---
title: "Rogue Wi-Fi at 35,000 Feet: What the Delta Flig… | Firevault"
url: https://fire-vault.com/news/delta-flight-rogue-wifi-deauth-attack-def-con-2026
description: "Delta Air Lines is investigating an unauthorised Wi-Fi network broadcast aboard Flight 591 from Las Vegas to Atlanta, alongside a deauthentication attack that…"
lang: en-GB
---

Insight · Breach Analysis · 13 August 2026

# Rogue Wi-Fi at 35,000 Feet: What the Delta Flight 591 Incident Teaches About Network Trust

Delta Air Lines is investigating an unauthorised Wi-Fi network broadcast aboard Flight 591 from Las Vegas to Atlanta, alongside a deauthentication attack that knocked passengers off the aircraft network. The lesson is not about aviation. It is about how easily a trusted connection can be impersonated.

Image: Mark Fermor (https://fire-vault.com/assets/mark-fermor-DWFWqeWL.jpg)

Mark Fermor CTO, CMO & Founder, Firevault

4 min read

Share

Share on LinkedIn: https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Fdelta-flight-rogue-wifi-deauth-attack-def-con-2026
Share on X: https://twitter.com/intent/tweet?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Fdelta-flight-rogue-wifi-deauth-attack-def-con-2026&text=Rogue%20Wi-Fi%20at%2035%2C000%20Feet%3A%20What%20the%20Delta%20Flight%20591%20Incident%20Teaches%20About%20Network%20Trust%0A%0ADelta%20Air%20Lines%20is%20investigating%20an%20unauthorised%20Wi-Fi%20network%20broadcast%20aboard%20Flight%20591%20from%20Las%20Vegas%20to%20Atlanta%2C%20alongside%20a%20deauthentication%20attack%20that%20knocked%20passengers%20off%20the%20aircraft%20network.%20The%20lesson%20is%20not%20about%20aviation.%20It%20is%20about%20how%20easily%20a%20trusted%20connection%20can%20be%20impersonated.
Share on Facebook: https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Ffire-vault.com%2Fnews%2Fdelta-flight-rogue-wifi-deauth-attack-def-con-2026

Image: Aircraft cabin window with cyan wireless signals being intercepted by a magenta rogue network, and a locked offline storage block separated by a physical gap, in Firevault navy, cyan and magenta (https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/news%2Fdelta-rogue-wifi-defcon-2026.jpg)

Aircraft cabin window with cyan wireless signals being intercepted by a magenta rogue network, and a locked offline storage block separated by a physical gap, in Firevault navy, cyan and magenta

Why it matters

## What this means for organisations holding critical data

**Delta Air Lines is investigating an unauthorised Wi-Fi network that appeared aboard Flight 591 from Las Vegas to Atlanta on 10 August 2026.** The aircraft was carrying passengers returning from the DEF CON 34 hacking conference. The incident was reported by BleepingComputer (https://www.bleepingcomputer.com/news/security/delta-probes-wi-fi-deauth-attack-on-flight-carrying-def-con-attendees/) on 11 August 2026.

## What Happened

Delta told BleepingComputer that an unauthorised wireless network, which was not provided, operated or supplied by Delta, was present onboard the aircraft for a short time during the flight. Cabin crew responded by deactivating the aircraft Wi-Fi for nearly 30 minutes. Delta stated that the incident did not affect the safety of passengers or aircraft operating systems, and that no emergency was declared with air traffic control. The aircraft was a Boeing 757 with six crew and 199 passengers.

According to crew messages sent through the Aircraft Communications Addressing and Reporting System and published by an aircraft technician, passengers were able to jam the aircraft Wi-Fi and broadcast a rogue network named "Delta WiFi Fast". One crew message read: "WE HAVE A PAX ON THIS HAS CREATED A SCAM WIFI CALLED DELTA WIFI FAST. WE BELIEVE THEY ARE TRYING TO SCAM THE OTHER PAX." A member of an online frequent flyer group reported that the fake network presented a phishing page collecting personal credentials and Google login data. Federal authorities and airport police boarded the aircraft after it docked, questioned the suspects and seized portable Wi-Fi hardware.

