A cybersecurity incident unfolded on a Delta Air Lines flight from Las Vegas to Atlanta, following the world’s largest hacking conference. Crew members discovered that someone onboard had disrupted the plane’s official Wi-Fi network and created a fraudulent network aimed at deceiving passengers.
Details of the Incident
The situation on Delta Flight 591 emerged roughly an hour after takeoff from Harry Reid International Airport. The crew alerted corporate security to a passenger who had set up a fake Wi-Fi network named ‘Delta WiFi Fast.’ This network aimed to mislead passengers into connecting, potentially capturing sensitive information.
According to reports derived from Aircraft Communications Addressing and Reporting System (ACARS) messages, several passengers from the recent cybersecurity event in Las Vegas were capable of jamming the plane’s Wi-Fi and broadcasting their own signal. This activity occurred shortly after the conclusion of the Hacker Summer Camp, which includes major events like BSides, Black Hat, and DEF CON.
Technique and Response
Security experts identified the tactic as an ‘evil twin’ attack, where an attacker mimics a legitimate network to lure users into connecting. Once connected, passengers might encounter a fake portal designed to steal credentials, such as Google logins.
Social media discussions and private forums suggested the attackers might have used a portable auditing device, possibly a Wi-Fi Pineapple, to disconnect devices from the legitimate network before deploying their phishing page. Delta confirmed the presence of an unauthorized network but assured that no Delta systems were compromised.
Investigation and Community Reaction
In response, the cabin crew temporarily disabled the genuine passenger Wi-Fi as a precaution. Delta spokesperson Morgan Durrant emphasized that flight safety was never at risk, and essential aircraft systems remained unaffected. The airline is actively collaborating with federal authorities to investigate the incident, which involved 199 passengers and six crew members.
The cybersecurity community responded with strong criticism, labeling the act as highly irresponsible. Experts warned that such actions could violate the Communications Act and potentially lead to charges under the Computer Fraud and Abuse Act, given the deliberate disruption of authorized communications.
As the investigation continues, the Federal Aviation Administration has not received a formal report, and the FBI has yet to comment. The event serves as a stark reminder of the vulnerabilities of in-flight Wi-Fi networks and the risks associated with connecting to unfamiliar networks.
Travelers are advised to remain vigilant and avoid connecting to unexpected networks, even if they promise enhanced performance.
