San Diego Comic-Con wrapped on Sunday, and right now a good chunk of the city is sitting in an airport terminal or a hotel lobby, phones nearly dead, bags heavy, hunting for free WiFi. That tired, in-a-hurry moment is exactly when the evil twin goes to work.
An evil twin is a fake WiFi network named to look exactly like the real one. “Airport_Free_WiFi.” “Marriott_Guest.” “SDCC_Shuttle.” You connect, and either a fake login page quietly captures your email and password, or the network pushes what looks like a required update that installs malware. Either way, you thought you were getting online. What you actually did was hand a stranger the keys.
This is not a hypothetical. It has happened, at airports and in hotels, and the cases are on the record.
The airport case: fake WiFi at the gate and in the air
In 2024, the Australian Federal Police charged a 42-year-old man who set up evil twin WiFi networks named to mimic the real ones at the Perth, Melbourne, and Adelaide airports, on domestic flights, and at a former workplace. When travelers connected, they were sent to a fake login page that harvested their email and social media credentials, which can then open the door to their messages, photos, and bank accounts.
It came apart when an airline crew reported a suspicious network during a flight in April 2024. Investigators found dozens of harvested credentials on his devices, and he was charged with nine offenses and later jailed. (Australian Federal Police, Security Affairs)
The setup takes cheap, portable gear and a name that looks right. A crowded terminal full of tired travelers is the ideal hunting ground.
The hotel case: DarkHotel
Hotels have their own long-running example. Security researchers at Kaspersky documented a campaign they named DarkHotel, which compromised luxury hotel networks to target traveling executives specifically. When a guest connected to the hotel WiFi, they were prompted to install what looked like a routine software update, dressed up as Adobe Flash, Google Toolbar, or Windows Messenger. Installing it dropped a keylogger and spyware onto the device.
The targets were not random. DarkHotel went after C-level executives and staff in government, defense, pharmaceuticals, and energy, hitting them while they were on the road and connected to untrusted hotel networks. (Kaspersky)
Why travelers are the target
It is not that travelers are careless. It is that travel strips away every normal defense. You are tired, you are rushed, your phone is dying, and you are on networks you do not control. On top of that, business travelers are carrying exactly the data attackers want: work email, saved logins, access to company systems. That combination is why airports and hotels keep showing up in these stories.
The traveler’s defense kit
None of this means you have to go offline on the way home. A few habits cover almost all of it:
Use your phone’s hotspot instead of public WiFi whenever you can. It is the single biggest upgrade.
Do not trust a network just because the name looks right. Confirm the exact name with airport or hotel staff, and be suspicious of open networks that ask you to log in with an email and password.
Never install an update that a WiFi page pushes at you. Real updates come from the app store or the software itself, not from a network you just joined.
Use a VPN if you have to use public WiFi, and turn off auto-join so your phone stops connecting to open networks on its own.
Save the banking and the password changes for a trusted connection, and keep your devices updated so known exploits have nothing to grab.
Why this matters for a business
One tired employee connecting to a fake network at an airport is not just their problem. Their work login is a door into your systems, and the whole point of an evil twin is to walk through it. This is the part we handle for clients: managed devices, always-on VPN, and policies that make the safe choice the default even when someone is exhausted in a terminal at 11pm. centrexIT is a San Diego managed IT and cybersecurity company, and keeping your team safe on the road is part of the job. People-First. AI-Amplified. Cyber IT.
Want to know where your team is exposed when they travel? Take our 2-minute security assessment and we will walk through it with you.
Sources
- Australian Federal Police, “Man charged over creation of ‘evil twin’ free WiFi networks to access personal data”: https://www.afp.gov.au/news-centre/media-release/man-charged-over-creation-evil-twin-free-wifi-networks-access-personal
- Security Affairs, “Australian man jailed over airport and in-flight Wi-Fi attacks”: https://securityaffairs.com/185205/cyber-crime/australian-man-jailed-for-7-years-over-airport-and-in-flight-wi-fi-attacks.html
- Kaspersky, “DarkHotel APT Attacks: How They Work”: https://www.kaspersky.com/resource-center/threats/darkhotel-malware-virus-threat-definition
The centrexIT team brings decades of combined IT expertise, helping San Diego businesses thrive with secure, reliable technology solutions.
Meet Our Team