Skip to content

Wi-Fi Deauthentication Attack

In plain terms

Your device is repeatedly disconnected from Wi-Fi until you choose another network. The drop isn't a glitch: it's the goal.

Definition

A deauthentication attack consists of repeatedly forcing devices off their wireless network. It grants access to nothing by itself: its function is to be the setup for something else, usually a switch to a fake access point.

How it works

Some wireless networks, particularly those relying on older generations of the standard, accept connection-management messages that aren't authenticated: a device can therefore be told to disconnect without that instruction being verified. This entry doesn't go further into the detail, which would give a reader nothing useful and a would-be attacker a great deal. What matters is the use made of it: the disconnection alone is of no interest, it serves to trigger a decision. A disconnected device looks for a network, and a person annoyed by repeated drops picks another one — whichever stays available, often open, often under the expected name. That's where the harm begins. A second use exists, aimed at the equipment rather than at you: cutting off wireless cameras or sensors, whose recording stops without anyone being alerted. Recent generations of wireless security protect these management messages, which makes keeping equipment up to date more useful here than any amount of vigilance.

Warning signs

  • Repeated Wi-Fi disconnections despite good signal and no configuration change
  • Drops affecting several devices at the same time, and only them
  • An open network with a similar name appearing right as your own becomes unstable
  • Wireless camera or sensor repeatedly losing connection, especially at night
  • Everything returns to normal as soon as you leave the premises

How to verify

Distinguish a fault from a maneuver: disconnections affecting every device in a location, with good signal, no configuration change, and during which an open network with a similar name appears, don't look like a hardware incident. Test a mobile hotspot from your phone: if it stays stable, the problem is indeed on the local wireless network.

What to do

The reflex that matters is not giving in to the disconnection: don't join an open network simply because your own has become unstable — that's exactly the decision being sought. Use your mobile connection in the meantime. Keep your router and equipment up to date and enable the most recent wireless security level they support, since current generations protect the management messages targeted here.

If it already happened

If you connected to another network during the drops, treat the situation as a fake access point: from a trusted connection, change the credentials entered at that time and remove any installed profile or certificate. For a wireless surveillance system that keeps dropping, consider a wired link, since the disconnection is itself the goal here. Report the incident to the relevant authority.

Frequently asked questions

How do I tell this apart from a simple router fault?
By the context rather than the drop itself. A fault doesn't come with an open network with a similar name appearing, doesn't stop when you change location, and doesn't spare wired devices. If all of that lines up, the hypothesis deserves to be taken seriously.
What's at risk for a wireless surveillance camera?
The interruption of the recording, which is precisely the goal in that use case — and the absence of footage doesn't alert anyone at the time. For equipment surveillance depends on, a wired link removes the vulnerability rather than reducing it.

Official sources

Also known as: deauthentication attack, deauth attack, forced Wi-Fi disconnection, Wi-Fi jamming.

This article is part of the Network and Wi-Fi attacks family. Last updated: 2026-09-03.