DEF CON Attendees Allegedly Cause Mid-Flight Wi-Fi Disruption on Delta, Sparking Federal Probe
A recent **Delta Air Lines** flight from Las Vegas to Atlanta, carrying attendees from the **DEF CON** hacker convention, experienced a significant Wi-Fi disruption. An unauthorized network, believed to be a rogue access point, appeared onboard, leading to a federal investigation into a suspected deauthentication attack and potential phishing attempt.
### Rogue Wi-Fi Network Emerges Mid-Flight
**Delta Air Lines** is currently investigating an incident involving an unauthorized Wi-Fi network that appeared on **Flight 591** from Las Vegas to Atlanta. The flight was carrying numerous passengers who had just attended the **DEF CON 34** hacker convention.
The airline confirmed to BleepingComputer that an "unauthorized WiFi network, which was not provided, operated, or supplied by Delta, was present onboard the aircraft for a short time during the flight." While the incident did not compromise aircraft safety or operating systems, it prompted the cabin crew to deactivate the aircraft's legitimate Wi-Fi functionality for approximately 30 minutes.
### Suspected Deauthentication Attack and Phishing Attempt
Online reports suggest that several passengers returning from **DEF CON 34** allegedly initiated a Wi-Fi deauthentication attack. This type of attack involves sending forged deauthentication packets to clients, compelling them to disconnect from the legitimate Wi-Fi access point (AP). By continuously transmitting these frames, an attacker can effectively create a denial-of-service condition for connected users.
Beyond simply disrupting connectivity, deauthentication attacks are often a precursor to more malicious activities, such as forcing clients to connect to a rogue AP β sometimes referred to as an "evil twin." In this scenario, the rogue AP can be used to intercept traffic or direct targets to malicious web pages.
### "Delta WiFi Fast" β A Scam Network?
Messages sent via the **Aircraft Communications Addressing and Reporting System (ACARS)** from the crew of **Delta Air Lines Flight 591** reportedly indicated that passengers were not only able to jam the aircraft's Wi-Fi but also broadcast a rogue network named "Delta WiFi Fast." According to **Turbine Traveller**, an aircraft technician, crew communications stated: βWE HAVE A BUNCH OF PAX [passenger] THAT WERE AT A CYBER CONFERENCE IN LASβ¦ THEY WERE ABLE TO JAM OUR WIFI AND BROADCAST THEIR SIGNAL.β Another message reportedly read, βWE HAVE A PAX ON THIS HAS CREATED A SCAM WIFI CALLED DELTA WIFI FAST. WE BELIEVE THEY ARE TRYING TO SCAM THE OTHER PAX.β
**Mary Perrault**, a member of frequent flyer groups, further claimed that this fake Wi-Fi network allegedly displayed a phishing page designed to collect "personal credentials and Google login data."
### Federal Authorities Intervene
Upon the aircraft's arrival at the gate, federal authorities and airport police reportedly boarded **Flight 591**. Their objective was to question the suspects and seize any portable Wi-Fi hardware involved in the incident, as reported by Perrault.
**Delta Air Lines** confirmed that the aircraft was a **Boeing 757** carrying six crew members and 199 passengers, and no emergency was declared with air traffic control. The airline has pledged to collaborate with federal law enforcement and aviation regulators to ensure a thorough investigation into the matter.

### The Blue Report 2026: Understanding Post-Initial Access Risks
While robust initial prevention is crucial, the **Blue Report 2026** highlights a critical vulnerability: once attackers gain valid credentials, only 37% of their subsequent actions are blocked. This significant drop in prevention after initial access underscores the importance of continuous monitoring and defense across the attack lifecycle. The report, which analyzes 338 million simulations in customer production environments, provides a detailed, technique-by-technique measurement of defenses. Security professionals are encouraged to review the report to better understand and mitigate post-initial access risks.
[Get the report](https://hubs.li/Q04sB3fb0)