You’re at a cafe. Laptop open, coffee going cold, answering emails before a meeting. It feels completely normal. Ten years ago, working from a coffee shop felt a little bit adventurous. Now it’s just regular remote work life and that comfort is exactly the problem. We stopped treating public networks like public places. We treat them like extensions of our own living room.
Let’s go through what actually could happen when you connect to the wrong network.
The Network Threats Are Real
Here’s the setup. An attacker sets up a rogue Wi-Fi hotspot near a legitimate one. They name it something close enough to fool you, Cafe_Guest_Secure instead of Cafe_Guest. You don’t check to verify, you trust and you connect. Now every piece of data you send passes directly through their hardware first. This is called an “Evil Twin” Man-in-the-Middle (MITM) attack, someone positioning themselves right between you and the internet.
Because you are connected directly to their device, the attacker doesn’t even need to use passive packet sniffing to capture your traffic; they are your network gateway.
Without encryption, your data is completely readable. The attacker quietly reads everything passing through - passwords, session cookies, private messages, in real time while you keep typing.
Maybe you’re thinking: sure, but who actually falls for that? Reasonable question. Here’s the answer.
Evil Twin Attacks: A Fake Network Wearing a Real One’s Name
In November 2025, an Australian court sentenced a 44-year-old West Australian man to seven years and four months in prison. He’d been running evil twin networks on domestic flights and at airports in Perth, Melbourne, and Adelaide since at least April 2024. It wasn’t some elite hack. He created fake free Wi-Fi access points to collect personal information from unsuspecting passengers. Passengers connected after mistaking the rogue access point for a legitimate service, typing their credentials into a fake page to gain access. The scam was finally discovered by a flight attendant who noticed a suspicious network name and reported it.
The Australian Federal Police (AFP)’s advice after their case was simple: a network that asks for your social media passwords or private account credentials just to grant Wi-Fi access should never be trusted. Legitimate hotspots won’t ask for your private logins.
A similar case turned up on a Delta flight from Las Vegas to Atlanta. An attacker sent hidden disconnect signals through the airwaves to forcibly kick passengers off the plane’s official Wi-Fi. Right alongside it, they broadcast a fake network named “DELTA WIFI FAST”. Frustrated by the sudden drop and eager to get back online, unsuspecting passengers reconnected straight to the trap. Once the crew discovered what was happening, they had to shut the plane’s Wi-Fi down completely for half an hour to clear the threat.
High-traffic environments like flights, subway terminals, or local cafes rely entirely on users blindly trusting the network name they see. Cybercriminals exploit that automatic trust.
What can protect you
Lock Down Your Network Path
Verify the network name: Don’t trust the name alone, confirm the exact Wi-Fi network name out loud with staff if you’re unsure.
Use a VPN: A VPN wraps all your network traffic in an encrypted tunnel before it leaves your device. Even if you land on a compromised network, the attacker cannot inspect or tamper with your data traffic.
Check for HTTPS: Ensure your browser displays https:// and the lock icon in the URL bar before entering sensitive details.
Save sensitive tasks for trusted networks: Handle banking, taxes and high-value logins on your home network or mobile data, never on open public Wi-Fi.
Harden Your Device Before You Step Outside
Turn off “Auto-Connect” for Wi-Fi and Bluetooth: This is the exact setting that lets rogue “Evil Twin” networks catch users off guard when their devices reconnect automatically to a Wi-Fi name that looks familiar.
Turn off local sharing: Disable AirDrop, Nearby Share, and local file/printer sharing when out in public.
Enable Multi-Factor Authentication (MFA): MFA blocks attackers who only have your password. Just remember: never enter your MFA codes or passwords into unexpected Wi-Fi login pop-ups.
Treat public Wi-Fi like what it is - a room full of strangers, not your home office. Never leave a device unattended in a public space, not even for 30 seconds.
References
Australian Federal Police, “WA man jailed for stealing intimate material and using ‘evil twin’ WiFi networks”, November 28, 2025
CBS News Atlanta, “Possible hoax Wi-Fi network on Delta flight to Atlanta under investigation”, August 2026
Delta flight carrying DEF CON “hackers” hit by Wi-Fi attack mid-air, August 2026
