A suspected onboard Wi‑Fi attack on Delta Air Lines flight 591 — which occurred the day after the Def Con security conference in Las Vegas — has drawn scrutiny from federal investigators and renewed questions about the security of inflight internet services.
What happened on the flight
According to incident reports circulated online and messages captured by flight watchers, cabin crew observed a bogus wireless network being broadcast shortly after takeoff on the Atlanta‑bound flight. Crew messages relayed over the aircraft communications addressing and reporting system (ACARS) warned that a number of passengers on board “were at a cyber conference in Las Vegas” and that they believed an individual had disrupted the legitimate onboard network before broadcasting a deceptive signal.
"WE HAVE A BUNCH OF PAX THAT WERE AT A CYBER CONFERENCE IN LAS THEY WERE ABLE TO JAM OUR WIFI AND BROADCAST THEIR SIGNAL."
The ACARS message continued with the crew reporting detection of a scam signal being broadcast under the name DeltaWiFi Fast and warned: "WE BELIEVE THEY ARE TRYING TO SCAM THE OTHER PAX."
Passengers later posted on social media platforms that they had been forcibly disconnected from the authentic onboard Wi‑Fi and, upon reconnecting to the rogue network, were presented with a phishing landing page designed to harvest credentials. Some accounts alleged the attacker used a deauthentication or jamming technique, and speculation pointed to specialised hardware such as a Wi‑Fi Pineapple.
Response and investigation
Federal agencies, including the Federal Aviation Administration and the FBI, have said they are looking into the matter. Delta confirmed to reporters that an unauthorized Wi‑Fi network was momentarily broadcast on the aircraft and said cabin crew disabled the airplane’s Wi‑Fi for roughly 30 minutes in response.
One passenger account said reports that federal agents were waiting at the gate after landing were disputed by other travellers. The full scope of any data exposure has not been confirmed publicly; investigators will evaluate digital evidence and passenger reports to determine whether credentials or other sensitive information was captured.
- Flight: Delta Air Lines flight 591, bound for Atlanta.
- Incident: Unauthorized Wi‑Fi network broadcast onboard; alleged deauthentication/jamming and phishing landing page.
- Immediate action: Cabin crew disabled aircraft Wi‑Fi for about 30 minutes.
- Investigators: FAA and FBI have acknowledged reviewing the event.
Why it matters for travellers and the aviation sector
Inflight Wi‑Fi has become a routine expectation for many travellers but also represents an expanding attack surface. The alleged exploitation on flight 591 highlights multiple vulnerabilities: the relative ease of broadcasting rogue wireless access points in a confined cabin, techniques that force devices off legitimate networks, and phishing pages designed to harvest login information.
For passengers from Delta and neighbouring communities on the Lower Mainland who rely on Wi‑Fi for work or personal use while travelling, the incident underscores the need for vigilance. Best practices include avoiding submission of sensitive credentials over public or inflight networks, using multi‑factor authentication on important accounts, and keeping device software and security apps up to date.
| Element | Known detail |
|---|---|
| Source of reports | ACARS crew message, passenger social posts |
| Airline response | Disabled onboard Wi‑Fi ~30 minutes; confirmed brief unauthorized network |
| Investigators | FAA and FBI reviewing incident |
The episode also serves as a reminder to airlines and service providers that inflight connectivity demands robust security controls and quick operational responses. As investigations proceed, regulators and carriers may consider policy and technical changes to mitigate similar risks on future flights.
For now, passengers should exercise caution when connecting to any public or in‑flight wireless network — even those that appear to carry an airline’s name — and monitor accounts for unusual activity after travel.
This reporting is based on airline and passenger statements and agency acknowledgements made public following the incident.