cybersecurity data protection public wifi san diego

How to Protect Your Data in Crowds

Crowded events like Comic-Con are hunting grounds for data thieves. Here's how to keep your logins, phone, and accounts safe from fake WiFi, QR scams, and more.

centrexIT Team
6 min read

Comic-Con week turns downtown San Diego into one of the densest crowds in the country. Hundreds of thousands of people, half of them on public WiFi, most of them running low on battery by noon, all of them scanning QR codes for badges, panels, and vendor deals.

To a certain kind of thief, that is not a convention. That is a target-rich environment.

The most valuable collectible on the floor is not the exclusive figure everyone lined up for. It is the data sitting in every pocket: logins, banking apps, work email, the whole kit. And unlike the person in the elaborate costume, the ones after it want you to not notice them at all.

Here is the rogues’ gallery worth knowing this week, and how to keep your data off the table.

Villain 1: The Evil Twin

The move: a fake WiFi network with a name that looks exactly like the real one. “SDCC_Guest,” “Marriott_Free_WiFi,” “Convention_Center_Public.” You connect, you get a login page that asks for your email and password, and you have just handed your credentials to a stranger.

This is not theoretical. In 2024, Australian authorities charged a man who allegedly ran “evil twin” WiFi networks on domestic flights and at multiple airports, spinning up fake access points from a portable device and harvesting email and social media logins from anyone who connected. The names matched the real airport and airline networks closely enough that people did not think twice. (BleepingComputer)

A packed convention center is the same setup with more targets.

The fix: do not connect to a network just because the name looks right. Confirm the exact network name with venue staff, or skip it entirely and use your phone’s hotspot.

Villain 2: The Juice Jacker

The move: you are at 4 percent, you spot a free USB charging station, and you plug in. The risk is that a tampered port or cable can push malware onto your device or pull data off it while you think you are just topping up your battery.

The FCC has warned about this directly. Their guidance: use a regular AC wall outlet instead of a public USB port, carry your own charger and cable, bring a portable battery pack, and if your phone ever asks whether to “share data” or “trust this computer” while charging, choose charge-only. Worth noting for accuracy: the FCC also says it has not confirmed a real-world case, so treat this as low-probability but trivial to avoid. (FCC)

The fix: bring your own battery pack. It solves the security question and the dead-phone-at-3pm question at the same time.

Villain 3: The Quisher

The move: QR code phishing, or “quishing.” A scammer covers a legitimate QR code with their own sticker, or prints a fake one on a flyer, and the code sends you to a spoofed site that steals your login or installs malware. Conventions run on QR codes for check-ins, menus, panels, and vendor promos, which makes them the perfect place to slip a bad one in.

The FTC has flagged this specifically, noting that scammers place malicious codes in unexpected spots, including physical stickers placed over real ones, and pair them with urgent messages like a failed delivery or an account problem. Their advice: inspect the URL before you act on it, watch for misspelled or slightly-off web addresses, and do not scan codes from unsolicited messages. (FTC)

The fix: when a code loads a page asking you to log in or pay, stop and check the web address before you type anything. If it looks even slightly off, close it.

Villain 4: The Eavesdropper

The move: intercepting what you do on public WiFi. The good news, straight from the FTC, is that this threat is smaller than it used to be, because most websites now encrypt your connection. The catch is that scammers build convincing fake sites that look encrypted but are not, so the encryption only protects you if the site itself is legitimate. (FTC)

The fix: look for the lock icon and “https” before you enter anything sensitive, and confirm you are on the real site, not a lookalike. When in doubt, save the banking and the password changes for when you are back on a trusted connection.

Villain 5: The Shoulder Surfer

The move: the oldest one in the book, and it needs zero hacking. In a slow-moving badge line, someone standing behind you can watch you type your passcode, read the email on your screen, or note the card number you just entered. Crowds put strangers closer to your screen than they will ever get in your office.

The fix: shield your screen when you type a PIN or password, tilt your phone away from the person behind you, and think twice before pulling up anything sensitive while packed shoulder to shoulder.

The pocket-sized defense kit

You do not need to be paranoid to be safe this week. Five habits cover almost all of it:

Bring a battery pack so you never need a public USB port. Use your phone hotspot instead of unknown WiFi. Check the web address before you log in or pay through any QR code or link. Look for the lock icon and the real site name before entering anything sensitive. Shield your screen in a crowd.

None of this is exotic. It is the same instinct that makes you keep a hand on your wallet in a packed room, applied to the more valuable thing you are carrying.

Comic-Con is a great week to be in San Diego. Just do not let it be a great week for someone going after your data.

The habits above protect you as an individual. If you run a business, the same crowd risks scale up fast, because every employee on public WiFi or scanning a random code is a door into your systems. That is the part we handle. centrexIT is a San Diego managed IT and cybersecurity company, and helping local teams close those doors before someone walks through them is the whole job. People-First. AI-Amplified. Cyber IT.

Want a plain-language read on where your business is exposed? Take our 2-minute security assessment and we will walk through it with you.

Sources

Found this helpful? Share it with your network.
Written by
centrexIT Team

The centrexIT team brings decades of combined IT expertise, helping San Diego businesses thrive with secure, reliable technology solutions.

Meet Our Team