A hacking incident on a Delta flight this week has reignited concerns among cybersecurity experts about “evil twin” Wi-Fi attacks.
Travel experts at Good Business Travel warn the same tactic could be just as likely to target travellers in airports across the UK during peak August travel season.
“This isn’t a one-off. It’s a known, repeatable attack that’s now been used on commercial flights and in airports, and August is exactly when it’s most dangerous,” says Natasha Inglis, Client Experience Director at Good Business Travel.
This isn’t an isolated incident, cyber crime is more prevalent than ever
In the past twelve months, over 5.19 million cyber crimes affected businesses in the UK and the recent attack on Beacon CRM has put the personal details held by 1,500 charities at risk.1,2
Natasha Inglis warns against a common cyber risk affecting travelling Brits. “An evil twin attack doesn’t need a sophisticated hacker, it just needs a name that looks familiar. Business travellers especially are the highest-value targets, because one set of stolen credentials can be a way into an entire company’s systems, not just one person’s inbox,” Natasha explains.
“”Fake Wi-Fi will almost always copy the exact name of the official network. If you see two networks with an identical or near-identical name, don’t connect to either until you can verify with staff which one is real.”
One Reddit user recently noticed a suspicious connection at Barcelona airport, “Many websites gave invalid certificate errors and insecure connection warnings. It looks very much like someone trying to steal personal information,” warned the user.
How to stay safe around public Wi-Fi
Natasha offers some advice on avoiding a dodgy connection:
Turn off auto-join before you travel, not after you land
“Most people’s phones are set to automatically reconnect to any network name they’ve used before. That’s the exact vulnerability evil twin attacks exploit. Your phone doesn’t just search for open Wi-Fi, it actively broadcasts a list of every network it’s connected to in the past, including things like ‘Heathrow_Free_WiFi’ or ‘Starbucks’.”
A padlock icon doesn’t mean the network is safe
“People are taught to look for ‘https’ and the padlock symbol as a sign of safety, but that only protects the connection between your device and whatever page you’re on. Scammers now use free security certificates to make a fake airport login portal just as ‘secure-looking’ as the real one. The padlock protects your data in transit; it does nothing to confirm you’re not transiting it straight to a criminal.”
Forget the network the moment you land, don’t just disconnect
“Disconnecting isn’t the same as forgetting. If you just switch your Wi-Fi off, the network name stays saved on your device and your phone will auto-reconnect the next time it’s in range, even if that network was a fake one to begin with. Travellers passing through the same airport repeatedly are actually more at risk over time, because their device is building up a longer list of trusted names for scammers to imitate.”

