After the hacker conference DEF CON 2026 ended in Las Vegas, a pilot message said passengers set up an 'evil twin' — a fake Wi Fi that mimics the airline's — and federal law enforcement is looking.
On Delta flight 591 from Las Vegas to Atlanta the day after DEF CON 2026 wrapped, the pilots relayed a message over the plane's air-to-ground text system, ACARS, saying passengers from a "cyber conference in LAS" were able to "jam our Wi-Fi and broadcast their signal." A Reddit post from the same flight described a fake hotspot named "Delta WiFi Fast" that served a phishing landing page asking for email and password, a detail the Ars Technica report picked up.
The technique is an "evil twin" attack: a fake Wi-Fi network that mimics the airline's name, paired with a captive portal that harvests whatever a traveler types. The technique itself is a well-known Wi-Fi impersonation trick that has shown up in hotels, airports, and at conferences before. In-flight Wi-Fi works on a shared radio, where any passenger's device can broadcast a network that looks like the airline's. The network name printed on the seatback card is the one a passenger should trust.
The pilot's message reached the public secondhand via the "ACARS Drama" social account, not through an on-the-record statement from Delta or law enforcement, and the framing stays "suspected." Ars Technica reports federal law enforcement is looking at the incident, but no arrests, charges, or confirmed credential theft have been disclosed.
The defensive move for travelers is straightforward: treat any in-flight login page as untrusted, prefer a personal hotspot or VPN, and verify the network name against the seatback card before typing a password.