You land at the airport, your phone battery is at 30%, and the first thing you do is hunt for free Wi-Fi. It feels harmless. It feels routine. Yet security experts and law enforcement agencies have been sounding alarm bells with increasing urgency, because that instinct to connect may be exactly what cybercriminals are counting on. The threat is no longer theoretical – it’s happening on active flights, in terminal lounges, and at boarding gates around the world. The scarier part? The security setting that could protect you most is often switched off by default.
The “Evil Twin” Attack: A Very Real Threat in Airport Terminals

Internet “evil twin” attacks are stalking airport Wi-Fi connections, and the cybercriminals behind these rising attacks are rarely caught. What cybersecurity experts refer to as “evil twin” attacks are on the rise, specifically targeting public Wi-Fi in airports and coffee shops. The name sounds like something from a thriller movie, but the mechanics are straightforward and brutally effective. Evil twinning occurs when a hacker or hacking group sets up a fake Wi-Fi network, most often in public settings where many users can be expected to connect.
An evil twin hotspot is a wireless network that impersonates a legitimate one by copying its name, also known as the SSID. When multiple networks with the same name exist, your phone or laptop often connects to the one with the stronger signal – which is usually the attacker’s. Once you’re in, the damage begins fast. Once you connect, everything you send – emails, passwords, credit card details – could be intercepted. You think you’re surfing safely, but you’re not.
It Already Happened – And the Arrest Was the Unusual Part

An Australian man was charged in May 2024 following an investigation launched in April 2024, after an airline reported a suspicious Wi-Fi network during a domestic flight. Investigators found a portable wireless access device, a laptop, and a mobile phone. The man was charged with carrying out evil twin Wi-Fi attacks during a domestic flight to steal user credentials and data. The operation was more extensive than just one flight. AFP cybercrime investigators collected evidence indicating the use of fraudulent Wi-Fi pages at airports in Perth, Melbourne, and Adelaide, on domestic flights, and at locations associated with the man’s previous employment.
Travelers connected, saw what looked like a login page from the airline or terminal, and handed over their email or social credentials. Dozens did, before staff caught on and flagged the rogue SSIDs. The case sent shockwaves across the cybersecurity world – not because the attack was novel, but because an arrest was made at all. As Aaron Walton, threat analyst at Expel, noted, “This incident isn’t unique, but it is unusual that the suspect was arrested. Generally, airlines are not equipped and prepared to handle or mediate hacking accusations.” The typical lack of arrests and punitive action, he added, should motivate travelers to exercise caution with their own data.
The Numbers Show Just How Exposed Travelers Really Are

A 2023 Forbes Advisor survey found that 40% of travelers had their security compromised while using public Wi-Fi. That’s a staggering proportion – nearly half of all travelers who connect to public networks have experienced some form of security incident. A 2025 Panda Security survey found that 36% of Americans at least suspect they had a security incident after using public Wi-Fi, with 19% being certain they did.
Over 5 million public unsecured global Wi-Fi networks were found since the beginning of 2025, with roughly one in three users connecting to public unsecured networks. The scale of the exposure is enormous. Only one in five Americans – about 20% – are “very confident” they could identify false Wi-Fi networks. Meanwhile, the miniaturization of the digital twinning technology has made this kind of cyberattack more appealing to hackers, with the technology to pull it off available for less than $500.
The Setting That’s Most Likely Turned Off on Your Phone

Auto-join is a feature that allows your phone to automatically join any Wi-Fi network it already has credentials for, or open Wi-Fi networks, without asking you to do anything. This can be a time-saver at home and at work. But it carries significant risks when used with public Wi-Fi networks. Specifically, when you automatically join open public Wi-Fi networks, you put your data and privacy at risk. You don’t know that the network is secure. You could be joining a clever network clone that is really a man-in-the-middle cyberattack trying to steal your passwords and usernames to sensitive accounts.
Disabling automatic Wi-Fi connection on your devices avoids connecting to untrusted networks unintentionally. On iPhone, the fix is straightforward. You can tap the circled “i” on the right of any network to turn off auto-join. You can also change the default setting of your iPhone asking if you want to join unknown networks – outside of the default “Ask,” you can set it to “Notify” you about available networks, or turn it “Off,” which will have you manually select and join all networks. On Android, enabling “Ask to join networks” instead of auto-connect prevents your phone from jumping onto a fake hotspot just because it shares a name.
How a VPN Fills the Gap Your Phone Settings Can’t Fully Cover

A Virtual Private Network (VPN) encrypts your internet traffic before it leaves your device. That means even if you’re on a hostile network, what attackers see is just encrypted gibberish heading to a VPN server somewhere else. This is the core reason security professionals consistently point to VPNs as the most reliable layer of protection. A VPN adds protection beyond your phone’s built-in or app-level encryption. Instead of just securing stored data or chats, it encrypts all the traffic leaving your phone – and this is especially important on public Wi-Fi, where attackers might try to snoop on your activity.
Not all VPNs are equal, though, and this matters. Security experts strongly advise against using free VPNs, because they are often unreliable and may compromise your privacy. Most free VPN providers monetize their activities by collecting your data, passing it on to third parties, and using that data to serve targeted ads. These VPNs also have limited functionality and are prone to data breaches. One of the best defenses against rogue Wi-Fi is a VPN. A VPN creates an encrypted tunnel between your device and the internet, making it far harder for attackers to intercept your data, even if you connect to the wrong hotspot. Pairing a reputable paid VPN with manual Wi-Fi connection settings gives you a meaningful, layered defense the next time you’re sitting in a departure lounge waiting to board.






