Delta Air Lines is currently investigating the appearance of an unauthorized wireless network aboard Flight 591, which operated from Las Vegas to Atlanta. Notably, a significant number of passengers on that flight had attended DEF CON – one of the world’s largest hacker conventions. As reported by Ars Technica, the rogue network is widely suspected to have been the deliberate work of a conference attendee.
Crew Detects the Anomaly and Alerts Ground Security
The crew aboard Delta Flight 591 detected a wireless network broadcasting under the name “Delta WiFi Fast” – a network entirely unaffiliated with the airline’s legitimate in-flight connectivity service. The attacker employed a technique known as a WiFi deauthentication attack, which forcibly disconnected other passengers from the aircraft’s genuine onboard wireless network by flooding it with spoofed deauthentication frames.
Upon identifying the anomaly, crew members promptly disabled the aircraft’s own WiFi service and reported the security incident to the ground security center, U.S. federal law enforcement, and U.S. aviation regulatory authorities. Delta Air Lines is now cooperating with investigators to examine the full scope of the incident.
Suspect Reportedly Apprehended at the Gate
The individual responsible appears to have been apprehended. According to a passenger account, after Flight 591 landed and docked at the gate, federal law enforcement officers and airport police conducted interviews with passengers and confiscated certain portable WiFi devices. The logic was straightforward: with no means of escape before the aircraft touched down, investigators were well-positioned to intercept suspects at the exit. The confined environment of the aircraft effectively eliminated any avenue of flight.
Rogue Hotspot Designed to Harvest Google Credentials
Critically, this incident bears none of the hallmarks of a benign prank. Multiple passengers reported that upon connecting to the attacker’s rogue network, they were immediately served a phishing page engineered to harvest personal credentials and Google account login data. That deliberate attempt to steal sensitive information elevates this well beyond a harmless stunt into territory that carries serious criminal implications. These accounts remain unconfirmed by official sources.
How the Deauthentication Attack Works
The attack method deployed here – a phishing-oriented deauthentication assault – follows a well-established playbook. The attacker continuously broadcasts forged deauthentication frames, compelling client devices to sever their connections from the legitimate access point. Once disconnected, those devices can be coerced into automatically reconnecting to the attacker’s rogue access point. From that position, the attacker gains the ability to intercept traffic and redirect victims to malicious pages at will – a technique as technically straightforward as it is legally consequential.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.