"Don't open mobile banking on public Wi-Fi." This advice has circulated for well over a decade, and is still repeated today.
Some of it still holds. But the landscape has changed considerably, and following the old advice without understanding why leaves people vigilant about the wrong thing, while the door that is actually open stays that way.
What has changed
When that advice first appeared, many sites and apps sent data unencrypted. Anyone on the same network could potentially read it.
Things are different now. Banking apps encrypt data from the device all the way to the bank's servers, and most also verify the server's certificate so they cannot be fooled by an intermediary. Browsers now refuse unencrypted pages too.
Which means the interception that was once the main worry is now far harder to carry out, but that does not make the risk zero. It has simply moved.
The risks that remain real
| Risk | How often | Network-related? |
|---|---|---|
| Social engineering and OTPs | Very often | No |
| Fake apps from outside official stores | Often | No |
| Your screen visible to people nearby | Often | No |
| Fake networks with similar names | Sometimes | Yes |
| Interception of encrypted data | Very rarely | Yes |
Note the top three rows: none has anything to do with the network you are using. This is what makes the old advice misleading, it directs vigilance at the bottom row, which is the rarest of all.
Fake networks, the one thing that really is about the network
Someone can create an access point with a name resembling a cafe's or an airport's, then wait for people to connect. Once connected, they can steer you to an imitation page.
An official banking app generally refuses to work in this situation because it verifies the server's authenticity. What is more vulnerable is a page opened in a browser, particularly if you dismiss a certificate warning.
The best way to avoid it is simple: ask staff for the correct network name, rather than guessing from the list. The name that looks most plausible is not necessarily the real one. This is discussed more fully in the guide to using public Wi-Fi safely.
Never press "continue" on a certificate warning. The browser shows that warning when a server's identity cannot be confirmed. On a public network, this is one of the clearest signs that something is wrong, and the only correct response is to close the page.
On VPNs
A question that comes up often: is a VPN needed for mobile banking?
Not necessarily. Banking apps already encrypt their own data, and a VPN adds no meaningful layer on top of the encryption already there. What a VPN does is hide your connection's destination from the network operator, useful for other things, but not for protecting a transaction that is already encrypted.
The limits of a VPN are discussed in more detail in the guide to VPNs for public Wi-Fi.
What genuinely protects you
Install apps only from official stores
Fake banking apps are a far more frequently used way in than network interception. Do not install from a link sent in a message, however much it appears to come from the bank.
Treat the OTP as absolutely secret
No bank employee has any right to ask for it, under any circumstances. If someone asks, it is fraud, without exception.
Turn on transaction notifications
This is what tells you within seconds that something is wrong, rather than when you check your statement at the end of the month.
Pay attention to your surroundings
In cafes and airports, the person behind you can see your screen and your finger movements as you type a PIN. This risk is real and entirely overlooked.
Lock the screen and keep the system updated
A phone lost without a screen lock is far more dangerous than any public Wi-Fi. System updates close holes that are already publicly known.
Safer options if you are unsure
If you remain uncomfortable, there are middle grounds better than postponing what you need to do:
- Use mobile data. The operator's network is not open to people around you, and a short transaction uses very little data.
- Tether from your own phone if you need to use a laptop. This avoids unfamiliar networks entirely.
- Postpone large transactions until you are on a network you know. Checking a balance carries a different risk from moving a large sum.
Putting the worry in the right place
Opening an official banking app on cafe Wi-Fi is not reckless. The encryption works, and the interception once feared is now very hard to carry out.
What needs guarding are the things that have not changed: never give an OTP to anyone, never install apps from unofficial sources, and make sure you are connected to the right network.
If the network in question is your own, the steps for securing it are different and covered in the guide to securing a home router.
If you have connected to a suspicious public network and want to be sure nothing is left behind on the device, start by forgetting that network and checking the device, the steps are in the guide to Wi-Fi problems on one device.
Frequently asked questions
Is it safe to open mobile banking on cafe Wi-Fi?
For an official banking app, relatively safe, because the data is already encrypted end to end and the app verifies the server's authenticity. The remaining risk comes more from fake networks and from your screen being visible to others than from interception.
Do you need a VPN for mobile banking?
Not necessarily. Banking apps already encrypt their own data, and a VPN adds no meaningful layer on top of that. A VPN is more useful for other, unencrypted traffic than for an app whose security was built in from the start.
What is a fake network and how do you recognise one?
A network with a name resembling the venue's, created to lure people into connecting. It is hard to spot from the Wi-Fi list, so the safest approach is asking staff for the correct network name rather than guessing.
What is the biggest threat then?
Social engineering, calls or messages claiming to be from the bank, fake apps outside official stores, and requests for an OTP code. None of the three has anything to do with the network you are using, and all are far more common than interception.