An “evil twin” hotspot is a counterfeit wireless network built to imitate a legitimate one, tricking nearby devices into connecting so an attacker can watch what passes through. Security researchers and federal authorities have flagged the tactic as a persistent hazard in airports, hotels, coffee shops, and other places where free internet access is expected. The setup is inexpensive to run and difficult to notice, which is a large part of what makes it effective.
How a counterfeit hotspot mimics a legitimate network
The scheme starts with a name. Every Wi-Fi network broadcasts an identifier, and an attacker simply copies one that travelers already trust, such as a hotel-branded connection or a generic label like “Free Airport WiFi.” A portable router, a laptop, or even a smartphone is enough to broadcast that duplicate identifier. Because the fake access point is often physically closer to victims than the real router, it can present a stronger signal, and devices tend to favor the strongest available option.
The trap tightens when a phone or laptop is set to reconnect automatically to familiar networks. A device that has joined a coffee-chain hotspot in one city may silently latch onto an imposter using the same name in another. From the moment that connection is made, the attacker sits between the victim and the wider internet, a position that gives them a clear view of unencrypted activity.
What an attacker can capture once a device connects
Sitting in the middle of a connection lets an operator log the sites a victim visits and, in many cases, read data that is not properly encrypted. Login names, passwords, credit-card numbers, and other account details can be harvested as they travel. Some evil-twin operations go further by presenting a fake sign-in page, sometimes called a captive portal, that asks visitors to enter an email address, a room number, or a payment method before granting access. Anything typed into that page flows straight to the attacker.
The technique can also be used to push malicious downloads. When a network operator controls the connection, they can attempt to redirect a browser toward a look-alike site or slip tampered files into a download. That combination of eavesdropping and manipulation is why the method is treated as a serious identity-theft and fraud vector rather than a minor nuisance.
Why airports, hotels, and cafes are prime hunting grounds
Public venues are attractive precisely because free Wi-Fi is normal there. Travelers arrive expecting an open network, rarely question a familiar-sounding name, and often move through quickly, which limits the chance that anyone notices a rogue signal. The Federal Trade Commission notes that hotspots in coffee shops, airports, and hotels are convenient but frequently insecure, a gap that leaves room for someone nearby to intercept information or reach into online accounts, according to its public Wi-Fi guidance. Crowds, transient users, and a steady demand for connectivity make these locations efficient places to run the attack.
Warning signs a traveler can watch for
A few clues can expose an imposter network. Seeing two or more networks with nearly identical names in the same spot is a strong hint that one of them is fake. Slight misspellings, added underscores, or extra words such as “Free” tacked onto an otherwise official name deserve suspicion. A sign-in page that demands a password from another account, a Social Security number, or a payment before granting basic access is another red flag, since legitimate venue networks rarely ask for sensitive credentials to let a guest online.
When anything looks off, the simplest check is to confirm the exact network name with staff at the front desk, gate, or counter before joining. Businesses that offer Wi-Fi generally post or can state the precise identifier, and matching it letter for letter removes much of the guesswork.
Steps that blunt the attack
Several habits reduce exposure. Turning off automatic joining, so a device asks before connecting to any open network, stops phones and laptops from silently linking to a look-alike. Sticking to encrypted websites matters as well: a lock icon and an address beginning with https indicate that traffic between the browser and the site is scrambled, which limits what an eavesdropper can read. The Federal Communications Commission advises that a virtual private network, or VPN, encrypts the connection between a device and the internet, shrinking what any intermediary network can capture, in its online-protection guide.
Beyond tools, timing helps. Consumers can hold off on banking, shopping, or logging into sensitive accounts until they are on a trusted connection or a phone’s cellular data. Keeping software and browsers updated, declining to reuse the same password across accounts, and signing out of services when finished all narrow the payoff for an attacker who does manage to intercept a session.
Where victims can report an incident
People who suspect they connected to a rogue hotspot and lost data or money have official channels. The FBI documents Wi-Fi-based fraud among the schemes it tracks and directs the public to file reports through its Internet Crime Complaint Center, part of the guidance on its common frauds and scams resource. Reporting helps investigators map where and how the attacks are spreading, even when an individual case cannot be traced. Anyone who entered card numbers or passwords on a suspicious network should also change affected passwords immediately and alert their bank or card issuer to watch for unauthorized charges.
Evil-twin attacks succeed on trust and momentum, not on sophisticated hacking. A moment spent confirming a network name, a preference for encrypted sites, and a habit of saving sensitive tasks for a secure connection remove most of the advantage an imposter hotspot relies on.
This article was produced with the assistance of AI and reviewed by Morning Overview editors prior to publication.
More from Morning Overview