Passengers on Delta flight 591 lost cabin Wi-Fi for half an hour on Monday while cruising over the middle of the country. The cause wasn’t a faulty router. The airline says a network it didn’t own was transmitting from inside the cabin.
The aircraft was flying from Las Vegas to Atlanta, a day after the DEF CON security conference closed out in Las Vegas. Anyone who has flown out of Vegas during that week can guess what the passenger list looked like.
The pilots said it out loud over ACARS
Delta wasn’t the source of the first public description of what happened. That came from social media accounts that track publicly available air-to-ground messaging, a system known as ACARS.
A message the pilots sent from the aircraft was posted by the “ACARS Drama” account: “NO INFO AS OF NOW WE HAVE A BUNCH OF PAX THAT WERE AT A CYBER CONFERENCE IN LAS THEY WERE ABLE TO JAM OUR WIFI AND BROADCAST THEIR SIGNAL.”
In other words, the crew was informing the ground mid-flight that passengers had commandeered the cabin’s wireless. All caps, no punctuation, typed the way flight crews type.
A network named to look official
An account of the incident shared on Reddit added more detail, claiming the passengers set up a bogus hotspot named “Delta WiFi Fast” paired with a phishing landing page “designed to harvest passengers’ personal credentials.”
That name does all the work. Scrolling through a Wi-Fi list at 35,000 feet, “Delta WiFi Fast” looks legitimate enough, particularly when the genuine network has stopped responding.
Security professionals have known about this approach for years, calling it an “evil twin” attack. The method is simple: stand up a counterfeit Wi-Fi network, then harvest login credentials and other data from anyone who joins it.
Delta confirms an unauthorized network was onboard
Delta spokesperson Morgan Durrant confirmed the details.
“One initial finding is an unauthorized WiFi network, which was not provided, operated, or supplied by Delta, was present onboard the aircraft for a short time during the flight,” Durrant said via email.
According to the airline, the flight’s safety was “never in question and no aircraft operating systems were affected,” and no emergency was declared. Onboard Wi-Fi was shut off for 30 minutes.
That separation is the part worth holding onto. Flight systems and passenger Wi-Fi run apart from one another, and nothing Delta has described contradicts that.
No arrests, and nobody was waiting at the gate
Questions directed to the Atlanta Police Department were passed along to the FBI. The bureau’s Atlanta office said the matter is under review.
According to officials there, nobody was arrested and no FBI agents met the aircraft at the gate. The story making the rounds online, in which federal agents descend on the jet bridge in Atlanta, isn’t what occurred.
“FBI Atlanta is aware of reports regarding a potential Wi-Fi-related incident involving Delta Flight 591,” Tony Thomas, a spokesperson for FBI Atlanta, said in an emailed statement. “We are in contact with our local and corporate partners on this matter. We have no additional information to provide at this time.”
Thomas declined to say anything further.
What to do the next time your plane’s Wi-Fi acts up
The lesson here has little to do with DEF CON attendees. It’s that a captive portal requesting your credentials on an airplane deserves exactly as much trust as one in an airport food court, which is none at all.
Should the cabin network drop out and a near-identical one appear in its place, assume the newcomer is hostile until a crew member tells you otherwise. The network that surfaced on Delta flight 591 wasn’t Delta’s, and it took the airline’s own investigation to determine that.















STAY ALWAYS UP TO DATE