Passenger returning from DEF CON 34 spoofs Delta Wi-Fi network while in flight using pentest tool — pilots tell ground crew to alert corporate security after attendee from hacking conference brings the party to the sky
A flight carrying passengers who attended a cybersecurity convention reportedly had its Wi-Fi network victimized by deauthentication attacks while an 'evil twin' hotspot rerouted potential victims to a phishing website. While flight safety was never affected, it's unclear if any of the other passengers had their credentials stolen while in the air.
Delta Flight 591, traveling from Las Vegas, Nevada, to Atlanta, Georgia, carried passengers who had recently attended the DEF CON 34 hacking conference. A passenger apparently decided to disrupt the experience by "jamming" the plane's Wi-Fi signal. According to View From the Wing, the hacker then set up their own Wi-Fi hotspot named "Delta WiFi Fast," which directed users to a phishing website designed to capture Google credentials from unsuspecting passengers.
The pilots communicated with the ground crew via ACARS, Delta's digital communications system, alerting them to the situation. They reported, "We have a passenger onboard that has created a scam Wi-Fi called 'Delta WiFi Fast.' We believe they are trying to scam the other passengers." Later, they said, "No information as of now. We have a bunch of passengers that were at a cybersecurity conference in Las Vegas.
They were able to jam our Wi-Fi and broadcast their signal." The exact details of the incident are still under investigation, but it appears that the attacker used a Wi-Fi Pineapple penetration testing device to execute Wi-Fi deauthentication attacks and then created an "evil twin" network that passengers could connect to instead.
The fake login page had the potential to harvest usernames, passwords, and other sensitive information. Although the plane was met at the gate by authorities, it is unclear if any arrests were made. In-flight Wi-Fi networks are generally unsecured, making them vulnerable to such attacks. Creating an "evil twin" network is not as alarming as a network or device named "bomb," but it could still result in legal consequences.
Interfering with in-flight Wi-Fi, or any Wi-Fi network, is prohibited by the FCC, while the phishing login page could potentially lead to wire fraud or identity theft. Despite the threat to passengers' cybersecurity, Delta assured passengers that the safety of the flight was never compromised, and no aircraft operating systems were affected.
The airline is actively investigating the incident and cooperating with federal law enforcement and aviation regulators to ensure a thorough investigation.
Written by urgent.news from Tom's Hardware's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.