Delta ‘evil twin’ WiFi incident raises cyber concerns | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


A fake WiFi network discovered aboard Delta Air Lines Flight DL591 may have been intended to steal passenger credentials rather than to take control of the aircraft. But the incident highlights a much broader cybersecurity challenge as aircraft become increasingly connected, according to Cyviation CEO Eliran Almog.

Delta Flight DL591 was travelling from Las Vegas to Atlanta on 10 August when an unauthorised wireless network called “Delta Wifi Fast” appeared onboard.

Delta said the network was not provided, operated or supplied by the airline. The crew temporarily disabled the Boeing 757’s passenger WiFi for around 30 minutes as a precaution. Delta said there was no hack of its systems and the safety of the flight was never in question. The airline is investigating alongside federal law enforcement and the Federal Aviation Administration (FAA).

Photo: BriYYZ / Wikimedia Commons

The incident came shortly after the DEF CON cybersecurity conference in Las Vegas, although who created the network, their intentions and precisely how it operated have not been publicly established.

Speaking to Aerospace Global News, Almog said the available evidence nevertheless appears consistent with a well-known cyberattack known as an “evil twin.”

“From what I read and see, it’s basically clear that what happened there is some sort of an attempt to do what’s called in the cyber industry ‘evil twin’,” Almog said. “This is something that is not new to the industry, and it’s not new also in aviation.”

What is an “evil twin” WiFi attack?

An evil twin works by creating a wireless network that appears to be a legitimate one a passenger expects to see.

The attacker can give the network a convincing name and potentially recreate the type of landing page passengers would see when connecting to an airline’s WiFi.

“You as a passenger or as a user, you cannot really distinguish between what is a credible, authentic network and what is an evil network,” Almog explained. “Once you log into this evil network, you get some sort of a landing page that looks exactly the same as you expect, with the logo of United or Delta or whatever. Then once you do that, you basically are in the hands of the hacker [to obtain] credentials or maybe credit cards and so on.”

Delta Air Lines selects Amazon Leo Project Kuiper connectivity for in-flight WiFi
Photo: Delta Air Lines

The Delta flight is not the first such occurrence in aviation. Almog pointed to similar attacks carried out at Australian airports and onboard domestic flights in 2024, which subsequently resulted in a prosecution. He also suspects that other similar incidents may have gone undetected or unreported. According to Almog, the incident became public after an aviation enthusiast monitoring ACARS communications noticed messages between the aircraft and Delta operations and posted them online.

What makes aircraft particularly interesting environments for hackers to launch such an attack is that passengers expect connectivity to be intermittent. A legitimate in-flight connection may drop due to coverage or technical issues. When it does, a passenger trying to reconnect may simply select another plausible-looking network.

“When you are frustrated in the middle of your document that you are working [on], any network that you see, you’re trying to get in,” Almog said.

A smartphone could potentially overpower aircraft WiFi

Cyviation has been investigating how easily rogue wireless networks could be created in an aircraft-like environment.

Almog said the company demonstrated in laboratory conditions that it did not necessarily require sophisticated computing equipment.

United Airlines Starlink WiFi
Photo: United Airlines

“We demonstrate in the lab with a phone – not even a computer – with a phone that is able to transmit enough powerful hertz in order to overcome the WiFi of the plane,” he said.

Cyviation’s experiment was conducted in a laboratory, not aboard an aircraft, and should not be interpreted as evidence of what occurred on DL591. Several aspects of the Delta event remain unconfirmed, including whether credentials were collected and whether the legitimate WiFi signal was technically jammed.

Need for “awareness training” for crew

Almog also praised the Delta crew’s response once the suspicious network was identified.

“The pilot identified that there is a network that is not a Delta network named Delta Fast, and what they have done is something very good,” Almog said. “They shut off the WiFi routers completely and basically disabled them for 30 minutes.”

Delta subsequently confirmed that the aircraft’s WiFi functionality was deactivated for roughly that period.

Delta Air Lines Premium Economy cabin
Photo: Delta Air Lines

For Almog, however, the incident raises the question of whether crews should have more formal procedures for identifying and responding to wireless cyber threats rather than relying on individual judgement. He recommends that airlines implement “awareness training” to help crew familiarise themselves with the threat environment and establish protocols for handling potential cyber threats onboard.  

“Give them clear checklist[s] of what to do, not just build on their own kind of judgment at that point,” he said. “Of course, the Delta pilots have done well, but maybe others were not necessarily aware.”

Could an attack move beyond passenger WiFi?

The more serious question is whether wireless attacks could reach other aircraft systems. Delta has been clear that no aircraft systems were hacked during the DL591 incident. Almog also stressed that passengers should not interpret the event as evidence that someone could easily take control of an aircraft.

But Cyviation’s research suggests airlines need to consider the wider digital environment onboard.

