Skip to content

The Dumbest Post-DEF CON Wi-Fi Stunt of the Year

Someone broadcast a fake Delta Wi-Fi network on a flight home from DEF CON, prompting an investigation, a flood of online commentary and one painfully obvious lesson.

Someone broadcast a fake Delta Wi-Fi network aboard a flight packed with people returning from DEF CON. The cybersecurity community's response has been about what you'd expect.

It took me a few hours to write anything about the apparent Wi-Fi shenanigans aboard a Delta flight from Las Vegas to Atlanta because I've watched this movie too many times.

Something happens. Social media catches fire. Every repost adds another detail. Someone was spoofing Wi-Fi. No, they were jamming it. No, they were de-authing everyone. They built a phishing portal. Federal agents stormed the plane. The engines were probably next.

Give it a few hours and suddenly someone with a Wi-Fi Pineapple is Hans Gruber.

So I waited.

The other reason I waited is simpler: There are only so many ways to say someone was being stupid.

Full coverage of Hacker Summer Camp:

Hacker Summer Camp 2026: Complete Black Hat, BSidesLV, Ai4 & DEF CON Coverage
The CYBR.SEC.Media crew is in Las Vegas to bring you all the insights coming from this week’s proceedings.

Messing with Wi-Fi aboard a commercial aircraft — particularly on a flight home from DEF CON, surrounded by cybersecurity professionals — falls into a category of stupid that doesn't require much technical analysis.

Instead, here's some of my favorite reporting and commentary on the incident:

Matt Johansen gets first crack

Matt Johansen of Vulnerable U had one of my favorite reactions, in part because he approached the story with the appropriate mixture of cybersecurity knowledge and disbelief.

His commentary cuts through what is already becoming an unnecessarily complicated discussion about tooling and techniques. Whether somebody was running a Wi-Fi Pineapple, spoofing an SSID, attempting de-authentication or doing something else is obviously relevant to investigators. For the rest of us? The larger lesson is considerably less sophisticated:

Don't screw with the Wi-Fi on an airplane. Especially one filled with hackers flying home from DEF CON.

There. Saved you a SANS course.

Johansen's commentary:

Don’t do this
Bekijk je favoriete video’s, luister naar de muziek die je leuk vindt, upload originele content en deel alles met vrienden, familie en anderen op YouTube.

What we actually know

This is where The Register's Brandon Vigliarolo did everyone a favor by separating some of the emerging facts from the social-media telephone game.

The incident involved Delta Flight 591 from Las Vegas to Atlanta. ACARS messages circulating online indicated the crew believed someone aboard had created a suspicious network called "DELTA WIFI FAST." One message initially suggested passengers had "jammed" the aircraft's Wi-Fi.

But Delta subsequently told The Register that nobody hacked Delta's systems or its in-flight Wi-Fi. The airline confirmed that an unauthorized Wi-Fi network was broadcast aboard the aircraft for a short period. The crew turned off the legitimate in-flight Wi-Fi for about 30 minutes while dealing with the situation, which could account for some of the early reports that someone had knocked the network offline. Delta also said aircraft systems were never affected and passenger safety was never in question.

That's a considerably more grounded description than some of what ricocheted around social media Tuesday morning.

The Register nevertheless landed on perhaps the finest headline of the day:

"DEF CON dingus suspected of trying to take over Delta in-flight Wi-Fi."

Article from The Register:

DEF CON dingus suspected of trying to take over Delta in-flight Wi-Fi
This is why we can’t have nice things, people

The airplane itself was talking

One reason this story exploded was that aviation geeks were watching the aircraft's ACARS traffic.

An archived message attributed to the flight crew warned corporate security about a passenger who had allegedly created a "SCAM WIFI CALLED DELTA WIFI FAST" and said they believed the network was intended to scam other passengers.

A later message blamed passengers returning from a cybersecurity conference in Las Vegas. Again, those messages reflect what the crew believed was happening at the time, not the final forensic findings. That's an important distinction given how quickly "the crew suspects something" became "here's exactly how the hack worked" online.

See the Airframes ACARS archive:

Airframes — Beyond ADS-B Tracking
Real-time ACARS, VDLM2, HFDL, and SATCOM aviation message tracking. Beyond ADS-B aircraft monitoring with live decoded messages from ground stations worldwide.

And then the Internet did its thing

The reactions across aviation and cybersecurity social media have been considerably more entertaining than another 800 words from me explaining evil-twin attacks.

That's really the point.

Experienced cybersecurity professionals do not need a lecture about why firing up rogue access points, spoofing networks or deliberately interfering with wireless communications aboard a commercial aircraft is a profoundly bad idea.

We have known this stuff forever.

You also don't get bonus hacker points because you did it while flying home from DEF CON. If anything, choosing an aircraft presumably loaded with security practitioners may qualify as one of history's less promising approaches to avoiding detection.

There are plenty of places to experiment. Labs exist. CTFs exist. DEF CON itself exists.

A commercial airplane carrying a couple hundred people is not your lab.

Congratulations, you became the post-DEF CON story

That's the part that annoys me.

Tens of thousands of people descended on Las Vegas for Hacker Summer Camp. Researchers shared new work. People taught each other. Communities came together. Security professionals spent a week demonstrating what is best about this industry.

And then everybody flies home. One person apparently decides that somewhere around 35,000 feet is the appropriate venue for Wi-Fi stupidity.

And guess what we're talking about now?

Well done.

HOU.SEC.CON CTA

Latest