On August 10, 2026, a passenger on Delta Flight 591 from Las Vegas to Atlanta allegedly jammed the legitimate in flight Wi Fi and broadcast a rogue 'evil twin' hotspot named 'Delta WiFi Fast' to phish fellow travelers.
Research answer

Create a landscape editorial hero image for this Studio Global article: What happened on a Delta flight from Las Vegas to Atlanta after an unidentified passenger allegedly set up a fake Wi-Fi network mid-flight,. Article summary: Here is a comprehensive summary of what happened, based on multiple news and security sources from August 11–12, 2026.. Topic tags: general, general web. Style: premium digital editorial illustration, source-backed research mood, clean composition, high detail, modern web publication hero. Use reference image context only for broad subject, composition, and topical grounding; do not copy the exact image. Avoid: logos, brand marks, copyrighted characters, real person likenesses, fake screenshots, UI text, readable text, watermarks, charts with fake numbers, clickbait thumbnails, icons, and tiny thumbnail layouts. Make it useful as an illustrative visual, not as f
On Monday, August 10, 2026, a routine Delta flight from Las Vegas to Atlanta turned into a cybersecurity incident that triggered a federal investigation. About an hour after takeoff, a passenger on Delta Flight 591 — a Boeing 757 carrying 199 passengers and six crew members — allegedly jammed the aircraft's legitimate in-flight Wi-Fi and set up a fake hotspot designed to steal personal data from other passengers .
The incident occurred on a flight carrying attendees returning home from DEF CON 34, the world's largest hacking conference, which had wrapped up the day before in Las Vegas . While the airline confirmed that no aircraft operating systems or avionics were ever affected, the event prompted an immediate law enforcement response and raised urgent questions about the security of in-flight connectivity.
The unidentified passenger used a portable device to jam the plane's official Wi-Fi signal and then broadcast a rogue network named 'Delta WiFi Fast' — designed to look identical to Delta's legitimate login page . This technique is known as an 'evil twin' attack: a lookalike Wi-Fi network that tricks nearby devices into connecting to a fake login page, where the attacker can harvest whatever credentials passengers enter
.
According to a person who claims to have been present when the plane landed, the fake hotspot served up a phishing landing page specifically designed to capture passengers' personal credentials and Google login data . The attacker's goal was likely credential theft and personal data collection from unsuspecting travelers
.
When the crew discovered the unauthorized network, they acted quickly. The pilots used the Aircraft Communications Addressing and Reporting System (ACARS) — a digital messaging system used for non-voice communication between aircraft and ground stations — to alert Delta's corporate security. The message read: "HEY ALERT CORP SECURITY WE HAVE A PAX [passenger] ON THAT HAS CREATED A SCAM WIFI CALLED DELTA WIFI F…" .
Seventeen minutes later, the crew sent a follow-up: "NO INFO AS OF NOW," indicating they were still gathering information. They reported that several passengers had attended a cybersecurity conference in Las Vegas and "were able to jam our Wi-Fi and broadcast…" . The pilots also directly alerted air traffic control about the unauthorized network
.
As a precaution, the cabin crew disabled the aircraft's legitimate in-flight Wi-Fi system for approximately 30 minutes .
Delta Air Lines confirmed that the safety of flight was never in question. The company stated that no aircraft operating systems or avionics were affected — the incident was strictly limited to the passenger internet network . Delta spokesperson Morgan Durrant told TechCrunch: "[The] safety of flight was never in question and no aircraft operating systems were affected," adding that the in-flight network itself was not compromised
.
Once the aircraft landed at Hartsfield-Jackson Atlanta International Airport, authorities boarded the plane and interviewed passengers . Delta released a statement saying, "We are fully investigating to gather a complete set of facts, which will take time. We will partner with federal law enforcement and aviation regulators to ensure the incident is thoroughly investigated"
.
Security researchers and reports indicate the attacker likely used a combination of two techniques: a Wi-Fi 'deauthentication' attack (deauth attack) to forcibly disconnect passengers from the legitimate network, and a portable 'evil twin' access point to broadcast the fake hotspot .
Common tools that could have been used include:
As of August 12, 2026, three entities are actively investigating:
No arrests have been announced, and the passenger(s) responsible have not been publicly identified. The investigation is ongoing.
Studio Global AI
This page includes a source-backed answer you can continue inside Studio Global.
On August 10, 2026, a passenger on Delta Flight 591 from Las Vegas to Atlanta allegedly jammed the legitimate in flight Wi Fi and broadcast a rogue 'evil twin' hotspot named 'Delta WiFi Fast' to phish fellow travelers.