Skip to main content
CybersecurityHacking

Delta Probes In-Flight Wi-Fi Spoofing Incident on Las Vegas Flight

Passenger holds small device, possibly a Wi-Fi hotspot, on plane with blurred travelers in background.

"We are fully investigating to gather a complete set of facts, which will take time," Morgan Durrant, a Delta spokesperson, told CyberScoop.

Delta Flight 591: what the crew reported

Passengers on Delta flight 591 from Las Vegas to Atlanta reported that a fellow traveler deployed an unidentified device that created a hotspot named "Delta WiFi Fast." Messages from the plane's Aircraft Communications Addressing and Reporting System (ACARS) show the crew informed personnel on the ground that a passenger set up the network and was "trying to scam the other passengers." The incident delayed the flight — originally scheduled for Sunday but which did not depart Las Vegas until 8:30 a.m. Monday — and authorities boarded the aircraft once it arrived at its destination.

Evil twin attacks: how the spoof likely worked

The episode "bears the hallmarks of an 'evil twin attack,'" the reporting notes. In that technique an attacker deploys a rogue Wi‑Fi access point that masquerades as a legitimate, trusted network by cloning its name and network settings. Such attacks are often paired with deauthentication operations that force devices off the real network, then rely on phones and laptops to automatically connect to the fraudulent hotspot. Once devices attach, an attacker can monitor unencrypted traffic, perform man‑in‑the‑middle operations, or present spoofed login portals intended to harvest credentials and personal data.

Delta's mitigation and law enforcement awareness

On the flight, the cabin crew deactivated the aircraft's Wi‑Fi functionality for approximately 30 minutes; Delta told CyberScoop that the flight's safety was never in question and that no aircraft operating systems were affected. Delta said it will "partner with federal law enforcement and aviation regulators to ensure the incident is thoroughly investigated." The Atlanta office of the FBI, along with the Federal Aviation Administration, said they were aware of the incident but declined further comment. The Transportation Security Administration and Homeland Security Investigations did not respond to requests for comment.

DEF CON's reported disruption and the timing of the flight

The flight left Las Vegas in the immediate aftermath of the annual DEF CON conference, which concluded on Sunday. Monika Hathaway, head of press for DEF CON, told CyberScoop that neither Delta nor federal authorities had reached out to the conference about the incident, and that "our conference this year also suffered from multiple similar 'deauthorization' Wi‑Fi attacks and it impacted some of our operations." Hathaway added that if the conference had identified perpetrators of those attacks while on site, they "would have removed and banned them from the conference."

What this means for passengers, federal agencies, and airlines

  • Passengers and the general public: Travelers aboard flight 591 faced delays and the risk that a fraudulent hotspot could capture unencrypted data; Delta says no aircraft systems were affected and the cabin crew acted to cut Wi‑Fi service for around 30 minutes.
  • Federal law enforcement and aviation regulators: The FBI's Atlanta office and the FAA confirmed awareness of the incident and Delta said it will partner with federal law enforcement and aviation regulators as the carrier "fully investigat[es] to gather a complete set of facts." TSA and HSI did not provide comment to CyberScoop.
  • Airlines and cabin crews: Delta credited its crew for professionalism in detecting and reacting to the spoofed hotspot; the carrier has flagged the matter for a broader internal review and a coordinated investigation with authorities.

The facts recorded so far paint a narrow but clear sequence: a passenger-created hotspot that mimicked Delta's onboard network, crew action to disable Wi‑Fi, a delayed departure and post‑landing boarding by authorities, and an ongoing investigation that Delta says will take time and involve federal partners. The airline's immediate steps — disabling service and escalating to law enforcement — ended the reported technical risk to the aircraft and initiated a formal inquiry into whether a crime or broader threat occurred.

Original CyberScoop report