CyberSecurityNews

DEF CON Attendees Allegedly Jammed Plane Wi-Fi and Broadcast Fake ‘Delta WiFi Fast’ Network Mid-Flight


A Delta Air Lines flight carrying passengers home from the world’s largest hacking conference became the center of a rapidly unfolding cybersecurity scare on Monday, after crew members reported that someone onboard had jammed the aircraft’s official Wi-Fi and stood up a convincing fake network designed to phish fellow travelers.

The incident, which unfolded on Delta Flight 591 from Las Vegas to Atlanta, has triggered a formal airline investigation and partnership with federal law enforcement, while drawing sharp criticism from security professionals who called the alleged stunt reckless.

According to accounts drawn from Aircraft Communications Addressing and Reporting System (ACARS) messages and subsequent reporting, the Boeing 757 departed Las Vegas Harry Reid International Airport roughly an hour before the crew first raised the alarm.

DEF CON Attendees Plane Wi-Fi Hack

About sixty minutes into the journey, pilots messaged corporate security that a passenger had created a “scam Wi-Fi” network named Delta WiFi Fast and appeared intent on scamming other passengers.

A follow-up ACARS transmission minutes later stated that several passengers who had attended a cybersecurity conference in Las Vegas “were able to jam our Wi-Fi and broadcast their signal.” The flight had left shortly after the close of Hacker Summer Camp, the cluster of events that includes BSides Las Vegas, Black Hat, and DEF CON 34.

Security researchers describe the reported activity as a classic evil twin attack. In this technique, an attacker broadcasts a rogue access point whose name closely mimics a trusted network. Passengers seeking a faster connection may join the impostor SSID and land on a fraudulent captive portal that harvests credentials such as Google logins.

Some social-media accounts and private flyer-group posts further claimed the operators used a portable auditing device such as a Wi-Fi Pineapple to deauthenticate devices from the legitimate cabin network colloquially described by the crew as “jamming” before presenting their own phishing page.

Delta has confirmed that an unauthorized Wi-Fi network was briefly active onboard but stressed that no Delta system, including the in-flight Wi-Fi infrastructure itself, was hacked.

Once the fake network was detected, the cabin crew disabled the aircraft’s legitimate passenger Wi-Fi for approximately thirty minutes as a precaution. Delta spokesperson Morgan Durrant told reporters that “safety of flight was never in question and no aircraft operating systems were affected.”

The airline is gathering a complete set of facts and has pledged to work with federal law enforcement and aviation regulators. The flight carried 199 passengers and six crew members; no emergency was declared with air traffic control.

Conflicting passenger accounts later circulated online about whether federal agents and airport police met the aircraft at Atlanta’s Gate A18 to question suspects and inspect equipment, claims that remain part of the still-open inquiry.

Within the information-security community, the reaction was swift and largely unforgiving. Commentators labeled the alleged behavior “catastrophically stupid,” noting that intentional interference with authorized radio communications can violate the Communications Act, while credential phishing may implicate wire-fraud or identity-theft statutes.

Even absent successful theft, deliberately impairing an airline’s network on a commercial flight can create liability under the Computer Fraud and Abuse Act and invite severe federal scrutiny.

Critics also warned that such publicity stunts damage the reputation of ethical researchers who attend DEF CON to improve defenses rather than exploit captive audiences at 35,000 feet.

As of Tuesday, the investigation remains active. The Federal Aviation Administration said it had not yet received an official report, and the FBI had not publicly commented.

For ordinary travelers, the episode is a blunt reminder that in-flight Wi-Fi networks are not immune to social-engineering attacks, and that connecting to an unexpected SSID, even one that promises “fast” service, carries real risk.

[Live Webinar] Join Elastic & UnderDefense to learn how small security teams can unify AI visibility and agentic response into one operating model -> Register Now



Source link