## How the Attack Works

The technique is a Wi-Fi deauthentication attack. An attacker observes wireless traffic, identifies the access point address, then forges deauthentication frames that appear to come from the legitimate access point. Connected devices obey and disconnect. Sent continuously, those frames keep devices off the real network. The disconnection is rarely the objective. It is the setup. Once a device is off the legitimate access point, it will look for another one, and an evil twin network with a convincing name is waiting. Traffic is then intercepted or the user is sent to a credential harvesting page. Networks that enforce Protected Management Frames can mitigate spoofed management frames.

## Why It Matters

Nothing about this attack required privileged access, a stolen password or a software vulnerability. It required proximity and a small radio. The network name did the rest. That is the uncomfortable point for every organisation whose staff work from airports, hotels, client sites and trains, because a corporate device that reconnects to a hostile access point is now inside an attacker controlled path, and the credentials it presents are real ones.

The same logic applies far beyond aviation. Any environment that treats an available connection as a trusted connection can be impersonated. Guest networks in offices, contractor links into operational sites and remote maintenance sessions all inherit the same weakness: the path is assumed to be safe because it is expected to be there.

## The Firevault View

This incident is a small, vivid example of a design principle we return to constantly. A connection that exists can be impersonated, jammed or abused. A connection that does not exist cannot. Encryption and authentication protect what travels along a path. They do not question whether the path should be open at all.

Offline Secure Storage (https://fire-vault.com/offline-secure-storage)® takes the opposite starting point. Crown-jewel records, gold copies and retained archives sit on dedicated hardware that is physically disconnected when nobody has been authorised to use it. Access is granted for a session, verified, then withdrawn, so the reachable surface is a deliberate decision rather than a permanent condition. An attacker who succeeds in taking over a network path still reaches nothing, because the asset is not on a path.

For operational environments, the equivalent discipline is physical segmentation: zones that hold under pressure, with control paths that are separate from data paths and vendor access that exists only on demand. Our control blueprint for enforcing physical segmentation (https://fire-vault.com/control-blueprints/cp-04) sets out how those zones are designed and evidenced, and controlling third-party access (https://fire-vault.com/control-blueprints/cp-03) covers the vendor paths that so often stay open between visits. If you want the underlying model first, start with why Offline Secure Storage® exists (https://fire-vault.com/why-oss) and how #OSS works (https://fire-vault.com/how-oss-works).

The question the Delta incident poses is worth asking about your own estate. If someone stood up a convincing fake network next to your people or your plant, what would still be reachable?

Sources

## Where this reporting comes from

01

**Original report**Primary coverage referenced in this analysis View original article (https://www.bleepingcomputer.com/news/security/delta-probes-wi-fi-deauth-attack-on-flight-carrying-def-con-attendees/)

About the author

### Mark Fermor

Mark Fermor on LinkedIn (https://www.linkedin.com/in/mfermor)

CTO, CMO & Founder

Founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

How Firevault would handle this

## Access decided by you, not assumed by the network

Control by Firevault removes standing pathways and replaces them with connection windows you approve, so stolen credentials and compromised suppliers have nothing standing to abuse.

Get started: https://fire-vault.com/get-started
Talk to the team: https://fire-vault.com/demo

**No standing access**Paths exist only when you open them

**Verification**Identity confirmed before any connection is made

**Containment**A compromised account cannot reach what is disconnected

**Control**Every window and closure is under your command

Related Reading

## You may also find these useful

Breach Analysis

### Dyfed-Powys Police confirms cyber attack as staff information may have been compromised

Dyfed-Powys Police has confirmed that a cyber attack identified on 14 September disrupted non-emergency systems and may have exposed staff information. The force says it has found no evidence that public data was accessed.

25 Sept 2026 3 min
https://fire-vault.com/news/dyfed-powys-police-cyber-attack-2026

Breach Analysis

### FBI investigates claims that hackers stole personnel and applicant data

The FBI is investigating unauthorised activity affecting its recruitment website after ShinyHunters claimed it stole sensitive records on current and former personnel and job applicants. The claimed scale remains unconfirmed.

22 Sept 2026 4 min
https://fire-vault.com/news/fbi-employee-applicant-data-breach-shinyhunters-2026

Breach Analysis

### Vulnerable children's health records caught up in HCRG Care Group cyber attack, families told 18 months later

Families of vulnerable children in Wiltshire, Bath and North East Somerset have been told their personal health information may have been accessed in a cyber attack on HCRG Care Group in February 2025, more than 18 months after the incident.

