Delta Air Lines is investigating an incident aboard Flight 591 from Las Vegas to Atlanta where an unauthorized Wi-Fi network appeared, allegedly disrupting the aircraft's legitimate in-flight Wi-Fi service. The incident occurred on August 10, 2026, and involved passengers returning from the DEF CON 34 hacker conference. Delta confirmed that an unauthorized Wi-Fi network, not operated or supplied by the airline, was present for a short duration.
According to Delta, the safety of the passengers and aircraft operating systems was not compromised. The airline is collaborating with federal law enforcement and aviation regulators for a thorough investigation. Following the discovery of the unauthorized network, the cabin crew deactivated the aircraft's Wi-Fi functionality for approximately 30 minutes.
Reports from the Aircraft Communications Addressing and Reporting System (ACARS), shared by an aircraft technician, indicated that some passengers were able to "jam" the aircraft's Wi-Fi and broadcast a rogue network named "Delta WiFi Fast." The ACARS messages suggested that the perpetrators were attempting to "scam" other passengers.
Online accounts from frequent flyer groups claimed that the fake Wi-Fi network displayed a phishing page designed to collect personal credentials, including Google login data. After the Boeing 757, carrying six crew members and 199 passengers, docked at its gate, federal authorities and airport police reportedly boarded the aircraft to question suspects and confiscate portable Wi-Fi hardware. Delta confirmed that no emergency was declared with air traffic control.
The incident is described as a Wi-Fi deauthentication attack, where clients connected to a legitimate Wi-Fi network receive forged packets, appearing to come from the access point, instructing them to disconnect. By continuously transmitting these forged deauthentication frames, an attacker can create a denial-of-service condition, persistently disconnecting users from the legitimate network. Such attacks are sometimes used to force clients to connect to a rogue access point, often referred to as an "evil twin," to intercept traffic or direct users to malicious websites. Networks employing Protected Management Frames (PMF) are designed to mitigate these types of spoofed management-frame attacks.






