Public Wi-Fi scams rarely involve hacking. They work because of one simple fact: the network you join determines where your requests go.
If someone else controls that network, they don't need to break into anything. They only need to answer first.
How it works
Three forms are most common, listed from easiest to set up.
A network that resembles the real one
A network name can be identical to the café's or the airport's, nothing prevents it. Your device picks whichever signal is strongest, and the strongest signal is easy to arrange for anyone sitting closer. This form is covered in more detail in the guide to fake Wi-Fi and evil twins.
A login page asking for more than it should
A login page is a normal thing to see on a public network, how it works is explained in the guide to captive portals. What isn't normal is what it asks for. Imitation pages copy a legitimate design and add fields the original never had.
A quiet redirect
The subtlest form. You type the correct address, but the network sends you to an imitation. This exploits the step that turns names into addresses, the mechanism is explained in the guide to DNS.
You personally aren't usually the target. What's set is a net, not a hook. Because of that, the imitation is often imperfect, and that imperfection is exactly what makes it recognisable.
Signs you can spot in seconds
No expertise required. The four checks below catch nearly every case, and each takes under five seconds.
A certificate warning, stop here
If the browser warns that the connection isn't secure or the certificate has a problem, don't continue. On a public network, this warning is the strongest signal you'll get. The habit of clicking "proceed" is exactly what this kind of scam relies on.
Read the address, not the design
Design is easy to copy; an address isn't. Watch for spelling off by one letter, additions that shouldn't be there, or a brand name appearing in the middle of the address rather than before the final dot.
Ask whether the data makes sense
Joining Wi-Fi needs no account password, no verification code, no card number, no ID number. If one is requested, no explanation makes it reasonable.
Be suspicious of urgency
Countdowns, threats of a locked account, or "two slots left" exist to stop you thinking. A legitimate page is not in a hurry.
What's reasonable to ask, and what isn't
| What's asked | Verdict |
|---|---|
| Accepting terms of use | Reasonable |
| A voucher code from a receipt or table | Reasonable |
| Name and room number at a hotel | Reasonable |
| Phone number or email | Reasonable, though not always necessary |
| Social media or email account password | Never reasonable |
| Verification code from an SMS | Never reasonable |
| Card number or bank details | Never reasonable |
| Installing an app or special profile | Never reasonable |
The last four rows have no exceptions. No legitimate Wi-Fi provider needs your account password to give you an internet connection, and no technical reason makes it necessary.
If you run a venue and are designing a login page, the list above also works as a boundary, and the regulatory side is covered in the guide to collecting customer data.
Habits that close most of the risk
Not a long list. These five cover almost all of it.
- Turn off auto-join for previously used networks. This removes an entire class of attack where the device connects on its own without you noticing.
- Postpone anything important. Banking and payments are better left until you're back on a known network, the reasoning is in the guide to mobile banking on Wi-Fi.
- Turn on two-step verification for accounts that matter. If a password leaks, that second step is what limits the damage.
- Use different passwords per service, so one leak doesn't spread, see the guide to building strong passwords.
- Consider a VPN on genuinely unfamiliar networks. It doesn't close every risk, and its limits are explained in the guide to VPNs on public Wi-Fi.
Other habits for unfamiliar networks are gathered in the guide to using public Wi-Fi safely.
If you've already entered something
Order matters, and the step most often got wrong is the first: many people try changing a password while still connected to the network that caused the problem.
Disconnect from that network
Forget it entirely, so the device doesn't rejoin on its own next time.
Change the password from a different network
Mobile data or your home network. Start with email, since email is the recovery key for almost every other account.
Change it wherever you used something similar
The most tedious part, and the most often skipped. Leaks spread through reused passwords, not through services being broken into one by one.
Turn on two-step verification
On the affected accounts, and on the others while you're there.
Review active sessions
Most services show a list of currently signed-in devices. Sign out anything you don't recognise.
If card details were entered, call the bank
Don't wait for a suspicious transaction first. Blocking a card is far easier than recovering money.
If what leaked is personal data at scale, or concerns a service holding customer records, the reporting route is covered in the guide to reporting a data breach, and your rights over that data in the guide to personal data protection.
If you're the one providing the Wi-Fi
Part of the responsibility sits with the network provider, and most of it is cheap.
- Post the official network name somewhere visible, so guests have something to compare against when a similar name appears.
- Never ask for account passwords on your login page, besides being unnecessary, it teaches guests a habit that's dangerous elsewhere.
- Enable encryption on the guest network rather than leaving it open, the difference is explained in the guide to WPA2 versus WPA3.
- Separate guests from business equipment: see the guide to separating guest networks.
Public Wi-Fi scams work not because they're sophisticated, but because they appear when people are in a hurry and not looking for them.
Two habits close most of it: never click through a certificate warning, and remember that joining Wi-Fi never requires an account password. If something has already been entered, speed is what matters, change passwords from a different network, and start with email.
Frequently asked questions
How can a fake page appear on public Wi-Fi?
The network you join determines where your requests are directed. If someone else controls that network, it can present its own page before you reach the site you wanted, without hacking anything.
What's the fastest sign that a page is fake?
A certificate warning on a public network is the strongest sign there is, and should never be clicked through. After that: an address whose spelling is slightly off, requests for data that makes no sense just to get online, and time pressure.
Is it normal for a Wi-Fi login page to ask for a social media account?
Treat it as suspicious. Joining Wi-Fi requires no account password at all. A legitimate page asks at most for a phone number or email, never a password, never a verification code, and never card details.
What should I do if I've already entered a password?
Disconnect from that network, then change the password from a different one, mobile data or your home network. Change it anywhere else you used something similar, and turn on two-step verification on the affected accounts.