Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Sandworm hackers target IT pros with trojanized WireGuard VPN client

    August 11, 2026

    Bitdeer’s $1 billion ATM could dilute Class A shares by 28.8%

    August 11, 2026

    What Is the Nancy Grace Roman Space Telescope? (Grades 5-8)

    August 11, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Sandworm hackers target IT pros with trojanized WireGuard VPN client
    • Bitdeer’s $1 billion ATM could dilute Class A shares by 28.8%
    • What Is the Nancy Grace Roman Space Telescope? (Grades 5-8)
    • Expro scores ‘major’ North Sea plug and abandonment win in UK waters
    • Special prosecutors have strong political ties and practically no public oversight
    • Deadly Earthquake in Colombia Tests President Abelardo De La Espriella
    • Fast and fearless: Baltic defence startups innovate to counter Russian threat
    • Former judge András Baka elected Hungarian president
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Tuesday, August 11
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Delta probes Wi-Fi deauth attack on flight carrying DEF CON attendees

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 11, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Delta Air Lines is investigating an unauthorized Wi-Fi network that appeared aboard a flight from Las Vegas to Atlanta carrying passengers who had attended the DEF CON hacker convention.

    ​The company told BleepingComputer that the incident occurred yesterday on Flight 591 and did not affect the safety of the passengers or aircraft operating systems.

    “We will partner with federal law enforcement and aviation regulators to ensure the incident is thoroughly investigated,” a company spokesperson said.

    image

    “One initial finding is an unauthorized WiFi network, which was not provided, operated, or supplied by Delta, was present onboard the aircraft for a short time during the flight.”

    After learning about the unauthorized wireless network, the cabin crew deactivated the Wi-Fi functionality in the aircraft for nearly 30 minutes.

    Wi-Fi deauth attack

    According to online reports, several passengers returning from the DEF CON 34 hacking conference allegedly carried out a Wi-Fi deauthentication attack mid-flight, disconnecting other passengers from the aircraft’s wireless in-flight network.

    In a deauthentication attack, clients connected to a Wi-Fi network receive forged packets pretending to be from the legitimate access point (AP), telling them to disconnect.

    An attacker can observe wireless traffic to identify the access point’s MAC address, then forge deauthentication frames with the AP’s address as the source and send them to connected clients.

    ​By repeatedly transmitting forged deauthentication frames, the attacker can repeatedly disconnect clients from the access point, potentially causing a denial-of-service condition. Networks that use Protected Management Frames (PMF) can mitigate this type of spoofed management-frame attack.

    By sending the forged deauthentication frames continuously, the attacker can keep the clients disconnected from the legitimate AP.

    Typically, hackers use deauthentication attacks to force clients to reconnect to a rogue AP (e.g., evil twin), to intercept traffic or direct targets to malicious pages.

    Rogue Wi-Fi network

    Turbine Traveller, an aircraft technician based in Nairobi, says messages sent by the crew of Delta Air Lines Flight 591 via the Aircraft Communications Addressing and Reporting System (ACARS) indicated that some passengers were able to jam the aircraft’s Wi-Fi and broadcast a rogue network named “Delta WiFi Fast:”

    “WE HAVE A BUNCH OF PAX [passenger] THAT WERE AT A CYBER CONFERENCE IN LAS… THEY WERE ABLE TO JAM OUR WIFI AND BROADCAST THEIR SIGNAL.”

    “WE HAVE A PAX ON THIS HAS CREATED A SCAM WIFI CALLED DELTA WIFI FAST. WE BELIEVE THEY ARE TRYING TO SCAM THE OTHER PAX.”

    ​Mary Perrault, a member of online frequent flyer groups with no formal affiliation to Delta Air Lines, states that the fake Wi-Fi network showed a phishing page that collected “personal credentials and Google login data.”

    After the aircraft docked at the gate, federal authorities and airport police boarded the aircraft to question the suspects and seize their portable Wi-Fi hardware, Perrault said.

    The suspects allegedly had been attending the DEF CON 34 hacker conference in Las Vegas.

    The Delta Air Lines spokesperson told BleepingComputer that the aircraft was a Boeing 757 with six crew members and 199 passengers. The company said that no emergency was declared with air traffic control.


    article image

    Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

    The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

    Get the report

    attack attendees carrying CON deauth DEF Delta Flight probes WiFi
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Sandworm hackers target IT pros with trojanized WireGuard VPN client

    Houthis reportedly kill six in first deadly attack since start of Iran war

    Cisco warns of ASA and FTD VPN flaw exploited to crash devices

    Researchers Disclose AI-Assisted SharePoint Exploit Chain Reaching Unauthenticated RCE

    Windows 11 KB5121003 & KB5120240 cumulative updates released

    OpenAI Launches GPT-5.6-Cyber with Reduced Safeguards for Exploit Development

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Sandworm hackers target IT pros with trojanized WireGuard VPN client

    August 11, 2026

    Bitdeer’s $1 billion ATM could dilute Class A shares by 28.8%

    August 11, 2026

    What Is the Nancy Grace Roman Space Telescope? (Grades 5-8)

    August 11, 2026

    Expro scores ‘major’ North Sea plug and abandonment win in UK waters

    August 11, 2026
    Latest Posts

    I grew up near Andy Burnham. This is what shaped our new PM | Andy Burnham

    July 25, 2026

    The Economic Philosophy of Britain’s Andy Burnham

    July 25, 2026

    Samsung Wallet Will Add Stablecoin Support, Including USDC

    July 25, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Sandworm hackers target IT pros with trojanized WireGuard VPN client

    August 11, 2026

    Bitdeer’s $1 billion ATM could dilute Class A shares by 28.8%

    August 11, 2026

    What Is the Nancy Grace Roman Space Telescope? (Grades 5-8)

    August 11, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.