Flight DL591 from Las Vegas to Atlanta: On August 10, 2026, one or more passengers returning from DEF CON 34 set up a fake “Delta WiFi Fast” WiFi network inside the cabin of a Delta Air Lines Boeing 757 and attempted a classic evil twin attack against fellow passengers. The crew realized this one hour after takeoff, notified the corporate security center via ACARS and disabled the official in-flight WiFi for approximately 30 minutes. The FBI has been notified and Delta is cooperating with federal authorities. The SecNews technical team documents what happened, why it was an extremely stupid move and what it means for Greek travelers.
See also: Active phishing targeting Eurobank customers: Fake SMS "9,428 points" leads to eurobanktes.vip

What happened on the Delta WiFi Fast flight?
Delta Flight 591 departed from Harry Reid in Las Vegas at approximately 8:30 a.m. local time, bound for Atlanta Hartsfield-Jackson. It had been delayed the previous day, filled with passengers returning from DEF CON 34 and Black Hat USA. About an hour after takeoff, the crew sent the first ACARS message to Delta's operations center:
"HEY ALERT CORP SECURITY WE HAVE A PAX ON THAT HAS CREATED A SCAM WIFI CALLED DELTA WIFI FAST WE BELIEVE THEY ARE TRYING TO SCAM THE OTHER PAX"
Seventeen minutes later, a second message followed, referring to “a group of passengers from a cybersecurity conference in Las Vegas” who “managed to jam our WiFi” and broadcast their own signal. The crew turned off the official in-flight WiFi for about half an hour to cut off passengers’ connection to the fake network.
How an evil twin attack on an airplane works
The evil twin attack is one of the most classic WiFi phishing scenarios. In the case of flight DL591, the following steps were probably followed:
- Deauthentication frames are sent to the legitimate access point, disconnecting passengers' devices from the official WiFi
- Fake access point broadcasts with an almost identical network name (SSID) — here, "Delta WiFi Fast" instead of "Delta WiFi"
- Devices automatically connect to the strongest signal or familiar SSID, without the user realizing it
- Captive portal with an exact copy of the official login page appears, asking for email, passwords or card details
- The data is sent to the attackers, along with any HTTP traffic detected through the man-in-the-middle proxy.

According to reports circulating on airline forums, the tool that may have been used was a WiFi Pineapple, a pocket-sized device specifically designed for wireless network security checks — but not at all legal to use against unknown passengers on a commercial flight.

Where is the perpetrator legally located?
The charges that can be brought in the US are serious and multiple. The Federal Communications Commission considers willful interference with WiFi systems a violation of section 333 of the Communications Act. A willful and knowing violation can be punished with imprisonment for up to one year and a fine of up to $10,000. If the attack is classified as a second attempt or is part of a broader criminal pattern, the prison sentence can reach two years.
To these are added categories for:
- Computer Fraud and Abuse Act (CFAA): Unauthorized access and attempted theft of credentials
- Wire Fraud: Fraud through telecommunications networks
- Possible aviation law categories: Interference with in-flight systems, even if the safety of the vessel was not affected
Delta has stated explicitly that no aircraft systems were compromised and that the safety of the flight was never compromised. However, the company is working with federal officials and aviation regulators to fully investigate.

See also: Hackers Tracked Child via Kids' Smartwatch
It's not the first time — a precedent from Australia
The exact same tactic was recorded in Australia in 2024. Michael Clapsis, 42, was arrested by the Australian Federal Police for using a portable wireless access point to mimic Qantas' legitimate in-flight WiFi on a domestic flight. Clapsis was eventually sentenced to seven years in prison, as the investigation uncovered wider criminal activity.
The common element in both cases is that the crew or alert passengers noticed the suspicious behavior. A fake SSID that suddenly appears on an aircraft is an extremely limited crime scene — the perpetrator cannot escape and the circle of suspects is limited to a few dozen people.
What can Greek travelers do?
Many Greeks fly with Delta, KLM, Air France and other airlines that provide in-flight WiFi. The SecNews technical team recommends the following measures on every flight:
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
- Confirm the SSID from the official aircraft card or crew announcement, not the first network with a convincing name that appears
- Avoid connecting to banking services via in-flight WiFi. Even on a legitimate network, security is not at bank level
- Use VPN from the start, with automatic connection once the terminal obtains an IP
- Disable automatic connection to known WiFi on your device before flying
- Use mobile eSIM where possible, instead of WiFi for critical transactions
- Observe the behavior of fellow passengers: someone with a large laptop and external WiFi antenna might deserve a discreet mention to the crew
See also: iCloud Private Relay: A passkey request is enough to reveal the real IP
Why is it the worst possible choice for this type of attack?
A commercial aircraft is the worst possible environment for an evil twin attack, for several reasons:
- Federal jurisdiction: Flights in the US are subject to federal law, with much stricter penalties than state law
- Confined space: The perpetrator cannot escape the crime scene
- Checked boarding: Each passenger is identified by security checks
- Crew monitoring: Flight attendants are trained to observe suspicious behavior
- Mutual exposure: The perpetrator is in the same WiFi range as potential victims, with no easy escape
- DEF CON Conference: The flight carried dozens of cybersecurity experts who will notice the attack immediately
Similar techniques are legally tested every year at DEF CON itself, in tightly controlled labs and networks set up for this purpose. Transferring these experiments to real systems and people is a criminal act, no matter how “technically interesting” it may seem.
The steps Delta is taking now
- Collaboration with FBI to identify and prosecute the perpetrator or perpetrators
- FAA update and possible revision of protocols for in-flight WiFi
- Internal investigation to determine if any passenger ultimately provided credentials to the fake network
- Informing flight passengers with clear instructions to change codes if they encounter suspicious activity
The Flight 591 incident is a reminder that any public wireless network, from airports to coffee shops to hotels, can be spoofed. Carefully verifying the real SSID, using a VPN, and avoiding banking on public networks remain key defenses. The SecNews editorial team will follow the investigation, any arrests of suspects, and announcements from Delta and the FBI. Sources: The Register, BleepingComputer, View from the Wing, The Detroit News.
