Skip to main content
Emerging Threats

Delta Investigates Wi-Fi Deauth Attack Onboard Flight with DEF CON Attendees

Airplane cabin with passengers and crew, laptop and smartphone on a tray table.

“We will partner with federal law enforcement and aviation regulators to ensure the incident is thoroughly investigated,” a Delta Air Lines spokesperson told BleepingComputer after passengers aboard Flight 591 reported an unauthorized onboard Wi‑Fi network and interruptions to the aircraft’s in‑flight wireless service.

Delta Air Lines' account and immediate actions

Delta said the event occurred on Flight 591, a Boeing 757 operating from Las Vegas to Atlanta, and that the incident “did not affect the safety of the passengers or aircraft operating systems.” The airline confirmed the aircraft carried six crew members and 199 passengers and that no emergency was declared with air traffic control. After crew members became aware of an unauthorized wireless network onboard, they deactivated the aircraft’s Wi‑Fi functionality for nearly 30 minutes.

What the crew reported via ACARS and what passengers saw

Messages relayed by an aircraft technician using the name Turbine Traveller indicate crew communications on the Aircraft Communications Addressing and Reporting System (ACARS) stated: “WE HAVE A BUNCH OF PAX [passenger] THAT WERE AT A CYBER CONFERENCE IN LAS… THEY WERE ABLE TO JAM OUR WIFI AND BROADCAST THEIR SIGNAL.” ACARS messages quoted by Turbine Traveller added: “WE HAVE A PAX ON THIS HAS CREATED A SCAM WIFI CALLED DELTA WIFI FAST. WE BELIEVE THEY ARE TRYING TO SCAM THE OTHER PAX.”

Mary Perrault, identified as a member of online frequent flyer groups with no formal affiliation to Delta, said the fake Wi‑Fi network displayed a phishing page that collected “personal credentials and Google login data.” Perrault also reported that, after the aircraft docked, federal authorities and airport police boarded and questioned suspects and seized portable Wi‑Fi hardware, saying the suspects had been attending the DEF CON 34 hacker conference in Las Vegas.

How a Wi‑Fi deauthentication attack works

BleepingComputer’s report described the incident as a Wi‑Fi deauthentication attack. In this type of attack, clients connected to a wireless network receive forged packets that pretend to come from the legitimate access point and instruct those clients to disconnect. An attacker can observe wireless traffic to identify the access point’s MAC address, then forge deauthentication frames using the AP’s address as the source and send them to connected clients.

By repeatedly transmitting forged deauthentication frames, the attacker can continuously disconnect clients from the legitimate access point, potentially causing a denial‑of‑service condition. The report notes that networks that use Protected Management Frames (PMF) can mitigate spoofed management‑frame attacks. Attackers who force disconnections commonly attempt to steer victims to rogue access points—so‑called “evil twin” networks—to intercept traffic or present malicious pages.

Federal law enforcement, regulators, and Delta’s next steps

Delta told BleepingComputer it will “partner with federal law enforcement and aviation regulators to ensure the incident is thoroughly investigated.” The airline’s statement framed the unauthorized network as “not provided, operated, or supplied by Delta,” and described the network as present onboard “for a short time during the flight.” Delta’s decision to disable onboard Wi‑Fi for roughly half an hour was presented as an operational response intended to limit further disruption.

What this means for technologists, airline crews, and passengers

  • Technologists and security teams: The deauthentication technique described in the report underscores the specific value of protections such as Protected Management Frames (PMF) in reducing spoofed management‑frame attacks and the downstream risk that users will be steered to rogue networks or phishing pages.
  • Airline crews and operations teams: Cabin crew response here included disabling Wi‑Fi for nearly 30 minutes and notifying authorities; ACARS messages shown in the account were used to describe the onboard situation and an alleged scam network named “Delta WiFi Fast.” Crews and operations centers will likely review procedures for handling reported wireless interference and suspected onboard fraud.
  • Passengers and airport authorities: According to the report, some passengers who had attended DEF CON 34 were identified in crew messages and by a passenger observer; airport police and federal authorities boarded after landing to question suspects and seize portable Wi‑Fi hardware, per passenger reporting.

Delta’s statement, the ACARS messages quoted by an aircraft technician, and passenger reports form a compact record: an unauthorized Wi‑Fi network appeared, cabin crew deactivated onboard wireless for a period, and law enforcement boarded after arrival. The airline has signaled a formal investigation with regulators and investigators; the public record provided to BleepingComputer leaves the next steps to those ongoing inquiries.

Original BleepingComputer report