapping Wi-Fi networks—one legitimate, o
Share

Key points

  • Delta Air Lines is investigating an unauthorised Wi-Fi network that briefly appeared on Flight 591 from Las Vegas to Atlanta, a Boeing 757 with 199 passengers and 6 crew.
  • Cabin crew turned off the aircraft's Wi-Fi for around 30 minutes after spotting a rogue network named "Delta WiFi Fast".
  • Crew messages sent via ACARS said passengers returning from DEF CON 34 had jammed the legitimate Wi-Fi and broadcast their own signal.
  • One passenger account says the fake network served a phishing page harvesting personal credentials and Google login data.
  • Federal authorities and airport police boarded the plane at the gate, questioned the suspects and confiscated their portable Wi-Fi hardware.

Delta Air Lines says it's working with federal law enforcement and aviation regulators after a fake Wi-Fi network appeared aboard a flight carrying DEF CON 34 attendees from Las Vegas.

The incident, first reported by BleepingComputer, took place on Flight 591 to Atlanta. Delta said the flight's safety was never in question and no emergency was declared with air traffic control. The aircraft was a Boeing 757 carrying 199 passengers and 6 crew.

"One initial finding is an unauthorized WiFi network, which was not provided or operated by Delta, was present onboard the aircraft for a short time during the flight," a company spokesperson said.

Cabin crew shut down the plane's real Wi-Fi for close to half an hour once they realised what was happening.

What actually happened on the plane?

Someone on board appears to have knocked other passengers off the legitimate in-flight Wi-Fi, then set up a lookalike network to trick them into logging in.

That first step is a Wi-Fi deauthentication attack: an attacker sends forged packets that appear to come from the real wireless access point, telling every connected device to disconnect. Run those packets on a loop and nobody stays online. Newer protections called Protected Management Frames can block this, but plenty of networks don't use them.

Once people are kicked off the real network, they tend to reconnect to whatever looks familiar. That's where the fake network came in.

An aircraft technician who posts as Turbine Traveller published ACARS messages (the text system airlines use to talk to the ground) that the crew sent mid-flight. One read: "WE HAVE A BUNCH OF PAX THAT WERE AT A CYBER CONFERENCE IN LAS… THEY WERE ABLE TO JAM OUR WIFI AND BROADCAST THEIR SIGNAL." A second confirmed the rogue network by name: "WE HAVE A PAX ON THIS HAS CREATED A SCAM WIFI CALLED DELTA WIFI FAST. WE BELIEVE THEY ARE TRYING TO SCAM THE OTHER PAX."

Mary Perrault, active in frequent-flyer groups and not affiliated with Delta, said the rogue network served a phishing page that collected "personal credentials and Google login data."

Who is behind it?

With medium confidence, based on the crew's own messages and passenger accounts, this looks like opportunistic mischief by conference attendees rather than an organised criminal or state-linked operation. No CTI vendor tracks a cluster here. Deauth-and-evil-twin is one of the oldest tricks in the wireless playbook, a staple of DEF CON village demos. It's worth comparing to the hotel Wi-Fi campaign we covered on 24 July, where infrastructure overlapping with APT28 was funnelling guests into fake Microsoft login pages: same technique, very different implied intent. Capability here is trivial with off-the-shelf hardware. Intent is the open question, and that's what the FBI will be trying to pin down.

Federal authorities and airport police met the aircraft at the gate and confiscated the suspects' portable Wi-Fi gear, according to Perrault.

Should you worry?

If you were on Flight 591 and logged in to anything through the plane's Wi-Fi, change your Google password, enable two-factor authentication and check recent sign-in activity on your account.

More broadly, treat any Wi-Fi on a plane or at a hotel with suspicion. Real airline Wi-Fi won't ask for your Google or Apple password. If a login screen wants email or social-media credentials to grant internet access, close it.

Detail Value
Flight Delta 591, Las Vegas to Atlanta
Aircraft Boeing 757
People on board 199 passengers, 6 crew
Rogue network name Delta WiFi Fast
Wi-Fi outage Around 30 minutes
Reported harvest Personal credentials, Google logins

The investigation is ongoing.

© 2026 Threat Vectr