This attack requires breaking into nothing. No password is cracked, no security flaw is exploited.
All it takes is a transmitter costing very little, and one weakness present in every phone: it recognises a network purely by its name.
How it works
Your phone keeps a list of networks it has used. When it detects a matching name, it connects by itself, that's a feature, and it's what makes home Wi-Fi feel seamless.
The problem is that only the name is matched. Not the owner, not the equipment, not the location.
The name is copied
Someone sits in a café, notes the network name in use, then creates a new network with exactly that name.
The signal is made stronger
Devices tend to pick the strongest signal among identical names. Sitting closer to the target is enough to win that choice.
The device connects by itself
Nothing needs clicking. A phone that has used that network before reconnects automatically the moment it finds it again.
Traffic passes through the attacker's equipment
The internet keeps working normally, that's the important part. Nothing feels wrong to the person affected.
What makes it effective is precisely that nothing breaks. Pages still open, messages still send, and no warning appears anywhere.
Why the padlock doesn't help
This is the most common misconception, and worth correcting on its own.
The padlock icon in the network list means exactly one thing: this network asks for a password. It says nothing about who is running it.
Whoever builds a fake network can set a password, even the same one as the real network, since café Wi-Fi passwords are usually written on the receipt or a chalkboard. The result is a fake network with a padlock, looking exactly like the genuine one.
What makes it worse. Some people check for the padlock, feel safe, and become less careful afterwards. False confidence often costs more than not checking at all.
The login page is where the damage happens
This is where real losses usually occur.
Once connected, an official-looking login page appears, the café's logo, matching colours, a plausible form. That page was built entirely by the attacker, and whatever you type into it goes straight to them.
Signs worth treating as suspicious on such a page:
- Asking for another account's password: email, social media, or banking. No legitimate Wi-Fi network needs it.
- Asking you to install an app or configuration profile. This is the most dangerous, because such a profile can read your traffic from then on.
- Asking for card numbers for a service advertised as free.
- Asking you to install a security certificate. Accepting one makes your encrypted connections readable.
How legitimate login pages work, and why they appear on their own, is explained in the captive portal guide.
Signs you can spot
| Sign | What to notice |
|---|---|
| Two networks with the same name | One with a padlock, one open, treat as suspicious |
| Nearly identical names | An extra space, letter O replaced by zero |
| Very strong signal far from the venue | Café Wi-Fi shouldn't be at full strength across the street |
| Suddenly asked to log in again | Especially if you were already connected fine |
| Certificate warning in the browser | The most serious sign, stop there |
That last row deserves emphasis. A certificate warning means something is trying to read a connection that should be encrypted. Pressing "continue anyway" discards the only protection you have left.
What actually protects you
In order of effectiveness:
Turn off auto-connect for public networks. This single step closes the most risk, because it removes the "connected without you noticing" part entirely. On both Android and iOS, the option sits in the details of each saved network.
Forget public networks when you're done. The hotel network you used last month is still stored on your phone, and its name can be copied anywhere you happen to be.
Switch on your VPN before connecting, not after. Your traffic contents become unreadable even while passing through someone else's equipment. Its limits are covered in the guide to VPNs for public Wi-Fi.
Use mobile data for anything that matters. To open mobile banking or enter a password, tethering from your own phone is far simpler than weighing up whether this network is genuine, the guide to mobile banking security on Wi-Fi.
Ask staff for the network name. It sounds trivial, but it's the only check that genuinely works. Takes ten seconds.
The full routine for everyday use is in the guide to using public Wi-Fi safely.
If you run the venue
You can't stop anyone creating a network with the same name, Wi-Fi names can't be registered or protected. But several things make it harder:
- Display the network name where it's visible, spelled exactly. Visitors who know the correct name are more likely to notice something is off.
- Provide a QR code on the table. Besides being convenient, it removes the guesswork about which name is right, the guide to making a Wi-Fi QR code.
- Use WPA3 where devices support it. It complicates some of the techniques used to push devices onto a fake network, the guide to WPA2 vs WPA3.
- Avoid overly generic names like "Free WiFi". A specific name is harder to imitate without looking suspicious.
Liability when your network is used to harm others is covered separately in the guide to Wi-Fi owner responsibility.
How worried to be
Worth keeping in proportion. This attack requires someone physically present in the same place as you, and most modern traffic is already encrypted, so what an attacker can actually read is far less than it was a few years ago.
What remains vulnerable is whatever you type into a fake page yourself. Which is why one habit is worth more than the entire list above: never type any account password into a page that appears after connecting to Wi-Fi.
Signs that your own network has been compromised are covered in the guide to signs your Wi-Fi has been compromised.
Frequently asked questions
What is an evil twin attack?
A Wi-Fi network deliberately created with exactly the same name as a real network at a venue, so visitors' devices connect without suspicion. Once connected, all their traffic passes through the attacker's equipment.
Why does my phone connect to a fake network by itself?
Because phones remember networks they've used and reconnect automatically when they find the same name. They can't tell which is genuine, the only thing matched is the name, and anyone can copy a name.
Does the padlock icon mean a network is safe?
No. The padlock only means the network requires a password, and whoever built a fake network can set a password too, even the same one as the real network. The padlock says nothing about who is running it.
Is a VPN enough protection against this?
It helps considerably, because your traffic contents become unreadable even while passing through someone else's equipment. But a VPN must be switched on before connecting, and it doesn't protect you from a fake login page asking you to type a password.