Delta flight carrying DEF CON “hackers” hit by Wi-Fi attack mid-air
Delta confirms “unauthorized” Wi-Fi network, but says no airline systems were compromised.

Delta Air Lines flight takes off from Las Vegas. Image by Janice Chen | Shutterstock
- A Delta flight returning from DEF CON was reportedly hit by a Wi-Fi phishing attack involving a fake "evil twin" network.
- Crew messages warned someone was jamming onboard Wi-Fi and broadcasting “Delta WiFi Fast” to allegedly scam passengers.
- Federal authorities reportedly boarded the aircraft in Atlanta after landing to investigate the suspected attack.
- Delta says flight safety was never in question and is now fully investigating the incident.
A Delta flight returning from DEF CON 34 is hit by a rogue Wi-Fi attack mid-air – jamming the plane's network to broadcast a fake “Delta WiFi Fast” signal – all to steal passenger credentials. Delta has now confirmed the incident to Cybernews as new details emerge.
It’s never a dull moment for those attending “hacker summer camp” in Las Vegas – and capping off this year’s DEF CON 34 is certainly no exception.
Delta Flight 591 was on its way from Las Vegas to Atlanta on Monday, one day after the annual hacker convention wrapped up in Sin City.
That’s when, apparently, Delta crew members became aware that someone – or something – was disrupting Delta’s legitimate onboard Wi-Fi while simultaneously broadcasting a rogue network designed to look like the airline’s service.
In a statement sent to Cybernews, Delta Air Lines spokesperson Taylor Dahl confirmed the August 10th mid-flight melee, although they did not reveal whether any arrests have been made.
“Safety of flight was never in question and no aircraft operating systems were affected. We are fully investigating to gather a complete set of facts, which will take time. We will partner with federal law enforcement and aviation regulators to ensure the incident is thoroughly investigated. We thank our crew for their professionalism and our customers for their understanding.”– Delta Air Lines spokesperson
Rogue ‘Delta WiFi’ network appears mid-flight
According to Delta passenger reports, a group heading home from the cybersecurity convention allegedly used a portable network hacking tool – think Wi-Fi Pineapple – to launch a mid-air "de-authentication" attack.
The bad actor, after kicking passengers offline, began to broadcast “a malicious clone network,” naming it “Delta WiFi Fast."
Those same reports claim “the fake hotspot served up a phishing landing page designed to harvest passengers' personal credentials and Google login data, prompting the captain to send an emergency ACARS alert to the ground.”
(ACARS is the digital communications system used by aircraft to exchange short messages with airlines and ground operations.)
Ross Filipek, CISO at Corsica Technologies, tells Cybernews that a Wi-Fi deauthentication attack essentially forces connected devices – such as your laptop, smartphone, or smartwatch – off a valid wireless network.
A Wi-Fi deauthentication attack is basically a forced disconnect. An attacker sends fake management frames that tell devices to drop off a legitimate wireless network,Filipek said.
Authorities board Delta flight in Atlanta
Intercepted cockpit messages posted online by aviation account Turbine Traveller appear to show the pilots alerting ground operations to the suspected attack while the aircraft was still in flight.
We have a bunch of pax that were at a cyber conference in Las [Vegas]. They were able to jam our WiFi and broadcast their signal,one Delta pilot wrote in a message sent on the Aircraft Communications Addressing and Reporting System (ACARS).
A second message appears to show the pilots escalating the incident to Delta corporate security.
“We have a pax on this [flight who] has created a scam WiFi called Delta WiFi Fast. We believe they are trying to scam the other pax,” the pilot said.
Calling it a “wild scene” unfolding at Atlanta's Hartsfield-Jackson International Airport (ATL), one supposed eyewitness claimed on X that as soon as the plane docked at its gate, federal authorities and airport police wasted no time.
They immediately boarded the aircraft, holding the cabin, questioning the suspects, and seizing the broadcasting hardware, the person reported.
Delta confirms unauthorized Wi-Fi network
Exactly who was responsible for the airborne attack remains unclear.
Delta says the Boeing 757 aircraft was carrying six crew members and 199 customers, taking off Monday around 8:30 a.m. PDT from Harry Reid International Airport in Las Vegas after a 16-hour delay.
Ironically, some DEF CON passengers also reported being rebooked on DL591 after an earlier Sunday flight was delayed for 20 hours before eventually being canceled.
Dalh told Cybernews the cabin crew was forced to “deactivate the aircraft’s WiFi functionality for approximately 30 minutes” while up in the air.
Reiterating that neither the aircraft’s flight systems nor passenger safety were compromised, the Delta spokesperson also stressed that “there was no hack of any Delta system, including the in-flight WiFi.”
The airline, which is now working with federal authorities, acknowledged one initial finding:
“An unauthorized WiFi network, which was not provided, operated, or supplied by Delta, was present onboard the aircraft for a short time during the flight.”– Delta Air Lines spokesperson
To note, Federal law prohibits the deliberate interference of authorized radio signals, which includes intentionally jamming the aircraft’s wireless communications.
According to the Federal Communications Commission (FCC), violations can result in substantial fines, seizure of illegal jamming equipment, and other enforcement action.
Rep says DEF CON 34 hit by similar Wi-Fi attacks
Apparently, the trouble may have started before passengers ever boarded Flight 591.
Monika Hathaway, head of press for DEF CON, told CyberScoop on Tuesday that neither Delta nor federal authorities had contacted the organization about the incident.
However, she said this August’s conference was hit by similar attacks.
“Our conference this year also suffered from multiple similar ‘deauthorization’ Wi-Fi attacks and it impacted some of our operations,”Hathaway said.
“Our conference this year also suffered from multiple similar ‘deauthorization’ Wi-Fi attacks and it impacted some of our operations,” Hathaway said.
“If we had caught them doing this at DEF CON we would have removed and banned them from the conference,” she added.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
How a "Wi-Fi deauth" attack targets passengers
“Incidents like this are a reminder that convenience can create trust very quickly. Public Wi-Fi depends on users recognizing the right network. Attackers can take advantage when that trust gets misplaced,” Filipek says.
And even though getting kicked off your wifi mid-flight is disruptive, Filipek says the bigger concern is what happens next.
After being dropped from the real network, Filipek says attackers – as alleged in this case – often attempt to lure unsuspecting users onto a fake WiFi network created for malicious purposes.
“Once users are kicked offline, some may reconnect to a rogue network that looks legitimate. That creates an opening for credential theft or phishing,” he says.
It’s also not the first time DEF CON and Black Hat attendees have been preemptively accused of questionable behavior.
Traditionally held during the same week, attendees at both hacker camps are explicitly warned to use a VPN and connect only to official conference Wi-Fi networks due to risks of data theft from fellow attendees.
In fact, in 2024, Hilton’s Resorts World Las Vegas – a popular hotel for attendees – announced a first-of-its-kind policy to subject all hotel guests to mandatory “search-and-seizure-style” room checks.
The invasive policy – igniting a firestorm of condemnation among attendees – was described by the hotel as necessary to protect itself from hacker convention antics and “potentially malicious” objects, such as routers and other networking equipment.
Check if your data has been leaked