A Delta Air Lines flight from Las Vegas to Atlanta was hit by an onboard rogue Wi-Fi incident after crew detected an unauthorized network impersonating the airline’s in-flight service. The fake SSID, reported as "Delta WiFi Fast", was suspected of being used in an evil twin phishing setup to lure passengers to a fraudulent captive portal, while crew messages also suggested possible interference with the legitimate onboard Wi-Fi. Delta said an unauthorized network was briefly broadcast on Flight 591, but stressed that no Delta systems, aircraft operating systems, or flight-safety functions were hacked or affected.
As a precaution, cabin crew disabled passenger Wi-Fi for about 30 minutes while the airline began an investigation with federal law enforcement and aviation regulators. Public reporting and security commentary pointed to possible deauthentication or Wi-Fi jamming activity, though those technical details were not confirmed by Delta. The incident, involving passengers returning from DEF CON, drew criticism from the security community because intentional interference with communications or attempts to steal credentials on a commercial flight could trigger liability under communications, fraud, identity-theft, and computer crime laws.

Get the infrastructure and lures behind it.
7 events from the most recent confirmed update back to the earliest known activity.
The FBI Atlanta field office said it was aware of reports of a potential Wi‑Fi-related incident involving Delta Flight 591 and was in contact with local and corporate partners. The bureau also said no arrests were made and that FBI agents did not meet the aircraft at the gate.
After Flight 591 arrived in Atlanta, authorities boarded the aircraft following the onboard rogue Wi-Fi incident. The FBI Atlanta field office and the FAA said they were aware of the matter, while Delta said it would work with federal law enforcement and aviation regulators.
As of Tuesday, the Federal Aviation Administration said it had not yet received an official report about the onboard Wi-Fi incident. The FBI had not publicly commented at that time.
Delta confirmed that an unauthorized Wi-Fi network was briefly active onboard but said no Delta systems, in-flight Wi-Fi infrastructure, or aircraft operating systems were hacked or affected. The airline said it was investigating and would work with federal law enforcement and aviation regulators.
After detecting the unauthorized onboard network, cabin crew shut off the aircraft's legitimate passenger Wi-Fi for roughly 30 minutes as a precaution.
A person claiming to be onboard said the fake 'Delta WiFi Fast' network presented a phishing landing page designed to steal passengers' personal credentials and Google login data. The report also said the attacker may have used deauthentication techniques to push devices toward the rogue network.
During Delta Air Lines Flight 591 from Las Vegas to Atlanta, crew reported that a passenger created a rogue Wi-Fi network named "Delta WiFi Fast," and follow-up ACARS messages said several passengers returning from a cyber conference may have jammed the aircraft's legitimate Wi-Fi while broadcasting their own signal.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
16 references tracked. Mallory keeps watching after this page renders.
cyberveille.ch
Open sourceitpro.com
Open sourcetomshardware.com
Open sourcexakep.ru
Open sourcereddit.com
Open sourcereddit.com
Open sourceapp.airframes.io
Open sourcedocs.fcc.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.