20 Sept 2026 4 min
https://fire-vault.com/news/hcrg-care-group-children-records-cyber-attack-2026

Breach Analysis

### FBI and Coast Guard board oil tankers after suspected foreign cyberattacks on ships entering US waters

US authorities boarded two foreign-flagged oil tankers in the Gulf of Mexico after indications their networks were compromised by foreign cyber actors. Mark Fermor on why a ship is a floating lesson in what happens when operational technology is reachable.

17 Sept 2026 4 min
https://fire-vault.com/news/fbi-coast-guard-probe-cyberattacks-oil-tankers-us-waters-2026

Breach Analysis

### FBI investigates 153 million drivers licenses put up for sale on a criminal forum

A dark web service claimed to be selling scans of more than 153 million drivers licenses, apparently taken from a Louisiana identity verification company used by household names. The FBI has opened an inquiry, and the case shows how long retention turns a routine check into national-scale exposure.

16 Sept 2026 4 min
https://fire-vault.com/news/fbi-investigates-153-million-drivers-licenses-dark-web-2026

Breach Analysis

### CenterPoint Energy confirms hackers stole customer data through an exposed API

CenterPoint Energy has confirmed that criminals stole customer data through one of its external facing systems, after a threat actor advertised 7.49 million files on a dark web forum. Mark Fermor on what an unsecured API says about the way critical infrastructure treats connected data.

16 Sept 2026 4 min
https://fire-vault.com/news/centerpoint-energy-confirms-cyberattack-data-theft-2026

## Suggested Reading

- What is Offline Secure Storage The foundation of physical disconnection: https://fire-vault.com/how-it-works/offline-secure-storage
- Why Offline Secure Storage The case for physical control: https://fire-vault.com/why-oss
- Ransomware Defence Hold gold copies offline: https://fire-vault.com/oss-for-ransomware-recovery
- Control Physical path control for IT and OT: https://fire-vault.com/solutions/control
- Knowledge Vault All articles, guides and whitepapers: https://fire-vault.com/learn/knowledge
- Book a Demo See Firevault in action: https://fire-vault.com/demo

