Delta targeted in Wi-Fi phishing attack

Delta Air Lines was targeted in a Wi-Fi phishing attack on a flight from Las Vegas to Atlanta earlier this month after an unauthorised network appeared on board. 

The incident occurred on August 10, after passengers were leaving Las Vegas following DEF CON 34, one of the world’s largest cybersecurity and hacking conferences. 

Crew members detected that something was interfering the airline’s legitimate onboard Wi-Fi. The unauthorised network appeared to mimic the aircraft’s Wi-Fi, prompting the crew to take precautionary measures and disable the service.

According to Aras Nazarovas, Senior Information Security Researcher at Cybernews, fake networks like this are known as an ‘evil twin’ attack. Hackers create a Wi-Fi network with a name that is similar or identical to a legitimate network, with the goal of stealing sensitive information from people who connect.

“Once a person connects to the hacker’s Wi-Fi network, the hacker may be able to see what the victim is doing online and what data they transfer. However, since most websites have HTTPS/TLS encryption, much of what the user does, even on the rogue network, is private,” said Nazarovas.

Risks

He said the main risk was that victims may be redirected to a phishing website. 

“In this case, it may have been a fake Delta login page asking for personal data like name, email, address. The hacker may go further and provide fake login pages for banks or social media, and try to extract login details from the victims.”

If a person entered credentials into a Wi-Fi login page, noticed security warnings popping up after visiting a website, downloaded something, or entered payment information into an unfamiliar page, then they may have had their data stolen. 

“If so, the victim should immediately change any passwords that were transmitted, do a thorough scan of their device for malware, and if bank details were transmitted, freeze the bank account until new credentials are received. If a user just connected and disconnected to the Wi-Fi without entering any details or clicking suspicious links, they should be fine,” said Nazarovas.

© Now Media. This content is protected by copyright and may not be adapted or republished. If you would like to discuss cooperation opportunities, please contact: editor@travelnews.co.za.