Delta probes Wi-Fi deauth attack on flight carrying DEF CON attendees
Delta Air Lines Flight 591 from Las Vegas to Atlanta experienced an unauthorized Wi-Fi network and a Wi-Fi deauthentication attack during the flight. Passengers who had attended the DEF CON 34 hacker conference allegedly conducted the attack, which involved jamming the aircraft's Wi-Fi and broadcasting a rogue network named "Delta WiFi Fast." The rogue network displayed a phishing page designed to collect personal credentials and Google login data. The aircraft crew disabled Wi-Fi for about 30 minutes to mitigate the disruption. Federal authorities investigated the incident after landing, questioning suspects and seizing their Wi-Fi hardware. Delta confirmed no safety impact to passengers or aircraft systems and is cooperating with law enforcement and aviation regulators.
AI Analysis
Technical Summary
During Delta Air Lines Flight 591, an unauthorized Wi-Fi network appeared onboard, and a Wi-Fi deauthentication attack was conducted, reportedly by passengers returning from DEF CON 34. The attack involved sending forged deauthentication frames to disconnect clients from the legitimate in-flight Wi-Fi access point, causing denial of service. Concurrently, a rogue Wi-Fi network named "Delta WiFi Fast" was broadcast, presenting a phishing page to collect sensitive credentials. The aircraft crew responded by disabling Wi-Fi for approximately 30 minutes. Federal authorities boarded the aircraft post-landing to investigate and confiscate equipment. Delta stated the incident did not affect flight safety or aircraft systems and is under thorough investigation with federal and aviation partners.
Potential Impact
The attack caused a denial-of-service condition on the aircraft's Wi-Fi network, disrupting connectivity for passengers. Additionally, the rogue Wi-Fi network attempted to phish personal and Google login credentials from passengers. There was no reported impact on the safety of passengers or aircraft operational systems. The incident required disabling Wi-Fi temporarily and prompted a law enforcement investigation. The phishing attempt could have led to credential compromise if passengers connected to the rogue network and submitted their information.
Mitigation Recommendations
Delta Air Lines disabled the aircraft's Wi-Fi functionality temporarily to stop the attack. The company is cooperating with federal law enforcement and aviation regulators to investigate the incident. Networks can mitigate Wi-Fi deauthentication attacks by implementing Protected Management Frames (PMF), though it is unclear if this was in place. Passengers should avoid connecting to unauthorized or suspicious Wi-Fi networks and be cautious of phishing pages requesting credentials. No official patch or fix applies as this is an operational security incident rather than a software vulnerability.
Delta probes Wi-Fi deauth attack on flight carrying DEF CON attendees
Description
Delta Air Lines Flight 591 from Las Vegas to Atlanta experienced an unauthorized Wi-Fi network and a Wi-Fi deauthentication attack during the flight. Passengers who had attended the DEF CON 34 hacker conference allegedly conducted the attack, which involved jamming the aircraft's Wi-Fi and broadcasting a rogue network named "Delta WiFi Fast." The rogue network displayed a phishing page designed to collect personal credentials and Google login data. The aircraft crew disabled Wi-Fi for about 30 minutes to mitigate the disruption. Federal authorities investigated the incident after landing, questioning suspects and seizing their Wi-Fi hardware. Delta confirmed no safety impact to passengers or aircraft systems and is cooperating with law enforcement and aviation regulators.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
During Delta Air Lines Flight 591, an unauthorized Wi-Fi network appeared onboard, and a Wi-Fi deauthentication attack was conducted, reportedly by passengers returning from DEF CON 34. The attack involved sending forged deauthentication frames to disconnect clients from the legitimate in-flight Wi-Fi access point, causing denial of service. Concurrently, a rogue Wi-Fi network named "Delta WiFi Fast" was broadcast, presenting a phishing page to collect sensitive credentials. The aircraft crew responded by disabling Wi-Fi for approximately 30 minutes. Federal authorities boarded the aircraft post-landing to investigate and confiscate equipment. Delta stated the incident did not affect flight safety or aircraft systems and is under thorough investigation with federal and aviation partners.
Potential Impact
The attack caused a denial-of-service condition on the aircraft's Wi-Fi network, disrupting connectivity for passengers. Additionally, the rogue Wi-Fi network attempted to phish personal and Google login credentials from passengers. There was no reported impact on the safety of passengers or aircraft operational systems. The incident required disabling Wi-Fi temporarily and prompted a law enforcement investigation. The phishing attempt could have led to credential compromise if passengers connected to the rogue network and submitted their information.
Defensive Guidance
Delta Air Lines disabled the aircraft's Wi-Fi functionality temporarily to stop the attack. The company is cooperating with federal law enforcement and aviation regulators to investigate the incident. Networks can mitigate Wi-Fi deauthentication attacks by implementing Protected Management Frames (PMF), though it is unclear if this was in place. Passengers should avoid connecting to unauthorized or suspicious Wi-Fi networks and be cautious of phishing pages requesting credentials. No official patch or fix applies as this is an operational security incident rather than a software vulnerability.
Technical Details
- Classification
- {"confidence":0.75,"severitySource":"heuristic","classifier":"rss-v2"}
Threat ID: 6a7b6cd1bf8831d539332229
Added to database: 08/11/2026, 18:41:21 UTC
Last enriched: 08/11/2026, 18:41:31 UTC
Last updated: 08/12/2026, 03:02:48 UTC
Views: 10
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.