Delta Air Lines is working with authorities after an unauthorized wireless network appeared aboard a Las Vegas to Atlanta flight carrying passengers returning from the DEF CON 34 cybersecurity conference. The airline confirmed the network was active briefly during Flight 591 but said it had no connection to Delta’s own onboard Wi-Fi equipment.
The incident occurred on a Boeing 757 carrying 199 passengers and six crew members. Once the cabin crew became aware of the unknown network, onboard Wi-Fi functionality was disabled for roughly 30 minutes while the situation was addressed. Delta said neither the aircraft’s operating systems nor passenger safety were affected, and the flight crew did not declare an emergency with air traffic control.
Exactly what happened to the legitimate Wi-Fi service remains under investigation. Online accounts allege that several passengers disrupted the aircraft’s wireless network using a Wi-Fi deauthentication technique and then made a separate access point available to nearby devices. Delta has confirmed the presence of an unauthorized network, but it has not confirmed those technical details or publicly identified the person responsible.
Reported ACARS communications from the aircraft provide additional context. Turbine Traveller, an aircraft technician who published the messages online, said the crew reported that passengers associated with a cybersecurity conference had managed to interfere with the Wi-Fi and broadcast their own signal. Another message reportedly identified a network called “Delta WiFi Fast,” with the crew expressing concern that other passengers could mistake it for a legitimate Delta service.
A deauthentication attack can disrupt Wi-Fi by sending forged management frames that appear to originate from the genuine wireless access point. Devices receiving those frames may disconnect from the network, and repeatedly transmitting them can make maintaining a connection difficult. The technique does not require compromising an aircraft’s flight-control systems.
A rogue wireless network can then create a separate risk if users mistake it for the connection they originally intended to use. Fake access points can imitate recognizable network names and may be paired with fraudulent login pages intended to collect information from anyone who connects.
Claims that this occurred on Flight 591 have not been fully confirmed. Mary Perrault, who participates in online frequent flyer communities but has no formal affiliation with Delta, said the unauthorized network presented a phishing page that requested personal information and Google account credentials. Delta’s statement confirms the rogue Wi-Fi network but does not say that passenger credentials were collected.
Perrault also reported that federal authorities and airport police met the aircraft after it arrived at the gate. According to her account, suspected individuals were questioned, and portable Wi-Fi equipment was seized. Delta has not publicly confirmed those details or announced whether any arrests or charges resulted from the incident.
The airline said it intends to cooperate with federal law enforcement and aviation regulators during the investigation. At this stage, Delta’s confirmed findings are limited to an unauthorized Wi-Fi network operating briefly aboard Flight 591 and the temporary shutdown of the aircraft’s Wi-Fi functionality in response.