Aircraft cockpit instruments
Photo: Maksim Denisenko / stock.adobe.com

One area of concern is electronic flight bags (EFBs), the tablets and other devices used by pilots for operational information. Almog said Cyviation has demonstrated in laboratory testing that a malicious wireless network could potentially trick an EFB user into connecting.

“If the hacker is able to get the pilots to log in by accident to that network, then the hacker can do other stuff,” he said.

Cyviation demonstrated attacks involving malicious pop-up messages to pilots, although Almog stressed that the company is only beginning its research into that area.

Cabin systems present another cybersecurity target

Cyviation has also identified vulnerabilities that could provide WiFi access to an aircraft cabin management system. Almog declined to identify the manufacturer involved because the findings have not been made public.

He stressed that cabin management systems are generally separated from cockpit systems. Compromising one therefore does not mean an attacker could take control of the aircraft.

New Airbus A330 main cabin seats
Photo: Delta Air Lines

However, an attack could still have indirect safety consequences.

“Think about sitting on a plane where the temperature suddenly goes up, or the lights go off, and then on the screen all the passengers have some sort of a ransomware message,” Almog said. “That’s something that can create some sort of a panic, some sort of maybe a distraction to the pilots.”

If pilots were already dealing with weather or heavy traffic, he added, that additional distraction could potentially become a safety issue.

Aviation’s cybersecurity problem moves faster than certification

Part of the challenge is the fundamental difference between the development cycles of aviation and cybersecurity.

Aircraft and avionics are developed and certified over long periods, and failures can have catastrophic consequences. But cyber threats can evolve in months or even days.

“We are flying on new aircraft that were on the design table years ago – and 10, 15 years ago no one knew what would be the cyber capabilities for the hackers,” Almog said. “Even if they were two years ago or three years ago, who thought about what AI can do?”

Cybercrime and Hacking Concept. Hacker Using Computer Virus Program For Cyber Attack
Photo: stock.adobe.com | Prostock-studio

“The technology and the capabilities… are developing much faster than the aviation industry can keep up,” Almog added.

That does not mean aircraft are completely exposed, Almog stressed. Instead, it means airlines, manufacturers and regulators need to continuously identify vulnerabilities before attackers exploit them.

Replacing legacy infrastructure is not straightforward either. A system such as the Instrument Landing System (ILS) cannot simply receive the equivalent of a consumer software update. Changes can affect ground infrastructure worldwide as well as certified avionics installed on thousands of aircraft.

Development and certification of individual avionics systems can take years on their own, Almog noted.

Airlines need to detect cyber threats earlier

Almog believes part of the answer lies in better visibility into what is happening inside the aircraft’s increasingly complex digital environment. He noted other recent incidents involving passengers with problematic network names on their devices, such as “bomb,” which have led to security concerns and flight disruptions, including even military jet escorts for flights entering high-security airspace.   

“Think about some sort of a technology that [is] popping up these problematic names or these suspected devices that might have capabilities that I don’t want to have,” he said.

Technically, airlines could detect suspicious wireless devices or network names before an aircraft departs—at the gate or even at check-in.

Airport check-in desks
Photo: An / stock.adobe.com

Preemptively blocking suspicious networks passengers may carry with them is technically possible, Almog said, although doing so raises substantial privacy and regulatory questions.

Cyviation has been discussing physical cybersecurity risks with regulators through an industry cyber forum, but Almog argues technological development cannot wait for regulation alone.

“We understand regulation takes time. We understand regulation is politics as well. It requires funding, requires talent,” he said. “We are trying to do what we can do faster, develop technologies faster and solutions faster, and we’re just looking for the coordination from the industry to apply these.”

Passengers should not panic about inflight WiFi

Despite the vulnerabilities, Almog’s message to passengers is not to stop using inflight connectivity.

“The passenger does not need to be panicked by this Delta issue,” he said. Almog noted that similar attacks can happen on public networks in hotels and other locations as easily as they can aboard aircraft.

More importantly, Almog said that an ordinary attacker’s ability to progress from a fraudulent WiFi network to controlling an aircraft is extremely limited.

“The capabilities of any such attacker to really take over a plane or mess with the aeroplane is very, very, very, very slim,” he said.

Alaska Airlines will launch Starlink in-flight WiFi connections.
Photo: Alaska Airlines

He believes an attack approaching that level would require capabilities more commonly associated with a state actor. Most cybercriminals are motivated primarily by money and are more likely to engage in attacks that offer financial gains.

For passengers, the immediate defence is much the same at 35,000ft as it is on the ground, in an airport, hotel or coffee shop: check the correct WiFi network name, be wary of unexpected login pages and avoid entering sensitive information when something looks wrong.

“Just be aware,” Almog said, “because it can happen to us everywhere today.”

——————————————————-


Click Here For The Original Source.