DEF CON crowd suspected in fake Wi-Fi attack on Delta flight

DEF CON crowd suspected in fake Wi-Fi attack on Delta flight

On Monday, passengers aboard Delta flight 591, traveling from Las Vegas to Atlanta, allegedly spoofed the plane's onboard Wi-Fi. The incident happened one day after the DEF CON security conference wrapped up in Las Vegas, and it drew the attention of federal law enforcement.

The episode first surfaced on social media accounts that track publicly available air-to-ground messages, known as ACARS. According to the account "ACARS Drama," the plane's pilots sent a message reading: "NO INFO AS OF NOW WE HAVE A BUNCH OF PAX THAT WERE AT A CYBER CONFERENCE IN LAS THEY WERE ABLE TO JAM OUR WIFI AND BROADCAST THEIR SIGNAL."

A description of the incident posted to Reddit added detail: the passengers had allegedly created a fake hotspot named "Delta WiFi Fast," complete with a phishing landing page designed to harvest passengers' personal credentials.

The method described is known in the security world as an "evil twin" attack, a long-established technique. It works by standing up a Wi-Fi network that mimics a legitimate one, then capturing whatever login credentials or other data unsuspecting users hand over once they connect.

No airline, FBI, or other official source has confirmed the account. The report rests entirely on the ACARS Drama social media post and the Reddit description, no passengers or other individuals are named, no headcount is given, and no arrest or other law enforcement action is described beyond the incident having "raised the attention of federal law enforcement."

Key facts

  • Passengers on Delta flight 591, from Las Vegas to Atlanta, allegedly spoofed the plane's Wi-Fi on Monday, one day after DEF CON ended in Las Vegas.
  • The plane's pilots sent an ACARS message, surfaced by the "ACARS Drama" account, describing passengers who "jammed our wifi and broadcast their signal."
  • A Reddit post described a fake hotspot named "Delta WiFi Fast" with a phishing landing page built to harvest passengers' personal credentials.
  • The technique is known as an "evil twin" attack: a fake network mimicking a real one, used to capture login credentials and other data.
  • No airline or law enforcement agency has confirmed the account, no passengers are named, and no arrest or other outcome has been reported.

Why it matters

The timing puts DEF CON, a conference built around demonstrating real-world hacking techniques, right next to a live incident that used one of the oldest tricks in that toolkit against a commercial flight full of strangers. It is a reminder that skills shown off at a security conference do not stay in the conference hall.

Who it affects

Anyone who connects to an unfamiliar Wi-Fi network expecting it to be the real one, in this case Delta passengers on flight 591, but the same setup works in any airport, hotel or cafe. Delta and the passengers on that specific flight are the ones directly involved.

How to use it

The practical takeaway for travelers is to treat in-flight and public Wi-Fi captive portals as untrustworthy by default: check that the network name matches what the airline actually offers, be wary of entering login credentials on a landing page, and use a VPN where possible rather than trusting the portal.

How solid is it

The account is built entirely on secondhand sources: an ACARS-tracking social media account relaying a pilot message, and a separate Reddit post describing the fake hotspot and phishing page. Neither Delta, the FBI, nor any other official body has confirmed the details, and the authenticity of the ACARS message and the Reddit post has not been independently verified.

Risks and caveats

Because the report has no official confirmation, key facts remain open: how many passengers were involved, whether anyone's credentials were actually taken, and what, if anything, comes of the case. The "evil twin" technique itself is well understood and easy to reproduce, which is precisely what makes an unconfirmed report like this plausible on its face.

“NO INFO AS OF NOW WE HAVE A BUNCH OF PAX THAT WERE AT A CYBER CONFERENCE IN LAS THEY WERE ABLE TO JAM OUR WIFI AND BROADCAST THEIR SIGNAL.”

— the flight's pilots, via ACARS message, according to the "ACARS Drama" account