Public Wi-Fi, like you might find at a café or a hotel, is a common convenience for many people. Travelers find these internet access points to be especially helpful when trying to avoid roaming charges or simply sip at their data plan. They can even be necessary for international travelers who don’t have access to the cell network in whatever country they are visiting. One Wi-Fi scam, though, is so easy to fall into you might not be able to tell it’s even happening.
The Evil Twin Attack
This might be one of the most basic and easily executed digital attacks there is and knowing how it works can help protect you from it.
Step 1: Find a place with where people want to access Wi-Fi. This is any place that commonly has a Wi-Fi network available. Coffee shops, cafés, airports, libraries, anything like that will work. Wherever the place is, so long as it has a Wi-Fi network for people to access and a bunch of people wanting to use it, it’s an ideal target.
Step 2: Once the target place is determined, the hacker will physically set up at the location, and this is where the attack begins. The attacker makes their own Wi-Fi network that copies the name of the legitimate network; that means that if the real Wi-Fi network is called Dark Roast Wi-Fi, the hacker will create a second network also called Dark Roast Wi-Fi. This step can be done with almost any device these days, including cellphones, laptops, tablets, and portable routers. The point is, you cannot just look around for a suspicious device and be alerted.
These Evil Twin attacks are so easy to execute, there’s nothing that will look out of place. It’s a very simple Wi-Fi Scam
Step 3: The hacker will try to encourage people to connect to the fake Wi-Fi. This is often done by making the signal stronger by using a more powerful antenna or simply moving closer to someone. By having a stronger signal, people are more likely to connect to that network. It could also force devices to connect to the network automatically if that option is selected on the device (more on this later).
Step 4: Once the fake network is established, the attacker may even go so far as to create a fake credential page. Many Wi-Fi access points ask you to login or register in some way before you use them and people are primed to accept this. This part of the attack is not necessary, but is quite common.
Step 5: Now that the target individual has connected to the fake network and is having their traffic routed through the hacker’s device, everything is vulnerable. The attacker can now monitor all of your traffic, observing everything you do, and possibly injecting malicious software onto your device without you even knowing.
What an Evil Twin Attack Might Look Like
Let’s game out a quick example of how this might play out in the real world.
You’ve been on a Virgin Voyages cruise for that last week, but’s it’s time to head back home. You’ve got a 6PM departure from MIA and there’s nothing to do but wait. You wanted an earlier flight, but those were more expensive and you didn’t mind waiting too much. You settle in at the gate for a bit and figure that you may as well get some work done before you get back to the office, you just know that there’s a pile-up waiting for you.
After grabbing a coffee from the Starbucks and settle in near one of the few available power outlets. Opening up your laptop, you find the airport Wi-Fi, which was a little odd because there were two of them with identical names. You choose the one with the stronger signal and connect to it. It asks you for some basic information, like your email address, first and last name, and birthday.
Now you’re online and you start answering emails and taking care of work. You also check your bank account and make sure that there’s no suspicious charges on your card. You’ve been away after all and you went to some strange restaurants, who knows if someone stole your card number when you handed it to the server. Everything seems fine and you get a jump start on those Monday morning emails. Unfortunately, all that was done through a fake network and you’ve compromised all sorts of information.
How Dangerous is an Evil Twin Wi-Fi Scam?
The reason that I bothered to write up such a banal story as an example is to demonstrate just how simple it is to fall prey to this attack. It’s amazingly simple and it can happen anywhere that Wi-Fi exists as a public access point. I wrote about Carnival Cruise Lines and their associated companies as well as Royal Caribbean and the lines they own all banning routing devices, and this is the exact type of attack I think they fear.
Here’s the bad news, these attacks are potentially quite dangerous. You really need to be vigilant when using Wi-Fi in public.
The good news is that these attacks are fairly easy to avoid if you take a few simple precautions.
Use mobile networks or your own hotspot
If you can, just use the cell network on your phone. This could mean using your cell phone as a hotspot or having your own mobile hotspot device, often called a jetpack. Staying on your own mobile connection will be very secure.
Avoid Unsecure Hotspots
These days, many devices will warn you or make you double check if you connect to an unsecure network. These unsecure networks are very common as Evil Twin attacks. Don’t connect to them.
Yes, these warnings can be frustrating, but they are also actively protecting your computer. Pay attention to them!
Check any warnings
If your computer/phone/tablet/browser/etc. starts giving you warnings that something isn’t secure, listen to it! Quit dismissing those things and pay attention.
Use a VPN and Stick to HTTPS
Without going into all the technicalities of why and how a VPN protects you, suffice it to say that they do. However, they need to be a reliable VPN. We use Nord VPN, which is a very common and reliable VPN and something that many people are aware of. To be clear this is not an endorsement nor an advertisement. There are many trustworthy VPNs available and you should consider getting one.
Another more technical bit is making sure that you are browsing websites in “https”. This is the start of websites that you can see in your browser’s address bar. Safe sites should show https at the start of their web address like, https://farfarawaytravels.com/. This simply represents a more secure type of connection.
Avoid logging into your accounts on public Wi-Fi
One way to protect yourself is to just not access anything you have to log into. This means don’t log into your bank or other financial accounts. It also means don’t check email, social media sites, or anything else that you sign in to.
What Can You do if You’ve Been a Victim of an Evil Twin Attack?
If you suspect you’ve been a victim of one of these attacks, immediately contact your financial institution. Should you see any suspicious charges on your cards or transfers from your accounts, that’s a sign that you’ve had your information stolen.
You also absolutely must change your passwords if you suspect you’ve been the victim of any Evil Twin Wi-Fi scam.
I wish that there was better advice about reconstructing things that I could give, but that would just be fantasy. Right now, the best defense is good defense. Avoiding these types of Wi-Fi scams is the best thing you can do to keep yourself safe because coming back from them is a lot harder than falling into them.