Back to Knowledge Vault: https://fire-vault.com/learn/knowledge

## Structured data

```json
[
  {
    "@context": "https://schema.org",
    "@type": "Organization",
    "@id": "https://fire-vault.com/#organization",
    "name": "Firevault",
    "legalName": "Firevault Limited",
    "url": "https://fire-vault.com",
    "logo": {
      "@type": "ImageObject",
      "url": "https://fire-vault.com/logo.png",
      "width": 200,
      "height": 60
    },
    "foundingDate": "2025-03",
    "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
    "address": {
      "@type": "PostalAddress",
      "addressCountry": "GB",
      "addressLocality": "United Kingdom"
    },
    "contactPoint": [
      {
        "@type": "ContactPoint",
        "contactType": "customer service",
        "email": "hello@fire-vault.com",
        "availableLanguage": "English",
        "areaServed": [
          "GB",
          "EU",
          "US",
          "AE"
        ]
      },
      {
        "@type": "ContactPoint",
        "contactType": "sales",
        "email": "sales@fire-vault.com",
        "availableLanguage": "English",
        "areaServed": [
          "GB",
          "EU",
          "US",
          "AE"
        ]
      }
    ],
    "founder": [
      {
        "@type": "Person",
        "name": "Mark Fermor",
        "jobTitle": "Founder, CTO and CMO"
      },
      {
        "@type": "Person",
        "name": "David Bailey",
        "jobTitle": "Founder and CEO"
      }
    ],
    "areaServed": [
      "United Kingdom",
      "Europe",
      "United States",
      "Middle East"
    ],
    "sameAs": [
      "https://www.linkedin.com/company/firevault",
      "https://x.com/firevaultuk"
    ],
    "slogan": "Disconnect to Protect",
    "brand": [
      {
        "@type": "Brand",
        "name": "Offline Secure Storage"
      },
      {
        "@type": "Brand",
        "name": "Control by Firevault"
      },
      {
        "@type": "Brand",
        "name": "Firebreak"
      }
    ],
    "knowsAbout": [
      "Offline Secure Storage",
      "Physically disconnected data storage",
      "Physical Air Gap Data Protection",
      "Ransomware Protection",
      "Ransomware recovery",
      "3-2-1-1-0 backup rule",
      "AI kill switch",
      "Operational technology security",
      "Critical national infrastructure resilience",
      "Data Sovereignty",
      "GDPR Compliance",
      "NIS2 Compliance",
      "DORA Compliance",
      "NCSC Cyber Assessment Framework"
    ]
  },
  {
    "@context": "https://schema.org",
    "@type": "WebSite",
    "@id": "https://fire-vault.com/#website",
    "name": "Firevault",
    "alternateName": [
      "Firevault",
      "Firevault UK",
      "Firevault Limited"
    ],
    "url": "https://fire-vault.com",
    "publisher": {
      "@id": "https://fire-vault.com/#organization"
    },
    "inLanguage": "en-GB",
    "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
    "potentialAction": {
      "@type": "SearchAction",
      "target": {
        "@type": "EntryPoint",
        "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
      },
      "query-input": "required name=search_term_string"
    }
  },
  {
    "@context": "https://schema.org",
    "@type": "WebPage",
    "@id": "https://fire-vault.com/news/delta-flight-rogue-wifi-deauth-attack-def-con-2026#webpage",
    "url": "https://fire-vault.com/news/delta-flight-rogue-wifi-deauth-attack-def-con-2026",
    "name": "Rogue Wi-Fi at 35,000 Feet: What the Delta Flig…",
    "description": "Delta Air Lines is investigating an unauthorised Wi-Fi network broadcast aboard Flight 591 from Las Vegas to Atlanta, alongside a deauthentication attack that…",
    "isPartOf": {
      "@id": "https://fire-vault.com/#website"
    },
    "about": {
      "@id": "https://fire-vault.com/#organization"
    },
    "primaryImageOfPage": {
      "@type": "ImageObject",
      "url": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/news%2Fdelta-rogue-wifi-defcon-2026.jpg"
    },
    "inLanguage": "en-GB",
    "breadcrumb": {
      "@id": "https://fire-vault.com/news/delta-flight-rogue-wifi-deauth-attack-def-con-2026#breadcrumb"
    }
  },
  {
    "@context": "https://schema.org",
    "@type": "BreadcrumbList",
    "@id": "https://fire-vault.com/news/delta-flight-rogue-wifi-deauth-attack-def-con-2026#breadcrumb",
    "itemListElement": [
      {
        "@type": "ListItem",
        "position": 1,
        "name": "Home",
        "item": "https://fire-vault.com"
      },
      {
        "@type": "ListItem",
        "position": 2,
        "name": "Learn",
        "item": "https://fire-vault.com/learn"
      },
      {
        "@type": "ListItem",
        "position": 3,
        "name": "Knowledge Vault",
        "item": "https://fire-vault.com/learn/knowledge"
      },
      {
        "@type": "ListItem",
        "position": 4,
        "name": "Rogue Wi-Fi at 35,000 Feet: What the Delta Flight 591 Incident Teaches About Network Trust",
        "item": "https://fire-vault.com/news/delta-flight-rogue-wifi-deauth-attack-def-con-2026"
      }
    ]
  },
  {
    "@context": "https://schema.org",
    "@type": "NewsArticle",
    "headline": "Rogue Wi-Fi at 35,000 Feet: What the Delta Flight 591 Incident Teaches About Network Trust",
