Delta Air Lines is investigating a rogue in-flight Wi-Fi network that appeared on Flight 591 from Las Vegas to Atlanta shortly after the DEF CON hacker conference, disrupting onboard connectivity and raising fresh questions about the security of aircraft internet services.[1][3][5][11] The suspicious network, reportedly named βDelta WiFi Fast,β mimicked the airlineβs official service and prompted cabin crew to shut down the legitimate Wi-Fi for roughly 30 minutes while they alerted airline security and, ultimately, federal authorities.[1][4][5][11] Delta has emphasized that there is no evidence its systems or the aircraftβs flight controls were compromised and that the safety of the flight was never in doubt.[1][2][5]
Posts from passengers and leaked messages from the Aircraft Communications Addressing and Reporting System (ACARS) suggest crew members believed a traveler was using an unidentified device to jam or interfere with the legitimate network and steer customers toward the lookalike hotspot.[4][5][11][12] The spoofed network is reported to have displayed a phishing page designed to harvest credentials, including email and Google logins, from anyone who attempted to sign on.[5][11] On arrival in Atlanta, federal agents met the aircraft as part of the ongoing investigation into whether the activity violated US laws governing interference with aircraft systems and communications.[1][5][12]
Delta says it is cooperating with federal law enforcement and aviation regulators to piece together exactly what happened and who was responsible.[1][2][3][5] The airline confirmed that Flight 591, a Boeing 757 carrying 199 passengers and six crew members, did not declare an emergency and suffered no impact to its operating systems or avionics.[1][11] Officials have also stressed that the incident appears confined to passenger connectivity, with no indications so far that any underlying airline infrastructure was breached.[1][2][3]
Security researchers have long warned that in-flight Wi-Fi can provide attackers with an attractive venue for βevil twinβ and man-in-the-middle attacks that rely on spoofed networks to trick users into entering passwords, payment data, or other sensitive information.[6][7][9][13] Prior analyses of airborne connectivity equipment have uncovered vulnerabilities in the routers and access points used to provide passenger internet service, potentially allowing attackers on board to intercept traffic or pivot into other onboard systems if segmentation is weak.[6][9] Even when core aircraft controls remain isolated, malicious hotspots can still serve as effective phishing platforms in the cramped, distracted environment of a commercial cabin.[7][13]
The Delta probe lands against a broader backdrop of concern about aviation cybersecurity, including recent disclosures about weaknesses in aircraft communications and data link protocols that could be abused to spoof messages or location data.[14][15] US authorities have cataloged several vulnerabilities in aviation data link communications under CVE-2025-71409 through CVE-2025-71413, warning that legacy, unauthenticated radio links are susceptible to manipulation even if passenger Wi-Fi is not directly involved.[15] While there is currently no indication that the Delta incident exploited any known CVE or affected cockpit systems, it underscores how every wireless service on and around an aircraft can expand the overall attack surface.[9][14][15]
For airlines, the episode highlights the need for tighter monitoring of onboard wireless environments, including automated detection of rogue SSIDs, stronger segmentation between passenger networks and operational systems, and clear playbooks for crews responding to suspected spoofing or jamming.[6][9][11] Passengers, meanwhile, can reduce their exposure by treating in-flight Wi-Fi like any other untrusted public hotspot: verifying the exact network name with crew, avoiding entry of high-value credentials, relying on vetted VPN services when possible, and disconnecting at the first sign of inconsistencies in login pages or connection behavior.[7][9][13] Until investigations into Flight 591 conclude, the incident will remain a cautionary case study in how quickly a single spoofed network can turn a routine journey into a cybersecurity lesson at 35,000 feet.[1][5][11]
References
- Unauthorized Wi-Fi network found on Delta flight after DEF CON
- DEF CON dingus suspected of trying to take over Delta in-flight …
- Delta Probes Suspicious Wi-Fi Incident After DEFCON …
- Delta Flight Hit By Hackers After DEF CON Las Vegas
- Delta investigates in-flight Wi-Fi spoofing on post-DEF CON …
- Passengers Exposed to Hacking via Vulnerabilities in Airplane Wi-Fi …
- Fake Wi-Fi on board a flight – Kaspersky
- In-flight Wi-Fi is ‘direct link’ to hackers
- Delta Air Lines investigates rogue Wi-Fi network on flight from DEF CON
- DL591 LAS-ATL arrival met by federal agents following mid-air …
- Midair Hack Shows the Dangers of In-Flight Wi-Fi
- CVE-2024-9310: Aircraft RF Signal Spoofing Vulnerability
- CISA Warns of Vulnerabilities in Aviation Data Link Communications
