A group of hackers attending the DEF CON 34 convention in Las Vegas took their skills on the road, allegedly orchestrating a Wi-Fi deauthentication attack mid-flight on a Delta Air Lines aircraft carrying passengers from the conference. The incident has raised concerns about the potential for airborne cyber threats and the measures airlines take to prevent them.
The unauthorized wireless network appeared onboard Flight 591, which was traveling from Las Vegas to Atlanta with six crew members and 199 passengers. According to reports, several passengers were able to connect to a rogue Wi-Fi network named “Delta WiFi Fast,” which was broadcasting a phishing page that collected personal credentials and Google login data. The cabin crew quickly responded by deactivating the in-flight Wi-Fi for nearly 30 minutes.
A Wi-Fi deauthentication attack involves sending forged packets pretending to be from the legitimate access point, telling connected clients to disconnect. This can cause a denial-of-service condition, where clients are repeatedly disconnected from the access point and forced to reconnect to a rogue network. By understanding how this type of attack works, it’s clear that the hackers on Flight 591 were attempting to intercept traffic or direct passengers to malicious pages.
The incident has sparked an investigation by Delta Air Lines in partnership with federal law enforcement and aviation regulators. The airline emphasized that no safety issues were raised during the flight, but the unauthorized Wi-Fi network was present for a short time. This raises questions about the measures airlines take to prevent airborne cyber threats and whether more needs to be done to protect passengers from rogue networks.
The use of Protected Management Frames (PMF) can mitigate spoofed management-frame attacks like deauthentication. However, it’s unclear if Delta Air Lines uses this technology on its aircraft. The incident serves as a reminder that airborne cyber threats are real and can have serious consequences.
In the wake of this incident, passengers are advised to be cautious when connecting to in-flight Wi-Fi networks. It’s essential to verify the network’s authenticity and avoid sharing sensitive information through unsecured connections. Airlines should also take steps to educate passengers about the risks associated with airborne cyber threats and implement robust security measures to prevent such incidents in the future.
As the cybersecurity landscape continues to evolve, it’s crucial for airlines and regulators to work together to address airborne cyber threats. The incident on Flight 591 serves as a wake-up call for both industries to prioritize passenger safety and security in the face of emerging cyber risks.
Source: Bleeping Computer — 2026-08-11