Somewhere over the middle of the country on Monday, the Wi-Fi on Delta flight 591 went dark for 30 minutes. Not a router glitch. According to the airline, a network that Delta didn’t own was broadcasting inside the cabin.
The flight was running Las Vegas to Atlanta, one day after the DEF CON security conference wrapped up in Las Vegas. If you’ve ever been on a plane out of Vegas that week, you already know the passenger mix.
The pilots said it out loud over ACARS
The first public account didn’t come from Delta. It came from social media accounts that monitor publicly available air-to-ground messages, known as ACARS.
The “ACARS Drama” account posted a message sent by the pilots from the plane: “NO INFO AS OF NOW WE HAVE A BUNCH OF PAX THAT WERE AT A CYBER CONFERENCE IN LAS THEY WERE ABLE TO JAM OUR WIFI AND BROADCAST THEIR SIGNAL.”
That’s the crew, mid-flight, telling the ground that passengers had taken over the cabin’s wireless. All caps, no punctuation, exactly as flight crews type.
A network named to look official
A description of the incident posted to Reddit went further. It said the passengers stood up a fake hotspot called “Delta WiFi Fast,” with a phishing landing page “designed to harvest passengers’ personal credentials.”
The name is the whole trick. Scroll a Wi-Fi list at 35,000 feet and “Delta WiFi Fast” reads like the real thing, especially when the real thing isn’t responding.
This technique is sometimes known as an “evil twin” attack, and it’s been known to the IT security community for a long time. You set up a fake Wi-Fi network, then capture login credentials and other data from whoever connects.
Delta confirms an unauthorized network was onboard
Morgan Durrant, a Delta spokesperson, confirmed the details.
“One initial finding is an unauthorized WiFi network, which was not provided, operated, or supplied by Delta, was present onboard the aircraft for a short time during the flight,” Durrant said via email.
Delta also said the flight’s safety was “never in question and no aircraft operating systems were affected,” and that no emergency was declared. The airline’s onboard Wi-Fi was disabled for 30 minutes.
That distinction matters more than the drama. Passenger Wi-Fi and flight systems are separate, and nothing in Delta’s account suggests otherwise.
No arrests, and nobody was waiting at the gate
The Atlanta Police Department referred all inquiries to the FBI. Atlanta’s FBI bureau said it is looking into the matter.
Officials there said no arrests were made, and that FBI agents did not meet the flight at the gate. So the version circulating online where federal agents swarm the jet bridge in Atlanta didn’t happen.
“FBI Atlanta is aware of reports regarding a potential Wi-Fi-related incident involving Delta Flight 591,” Tony Thomas, a spokesperson for FBI Atlanta, said in an emailed statement. “We are in contact with our local and corporate partners on this matter. We have no additional information to provide at this time.”
Thomas offered nothing beyond that.
What to do the next time your plane’s Wi-Fi acts up
The useful takeaway isn’t about DEF CON attendees. It’s the reminder that a captive portal asking for your credentials on an aircraft carries the same weight as one in an airport food court, which is to say none.
If the cabin Wi-Fi drops and a suspiciously similar network appears in its place, treat the new one as hostile until the crew says otherwise. On Delta flight 591, the network that showed up wasn’t Delta’s, and the airline needed its own investigation to establish that.