Key Takeaways
- An unauthorized Wi‑Fi network titled “Delta Wifi Fast” appeared on Delta Flight DL591 (Las Vegas → Atlanta, 10 August 2024).
- The network was not operated by Delta; the crew disabled the aircraft’s Wi‑Fi for about 30 minutes as a precaution.
- Evidence suggests the incident was an “evil‑twin” attack aimed at stealing passenger credentials rather than compromising aircraft controls.
- Similar attacks have occurred in Australian airports and on domestic flights in 2024, indicating a growing threat to aviation Wi‑Fi.
- Cyviation’s laboratory tests show a rogue network can be created with a ordinary smartphone, potentially overpowering legitimate in‑flight Wi‑Fi.
- Crew awareness and formal response procedures are currently ad‑hoc; Almog recommends standardized training and check‑lists for identifying and mitigating wireless threats.
- While attacks on passenger Wi‑Fi are realistic, extending them to critical flight systems (e.g., electronic flight bags, cabin‑management systems) remains difficult but warrants research.
- The rapid evolution of cyber capabilities outpaces the long certification cycles of aviation hardware, necessitating continuous vulnerability monitoring and faster coordination among airlines, manufacturers, and regulators.
- Passengers should practice the same Wi‑Fi hygiene used on the ground: verify the network name, scrutinize login pages, and avoid entering sensitive data if anything looks suspicious.
Incident Overview
On 10 August 2024, Delta Air Lines Flight DL591, a Boeing 757 en route from Las Vegas to Atlanta, experienced the appearance of an unauthorised wireless network labelled “Delta Wifi Fast.” Delta confirmed that the network was neither provided nor operated by the airline. As a precaution, the flight crew temporarily disabled the aircraft’s passenger Wi‑Fi for roughly 30 minutes. The airline stated that none of its systems were compromised and that flight safety was never jeopardised. Delta is cooperating with federal law‑enforcement and the Federal Aviation Administration (FAA) in an ongoing investigation.
Connection to DEF CON and the “Evil Twin” Concept
The rogue network surfaced shortly after the DEF CON cybersecurity conference in Las Vegas, though no direct link has been proven. Cyviation CEO Eliran Almog told Aerospace Global News that the available evidence aligns with a classic “evil‑twin” Wi‑Fi attack. In such an attack, threat actors create a counterfeit wireless network that mimics a legitimate one, tricking users into connecting and divulging credentials or payment information. Almog emphasized that the tactic is not new to aviation but remains a potent method for harvesting data from unsuspecting passengers.
How an Evil‑Twin Attack Works
An evil‑twin network reproduces the expected service set identifier (SSID) and often replicates the captive‑portal landing page that passengers see when joining an airline’s Wi‑Fi. Because the visual cues appear authentic, users cannot easily distinguish the fraudulent network from the real one. Once a passenger logs in, the attacker can harvest usernames, passwords, and potentially credit‑card details entered on the spoofed page. Almog noted that passengers, especially when frustrated by intermittent connectivity, may readily select any plausible‑looking network to regain access, increasing the success rate of the ruse.
Precedent and Undetected Cases
Almog cited similar evil‑twin incidents at Australian airports and on domestic flights in 2024 that led to prosecutions. He suspects that many comparable events go unnoticed or unreported because they do not trigger overt system alerts. The Delta incident entered the public domain after an aviation hobbyist monitoring ACARS (Aircraft Communications Addressing and Reporting System) traffic observed anomalous messages between the aircraft and Delta operations and shared them online, prompting the airline’s acknowledgment.
Laboratory Demonstration of Rogue Network Power
Cyviation conducted controlled experiments showing that a rogue Wi‑Fi network could be generated using only a standard smartphone, without needing sophisticated computing gear. In the lab, the phone emitted sufficient radio‑frequency power to override the aircraft’s legitimate Wi‑Fi signal. Almog was quick to clarify that these tests were performed in a laboratory setting, not aboard an actual flight, and therefore do not confirm what transpired on DL591. Nonetheless, the demonstration underscores how accessible the required tools are for a potential attacker.
