For years I really enjoyed working on my laptop on a plane. Without WiFi I was disconnected from the barrage of emails and IM’s. I enjoyed uninterrupted deep thought, planning, and personal reflection free of distractions. Unfortunately, Wi Fi is now the norm on most planes. My cross-country jaunts are punctuated by emergency requests, direct messages (DM’s) and instant messages (IMs). With this last bastion of non-connectivity gone, should I have cybersecurity concerns? Is WiFi at 40,000 feet safe?
Unfortunately, the answer is no, it is definitely not safe! Recent federal advisories highlight critical cybersecurity risks associated with in-flight Wi-Fi. Recent howto articles have shown how easy it is to stand up a rogue WiFi access point (AP) on a plane and co-opt unsuspecting travelers into connecting to this person-in-the-middle attack even at 40,000 feet in the air! Let’s explore these risks and what you can do to protect yourself.
Airplane Wi-Fi, while allowing passengers to stay connected, exposes them to various risks. According to the federal advisory issued in July 2024, the primary concern is that in-flight Wi-Fi networks are often unencrypted, making it easy for malicious actors to intercept communications between passengers and the Internet. Secondly, cheap networking equipment can easily stand up rogue, malicious Wi-Fi networks for unsuspecting passengers to connect to. Finally, weak network security configurations, shared access points, and a lack of robust authentication methods compound these risks.
In-flight Wi-Fi is a shared public network, which means that once connected, all passengers’ devices are visible to each other. This makes it easier for malicious actors to identify and target vulnerable devices. Compounding this openness is the fact that most travelers fail to implement proper security measures such as a VPN, leaving their data wide open for theft.
Moreover, airlines prioritize convenience and speed over robust security protocols. As a result, many networks lack the sophisticated encryption and authentication standards you’d expect from a secure network. This lack of protection creates fertile ground for cybercriminals.
Connecting to a rogue access point on an airplane puts your equipment at risk of a person-in-the-middle (PITM) attack. Hackers have been caught standing up fake Wi-Fi networks, and scanning all traffic passed through the Fake WiFi network for sensitive data to steal, while forwarding it on to the legitimate airline Wi-Fi network. Unsuspecting passengers are open to a host of additional risks when connected in this fashion.
Even though the risks are real, there are ways to reduce your exposure. Consider the following precautions when using airplane Wi-Fi:
The federal advisory suggests that airline companies should strengthen the security of their in-flight networks, and passengers should remain alert. Moving forward, airlines will need to adopt stronger encryption protocols, implement multi-factor authentication for network access, and monitor for rogue access points and alert personnel on the plane to investigate, and monitor for additional emerging security threats.
In the meantime, passengers must prioritize their own security when flying, keeping in mind that public Wi-Fi—whether on a plane or elsewhere—presents inherent risks.
For travelers who wish to stay connected at 40,000 feet you must recognize the associated cybersecurity risks. With man-in-the-middle attacks, malware infections, and unencrypted data transfers, in-flight Wi-Fi poses numerous threats to your personal and business information. By taking appropriate precautions, such as using a VPN, avoiding sensitive transactions, and keeping devices updated, you can better protect yourself from the Wi-Fi dangers.
Fly high, stay wise—protect your data and avoid costly surprises.
Discover and share the latest cybersecurity trends, tips and best practices – alongside new threats to watch out for.
Stop tricking employees. Start training them. Take Control of Your Security Awareness Training with a Platform...
Read moreA recent discovery by cybersecurity firm Oligo Security has unveiled a series of critical vulnerabilities in...
Read moreGet sharper eyes on human risks, with the positive approach that beats traditional phish testing.