    "description": "Delta Air Lines is investigating an unauthorised Wi-Fi network broadcast aboard Flight 591 from Las Vegas to Atlanta, alongside a deauthentication attack that knocked passengers off the aircraft network. The lesson is not about aviation. It is about how easily a trusted connection can be impersonated.",
    "url": "https://fire-vault.com/news/delta-flight-rogue-wifi-deauth-attack-def-con-2026",
    "image": [
      {
        "@type": "ImageObject",
        "url": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/news%2Fdelta-rogue-wifi-defcon-2026.jpg",
        "width": 1200,
        "height": 1200
      },
      {
        "@type": "ImageObject",
        "url": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/news%2Fdelta-rogue-wifi-defcon-2026.jpg",
        "width": 1200,
        "height": 900
      },
      {
        "@type": "ImageObject",
        "url": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/news%2Fdelta-rogue-wifi-defcon-2026.jpg",
        "width": 1200,
        "height": 675
      }
    ],
    "thumbnailUrl": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/news%2Fdelta-rogue-wifi-defcon-2026.jpg",
    "author": {
      "@type": "Person",
      "name": "Mark Fermor",
      "jobTitle": "CTO, CMO & Founder",
      "worksFor": {
        "@id": "https://fire-vault.com/#organization"
      },
      "url": "https://fire-vault.com/why-oss/about"
    },
    "publisher": {
      "@type": "NewsMediaOrganization",
      "name": "Firevault",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 600,
        "height": 60
      }
    },
    "datePublished": "2026-08-13T04:30:00+00:00",
    "dateModified": "2026-08-28T08:03:22.256672+00:00",
    "mainEntityOfPage": {
      "@type": "WebPage",
      "@id": "https://fire-vault.com/news/delta-flight-rogue-wifi-deauth-attack-def-con-2026"
    },
    "inLanguage": "en-GB",
    "articleSection": "Breach Analysis",
    "wordCount": 715,
    "keywords": "Rogue, Breach Analysis, data breach, cyber security, offline secure storage, data protection, physical air gap, Delta rogue Wi-Fi deauthentication attack, Delta Flight 591 Wi-Fi attack, Wi-Fi deauthentication attack, evil twin network, rogue access point, DEF CON 34, in-flight Wi-Fi security, physical network segmentation, offline secure storage network trust",
    "articleBody": "Delta Air Lines is investigating an unauthorised Wi-Fi network that appeared aboard Flight 591 from Las Vegas to Atlanta on 10 August 2026. The aircraft was carrying passengers returning from the DEF CON 34 hacking conference. The incident was reported by BleepingComputer on 11 August 2026. What Happened Delta told BleepingComputer that an unauthorised wireless network, which was not provided, ope",
    "dateline": "United Kingdom",
    "speakable": {
      "@type": "SpeakableSpecification",
      "cssSelector": [
        "h1",
        ".article-summary",
        "h2"
      ]
    },
    "isAccessibleForFree": true,
    "copyrightHolder": {
      "@id": "https://fire-vault.com/#organization"
    },
    "copyrightYear": 2026
  },
  {
    "@context": "https://schema.org",
    "@type": "FAQPage",
    "mainEntity": [
      {
        "@type": "Question",
        "name": "What happened on Delta Flight 591?",
        "acceptedAnswer": {
          "@type": "Answer",
          "text": "On 10 August 2026, an unauthorised Wi-Fi network named Delta WiFi Fast was broadcast aboard Delta Flight 591 from Las Vegas to Atlanta, alongside a deauthentication attack that disconnected passengers from the aircraft network. Cabin crew disabled the aircraft Wi-Fi for nearly 30 minutes, and federal authorities questioned suspects and seized portable Wi-Fi hardware after landing."
        }
      },
      {
        "@type": "Question",
        "name": "What is a Wi-Fi deauthentication attack?",
        "acceptedAnswer": {
          "@type": "Answer",
          "text": "An attacker forges deauthentication frames that appear to come from a legitimate access point, causing connected devices to disconnect. Sent repeatedly, this keeps devices off the real network and pushes them towards a rogue evil twin access point where traffic can be intercepted or credentials harvested. Protected Management Frames mitigate spoofed management frames."
        }
      },
      {
        "@type": "Question",
        "name": "Why does this matter outside aviation?",
        "acceptedAnswer": {
          "@type": "Answer",
          "text": "The attack needed only proximity and a small radio, not a stolen password or a software flaw. Any environment that treats an available connection as a trusted connection, including office guest networks, contractor links and remote maintenance sessions, can be impersonated the same way."
        }
      },
      {
        "@type": "Question",
        "name": "How does Offline Secure Storage reduce this risk?",
        "acceptedAnswer": {
          "@type": "Answer",
          "text": "Offline Secure Storage keeps crown-jewel records, gold copies and retained archives on dedicated hardware that is physically disconnected unless an authorised session is open. An attacker who takes control of a network path reaches nothing, because the asset is not on a path."
        }
      }
    ]
  }
]
```