ATLANTA– Delta Air Lines (DL) is investigating an alleged cybersecurity incident after passengers on Flight DL591 reportedly broadcast a fake Wi Fi network while traveling from Las Vegas Harry Reid International Airport (LAS) to Hartsfield-Jackson Atlanta International Airport (ATL).
The alleged incident occurred during the flight from Las Vegas (LAS) to Atlanta (ATL), with the crew notifying Delta Air Lines (DL) operations through the aircraft’s ACARS messaging system. The airline said flight safety was never compromised, and no aircraft systems were affected.

Delta Investigates Alleged Fake Wi Fi Network on Flight
Delta Flight DL591 departed Las Vegas Harry Reid International Airport (LAS) at approximately 8:30 a.m. on Monday after an overnight delay from Sunday.
During the three-and-a-half-hour flight to Hartsfield Jackson Atlanta International Airport (ATL), several passengers who had reportedly attended the Def Con 34 cybersecurity conference in Las Vegas allegedly created and broadcast a fake wireless network that closely resembled Delta’s official onboard Wi Fi service.
According to PYOK, the flight crew became aware of the issue while the aircraft was en route and quickly informed Delta’s Operations Control Center in Atlanta using the Aircraft Communications Addressing and Reporting System (ACARS). This secure text messaging system enables pilots to communicate with airline operations when other communication channels are unavailable.
One of the ACARS messages reportedly stated that several passengers from the cybersecurity conference had managed to jam the aircraft’s Wi Fi and broadcast their own signal.
In a follow-up message, the pilots warned Delta’s corporate security team that a passenger had created a fake network named “Delta WiFi Fast,” which they believed was intended to deceive other travelers.

Crew Disabled Onboard Internet During Investigation
As the crew assessed the situation, Delta temporarily disabled the aircraft’s onboard Wi Fi service for approximately 30 minutes. The airline later clarified that its official Wi Fi system was not hacked or compromised.
Following the aircraft’s arrival in Atlanta, law enforcement officers reportedly boarded the aircraft and questioned several passengers regarding the alleged incident. However, there has been no confirmation that any arrests were made.
In a statement, a Delta spokesperson told PYOK:
Safety of flight was never in question and no aircraft operating systems were affected. We are fully investigating to gather a complete set of facts, which will take time.”
The airline added that it would cooperate with federal law enforcement agencies and aviation regulators to ensure a thorough investigation while thanking the crew for their professionalism and passengers for their patience.

What Is an Evil Twin Wi Fi Attack?
The alleged incident resembles a cyberattack commonly known as an evil twin attack.
In this type of attack, a malicious actor creates a fake wireless network that appears nearly identical to a legitimate Wi Fi service. Unsuspecting users may connect to the fraudulent network, believing it to be authentic.
Once connected, victims can be directed to counterfeit login pages designed to capture sensitive information such as email addresses, usernames, passwords, and in some cases, payment card details. The technique does not require compromising the aircraft’s operational systems, but instead targets passenger devices connected to the fake network.
Cybersecurity experts have long warned that public Wi Fi environments remain attractive targets because travelers often connect without carefully verifying the network’s authenticity.

Similar Cases Have Occurred Before
This is not the first reported case involving an alleged fake onboard Wi Fi network.
In 2024, Australian Federal Police arrested 42-year-old Michael Clapsis after accusing him of using a portable wireless access device to imitate the legitimate onboard Wi Fi service during a domestic Qantas (QF) flight. Investigators alleged that the fake network was designed to collect passenger credentials after travelers connected to it.
The investigation began after a flight attendant became suspicious of unusual activity onboard and alerted the airline. Authorities later expanded the investigation and uncovered what they described as a much larger cybercrime operation. Clapsis was eventually sentenced to seven years in prison.
Another well-known aviation cybersecurity case occurred in 2015 when United Airlines (UA) passenger Chris Roberts was accused by the FBI of accessing an aircraft’s inflight entertainment system.
Investigators alleged that Roberts connected an Ethernet cable directly to hardware located beneath his seat rather than using the aircraft’s Wi Fi network.
The case generated significant attention within the aviation industry, although the claims surrounding access to flight control systems have remained widely debated.

Delta Continues Investigation
Delta has emphasized that the alleged incident did not affect the aircraft’s operational systems or the safety of the flight. The airline is continuing its investigation in coordination with federal authorities and aviation regulators to determine exactly what occurred onboard Flight DL591.
The incident also highlights the growing importance of cybersecurity awareness during air travel, particularly as airlines continue expanding onboard connectivity services for passengers worldwide.
Stay tuned with us. Further, follow us on social media for the latest updates.
Join us on Telegram Group for the Latest Aviation Updates. Subsequently, follow us on Google News
