Skip to content

Evil Twin Wi-Fi Hotspot

In plain terms

A Wi-Fi network carrying the name you expect — the café's, the hotel's, the airport's — but belonging to someone else. Nothing distinguishes it from the real one in the list of networks.

Definition

A fake access point is a wireless network published by a third party under a name that imitates a legitimate one, so that devices connect to it and their traffic passes through it. It is the most common form of man-in-the-middle attack in a public place.

How it works

A wireless network's name is just a label that whoever publishes it chooses freely: nothing stops two networks from carrying the same name, and nothing in the list shows which one belongs to the venue. A device that has already known a network with that name can even reconnect to it on its own, without anyone choosing anything — which is why turning off automatic connection to open networks is the single most useful setting to disable. Once the connection is made, all traffic passes through the third party's equipment. What follows depends on encryption, as with any interception: over encrypted connections, it observes destinations; what interests it more is prompting you to type something in, generally through a Wi-Fi login page asking for information no Wi-Fi access actually needs. It is that page, not the interception itself, that most often causes the harm.

Warning signs

  • Two networks with the same name in the same place, or a variant one character apart
  • Open network under the name of a venue that normally hands out a password to its customers
  • Login page asking for an email address with its password, a card number, or the installation of a profile or certificate
  • Connection made on its own in a place you've never been before
  • Certificate warning right after connecting to the network
  • Venue staff don't recognize the displayed network name

How to verify

Ask staff for the network's exact name and how to access it: that's the check that settles it, and it takes ten seconds. Be wary of an open network where the venue normally hands out a password. A login page asking for an email password or bank card details is fraudulent without any further examination: no Wi-Fi access needs that.

What to do

Turn off automatic connection to open networks, and make your device forget public networks once you leave. Never enter an account credential or payment method on a Wi-Fi login page. Don't install any profile or certificate requested by a network. If in doubt, your phone's mobile hotspot is safer than any public Wi-Fi.

If it already happened

From another network, immediately change any credential entered on the login page, as well as any account reusing the same password, and close open sessions. If you shared banking details, contact your bank without delay. If you installed a profile or certificate at the network's request, remove it in the device's settings: it allows connections that encryption was protecting to be observed. Report the incident to the relevant authority.

Frequently asked questions

Is it really risky to use a café's Wi-Fi?
Less than is often said, and not for the usual reasons. Serious sites' connections are end-to-end encrypted: an intermediary sees where you're going, not what you're doing there. The real risks lie elsewhere — a login page that gets you to type a password, a certificate you're asked to install, a download replaced along the way. That's what to be firm about, not using public Wi-Fi itself.
How do I know which of the two networks is the real one?
You can't tell from your device: the name is freely chosen and nothing displayed is authoritative. The only reliable answer comes from the venue itself. Failing that, treat the place as untrusted and use your mobile connection.
My phone connected on its own — is that serious?
That's the normal behavior of a device recognizing a name it already remembers, and it's exactly what this technique exploits. Make your device forget public networks after use and turn off automatic connection: that removes the main way in, at no cost to you.

Official sources

Also known as: evil twin, fake hotspot, rogue access point, rogue AP, fake public Wi-Fi.

This article is part of the Network and Wi-Fi attacks family. Last updated: 2026-09-03.