Delta, FAA probe rogue Wi-Fi network on Las Vegas-to-Atlanta flight carrying DEF CON attendees
A Delta passenger jet takes off from Harry Reid International Airport Wednesday, Feb. 18, 2026. Photo by: Steve Marcus
Wednesday, Aug. 12, 2026 | 1:19 p.m.
Delta Air Lines and federal authorities are investigating an unauthorized wireless network that appeared aboard a Boeing 757 midflight Monday, shortly after thousands of cybersecurity professionals departed Las Vegas following DEF CON 34, one of the world's largest hacking conferences.
Delta Flight 591, carrying 199 passengers and six crew members, was en route from Harry Reid International Airport in Las Vegas to Hartsfield-Jackson Atlanta International Airport on Monday when the rogue network was discovered, according to the airline.
Pilots messaged corporate security about 60 minutes into the flight via the Aircraft Communications Addressing and Reporting System, known as ACARS, reporting that a passenger had created a "scam Wi-Fi" network named "Delta WiFi Fast," according to BleepingComputer, a cybersecurity news site that first detailed the ACARS transmissions.
Those messages, independently intercepted by ground-based ACARS receivers and shared publicly by an aircraft technician known online as Turbine Traveller, quoted the crew as reporting: "We have a bunch of pax that were at a cyber conference in Las Vegas. They were able to jam our Wi-Fi and broadcast their signal."
The unauthorized hotspot routed connecting passengers to a phishing website designed to harvest Google login credentials, according to View From the Wing, an aviation industry trade publication. Cybersecurity experts describe the technique as an "evil twin" attack, in which an attacker deploys a rogue Wi-Fi access point that mimics a legitimate, trusted network by cloning its name and settings, as CyberScoop, a cybersecurity news outlet, reported.
Cabin crew shut down the plane's Wi-Fi for about 30 minutes as a precaution. Delta confirmed no emergency was declared with air traffic control.
"Safety of flight was never in question, and no aircraft operating systems were affected. We are fully investigating to gather a complete set of facts, which will take time," Delta said in a statement provided to multiple outlets, including CBS News Atlanta and WSB-TV, the Atlanta ABC affiliate. "We will partner with federal law enforcement and aviation regulators to ensure the incident is thoroughly investigated. We thank our crew for their professionalism and our customers for their understanding."
Delta said an initial review confirmed the network was not provided, operated or supplied by the airline, and the company has not determined whether any passenger information was compromised.
The Atlanta office of the FBI acknowledged awareness of the incident but declined further comment, CyberScoop reported. The Transportation Security Administration referred inquiries to the FBI. The FAA said it was looking into the report and noted that a breach of an onboard Wi-Fi system would not affect a flight's critical safety systems, CyberScoop reported.
FBI agents met the plane at the gate upon its arrival in Atlanta and questioned passengers and confiscated devices, according to TechCrunch, the technology news site. No arrests had been announced as of Wednesday.
DEF CON spokesperson Monika Hathaway told Bloomberg, the financial and business news organization, that conference organizers had not been contacted by Delta or law enforcement but planned to launch their own investigation.
"DEF CON does not encourage or condone illegal activities," Hathaway said. "If one of our attendees was involved, we will ban them from attending in the future and apologize to everyone affected."
DEF CON, which bills itself as the world's largest hacking and security conference, was founded in 1993 by Jeff Moss and has grown into a major annual event in Las Vegas attracting cybersecurity professionals, researchers, government officials and technology enthusiasts.
Interfering with in-flight Wi-Fi is prohibited by the FCC, and a phishing login page could constitute additional federal violations, according to Tom's Hardware, a technology news and review publication.