Crew Response and the Need for Formal Procedures
The Delta crew’s reaction—identifying the unfamiliar “Delta Fast” network and shutting down the Wi‑Fi routers for about 30 minutes—was praised by Almog as an appropriate, albeit ad‑hoc, response. He argued that reliance on individual judgment is insufficient and advocated for structured “awareness training” programs. Such training would equip flight crews with clear check‑lists for detecting suspicious networks, isolating them, and reporting incidents, thereby reducing variability in responses across different flights and crews.
Potential Expansion Beyond Passenger Wi‑Fi
While Delta confirmed that no aircraft systems were hacked during the incident, Almog warned that the threat surface could extend to other onboard devices. Of particular concern are electronic flight bags (EFBs)—tablets or laptops pilots use for charts, weather, and performance data. Cyviation’s lab work has shown that a malicious Wi‑Fi network could lure a pilot into connecting to an EFB, after which the attacker might deliver malware or phishing prompts. Although the research is still early, Almog stressed that any compromise of pilot‑facing tools could indirectly affect flight safety, for instance by causing distracting alerts or degrading situational awareness.
Cabin Management Systems as a Secondary Target
Cyviation has also identified vulnerabilities that could allow a rogue network to reach the cabin‑management system (CMS), which controls lighting, temperature, and passenger‑entertainment displays. Although CMS architectures are typically isolated from flight‑control avionics, an attacker could still provoke a safety‑relevant scenario: imagine cabin lights flickering, temperature rising, or ransomware messages appearing on every seat‑back screen while pilots are navigating challenging weather or heavy air traffic. Such distractions could impair crew performance, even if the aircraft remains controllable.
Mismatch Between Aviation Certification Cycles and Cyber Threat Evolution
A core challenge highlighted by Almog is the disparity between the long development and certification timelines of aviation hardware—often spanning years—and the rapid pace at which cyber threats emerge, sometimes within days or weeks. Aircraft entering service today were designed when today’s sophisticated attack tools, including AI‑driven techniques, were unimaginable. Consequently, even recently certified systems may harbor unknown exploitable flaws. Almog urged airlines, manufacturers, and regulators to adopt continuous vulnerability‑identification processes rather than relying solely on periodic certification updates.
Barriers to Updating Legacy Infrastructure
Critical ground‑based systems such as the Instrument Landing System (ILS) cannot be patched with a simple software push; modifications require extensive re‑certification and can affect thousands of aircraft and associated ground equipment worldwide. This inertia means that legacy components remain in service longer than ideal from a cybersecurity perspective, amplifying the attack surface. Addressing these constraints demands coordinated investment, phased upgrades, and robust risk‑management strategies.
Enhancing Threat Visibility Inside the Aircraft
Almog believes that improving real‑time visibility into the aircraft’s digital environment is key to early threat detection. Technologies that monitor for anomalous SSIDs, unusual device behavior, or suspicious network traffic could flag potential evil‑twin attempts before they affect passengers. He also referenced other recent incidents where passengers’ devices bore alarming network names (e.g., “bomb”), prompting security responses and, in some cases, military escorts. Proactive screening at gates or check‑ins—while technically feasible—raises privacy and regulatory considerations that must be balanced against security benefits.
Guidance for Passengers
Despite the vulnerabilities, Almog advises passengers not to abstain from using in‑flight Wi‑Fi. He notes that evil‑twin attacks are equally possible on hotel, airport, or café networks. The recommended defensive posture mirrors everyday Wi‑Fi hygiene: verify that the network name matches the official service provided by the airline, scrutinize any login page for irregularities (poor grammar, unexpected requests for personal data), and refrain from entering sensitive credentials if anything seems amiss. In essence, “just be aware” because wireless threats are ubiquitous in today’s connected world.

