A number of attendees of the most recent DEF CON are accused of jamming a Delta flight’s Wi-Fi network during their flight home and attempting to get other passengers to connect to a rogue hotspot they controlled.
A security researcher posted about the attack on social media as it was unfolding, after accessing a message from flight staff to authorities on the ground indicating that the hackers were targeting other passengers and attempting to phish login credentials. Police boarded the flight upon its arrival, questioned the suspects and seized portable Wi-Fi hardware allegedly used in the attack.
Rogue Wi-Fi network appeared after Delta internet service went down
The flight was from Las Vegas to Atlanta on August 10, carrying some amount of passengers that had attended the most recent DEF CON security conference (which had just wrapped up the day before). Investigating authorities say that the attempted hack did not endanger the safety of the flight, but did make the legitimate Delta on-board Wi-Fi network unavailable for about 30 minutes of flight time.
During that time, the hackers executed a “deauthentication attack” by using their portable network gear to send forged disconnection packets out to other passengers using the plane’s Wi-Fi network. The hackers also operated a rogue hotspot under their control called “Delta WiFi Fast” in the hopes that passengers would connect to it upon no longer being able to access the legitimate Wi-Fi. Once connected, the rogue hotspot sent them to a phishing page that reportedly prompted them for login and Google credentials.
An X user going by the handle of “Turbine Traveller” posted about the attack on his account mid-flight after flight staff broadcast an Aircraft Communications Addressing and Reporting System (ACARS) message to Delta corporate security about the unfolding attack. The Delta flight staff was also notified and disabled the legitimate Wi-Fi network for about 30 minutes as a precaution as the flight made its way into Atlanta.
Apparently “several” passengers were involved in the attack, but no information about names or charges have been released. DEF CON takes place annually in Las Vegas for several days in early August at the city’s central convention center, and ran from August 6 to 9 this year. The flight had actually been scheduled to leave the evening of August 9, but was delayed to the following morning due to severe thunderstorms in the Atlanta area.
DEF CON hijinks no longer staying In Vegas
After the story broke, a Reddit poster claimed that they observed at least one of the hackers attempting to do the same thing to the Las Vegas airport public Wi-Fi network shortly before the Delta flight left. There has not been any media confirmation of this incident, however.
Monika Hathaway, head of press for DEF CON, has told media outlets that the conference had a substantial number of deauthorization attack attempts on its own Wi-Fi networks this year that impacted operations at times. Hathaway indicated that the attackers were not identified, but would have been kicked out and banned from the conference had they been.
Redirecting Wi-Fi network users to a fake login portal that tries to harvest credentials is one application of a deauthorization attack, but more dangerous types attempt to more carefully spoof the legitimate access point to have user devices automatically attempt to re-connect to it. A more sophisticated attacker might then execute a man-in-the-middle attack, or simply hope that the victim browses the internet or uses apps that are passing unencrypted data that can be readily picked up.
Everything about this case points to someone who is not all that sophisticated, despite being a DEF CON attendee. Though the culture tends to frown on outright criminality such as was displayed here, the hacking convention is known for all manner of digital vandalism when it is in Vegas. Attendees regularly mess with hotel Wi-Fi networks, jam cell phones and attempt to knock out point-of-sale ordering systems and even slot machines that are inadequately defended. The “fun and games” does occasionally spill over into types of reckless criminal behavior, however, such as an incident at a prior DEF CON in which fake ATMs were scattered throughout the conference floor.
The suspects will most likely not be having fun nor playing games with the federal government, however. Even if no one fell for the fake login portal, the Federal Communications Act makes intentional Wi-Fi network jamming a crime punishable by up to a year in prison and a fine up to $10,000.
But the incident does leave some questions about Delta’s own Wi-Fi network security. Wi-Fi networks generally implement the IEEE 802.11w standard to counter this attack type, which enables the Protected Management Frames (PMF) technology that encrypts and adds additional security checks to management frames (such as deauthentication) that are key to pulling these attacks off.
Ross Filipek, CISO at Corsica Technologies, additionally notes that this incident illustrates that Wi-Fi networks are not automatically trustworthy or secure just because they come from a “big name” provider: “Incidents like this are a reminder that convenience can create trust very quickly. Public Wi-Fi depends on users recognizing the right network. Attackers can take advantage when that trust gets misplaced.”

