Cybersecurity experts are warning that so-called “evil twin” attacks on planes and other publicly-accessible Wi-Fi systems can create an overlooked attack surface for connected devices, after passengers returning from a hacking conference in Las Vegas apparently made a rogue network appear on a Delta Air Lines flight.
According to Delta Airlines, an unauthorised Wi-Fi network appeared on its flight DL591 from Las Vegas to Atlanta on August 10, prompting the crew to disable the aircraft’s Wi-Fi functionality for around 30 minutes.
The airline stressed that there was no hack of its aircraft systems and that flight safety was never at risk. It is investigating the incident with federal law enforcement and aviation regulators.
Messages reportedly sent by the flight crew through the Aircraft Communications Addressing and Reporting System (ACARS) stated that a passenger had created a network called “DELTA WIFI FAST” and that the crew believed it was being used to scam other passengers.
“An evil twin attack is when hackers create fake Wi-Fi networks with the goal of stealing sensitive information from people, or exploiting known vulnerabilities present in victim devices,” said Aras Nazarovas, Senior Information Security Researcher at Cybernews.
The networks can use names that are identical or very similar to legitimate services. Once a victim connects, an attacker may be able to inspect aspects of their traffic, probe their device for vulnerabilities or redirect them to malicious websites – risks that become particularly relevant as more devices depend on wireless connectivity without continuous human oversight.
“The risk here is that the hacker may attempt to redirect the victim to a phishing website,” Nazarovas said.
The incident raises a broader question for the IoT industry: what happens when a connected device cannot reliably distinguish between a legitimate network and a malicious one? As IoT deployments expand across vehicles, buildings, industrial environments and other physical infrastructure, devices increasingly operate across networks that are outside the manufacturer’s direct control. Asset trackers, robots, or an industrial devices may encounter wireless networks that appear legitimate but cannot necessarily be trusted.
“Connecting to a network controlled by a threat actor allows them to probe your device for potential vulnerabilities and maliciously redirect your internet traffic to their own servers,” Nazarovas said.
There’s plenty of other editorial on our sister site, Electronic Specifier! Or you can always join in the conversation by visiting our LinkedIn page.
