Delta flight carrying DEF CON “hackers” hit by Wi-Fi attack mid-air
Crew messages warned a fake “Delta WiFi Fast” network was targeting passengers.

Delta Air Lines flight takes off from Las Vegas. Image by Janice Chen | Shutterstock
- A Delta flight returning from DEF CON was reportedly hit by a Wi-Fi phishing attack involving a fake network.
- Crew messages warned someone was jamming onboard Wi-Fi and broadcasting “Delta WiFi Fast” to allegedly scam passengers.
- Federal authorities reportedly boarded the aircraft in Atlanta after landing to investigate the suspected attack.
A Delta flight returning from DEF CON 34 is hit by a rogue Wi-Fi attack mid-air – jamming the plane's network to broadcast a fake “Delta WiFi Fast” signal – all to steal passenger credentials.
It’s never a dull moment for those attending “hacker summer camp” in Las Vegas – and capping off this year’s DEF CON 34 is certainly no exception.
Delta Flight 591 was on its way from Las Vegas to Atlanta on Monday, one day after the annual hacker convention wrapped up in Sin City.
That’s when, apparently, Delta crew members became aware that someone – or something – was disrupting Delta’s legitimate onboard Wi-Fi while simultaneously broadcasting a rogue network designed to look like the airline’s service.
Rogue ‘Delta WiFi’ network appears mid-flight
According to Delta passenger reports, a group heading home from the cybersecurity convention allegedly used a portable network hacking tool – think Wi-Fi Pineapple – to launch a mid-air "de-authentication" attack.
The bad actor, after kicking passengers offline, began to broadcast “a malicious clone network,” naming it “Delta WiFi Fast."
Those same reports claim “the fake hotspot served up a phishing landing page designed to harvest passengers' personal credentials and Google login data, prompting the captain to send an emergency ACARS alert to the ground.”
(ACARS is the digital communications system used by aircraft to exchange short messages with airlines and ground operations.)
Ross Filipek, CISO at Corsica Technologies, tells Cybernews that a Wi-Fi deauthentication attack essentially forces connected devices – such as your laptop, smartphone, or smartwatch – off a valid wireless network.
“A Wi-Fi deauthentication attack is basically a forced disconnect. An attacker sends fake management frames that tell devices to drop off a legitimate wireless network,"Filipek said.
Authorities board Delta flight in Atlanta
Intercepted cockpit messages posted online by aviation account Turbine Traveller appear to show the pilots alerting ground operations to the suspected attack while the aircraft was still in flight.
“We have a bunch of pax that were at a cyber conference in Las [Vegas]. They were able to jam our WiFi and broadcast their signal,”one Delta pilot wrote in a message sent on the Aircraft Communications Addressing and Reporting System (ACARS).
A second message appears to show the pilots escalating the incident to Delta corporate security.
“We have a pax on this [flight who] has created a scam WiFi called Delta WiFi Fast. We believe they are trying to scam the other pax,” the pilot said.
Calling it a “wild scene” unfolding at Atlanta's Hartsfield-Jackson International Airport (ATL), one supposed eyewitness claimed on X that as soon as the plane docked at its gate, federal authorities and airport police wasted no time.
They immediately boarded the aircraft, holding the cabin, questioning the suspects, and seizing the broadcasting hardware, the person reported.
But exactly who was responsible for the airborne attack remains unclear. There is also no indication that the aircraft’s flight systems or passenger safety were compromised.
So far Delta has not publicly commented about the cyber incident. Cybernews has reached out to Delta Air Lines for confirmation.
How a "Wi-Fi deauth" attack targets passengers
“Incidents like this are a reminder that convenience can create trust very quickly. Public Wi-Fi depends on users recognizing the right network. Attackers can take advantage when that trust gets misplaced,” Filipek says.
And even though getting kicked off your wifi mid-flight is disruptive, Filipek says the bigger concern is what happens next.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
After being dropped from the real network, Filipek says attackers – as alleged in this case – often attempt to lure unsuspecting users onto a fake WiFi network created for malicious purposes.
“Once users are kicked offline, some may reconnect to a rogue network that looks legitimate. That creates an opening for credential theft or phishing,” he says.
However, Filipek also stressed that none of that means the aircraft itself was in danger.
“The risk is much more personal and quieter. Travelers may expose passwords or sensitive account information without realizing anything is wrong,” he said.
Check if your data has been leaked