How a fake hotspot actually works
The simplest version of this scam uses a network name deliberately close to an airport's genuine free Wi-Fi, banking on travellers connecting to whichever plausible-looking option appears first in their device's list without checking it against official signage. A more sophisticated "evil twin" attack goes further, broadcasting the exact same name as the genuine network, so the fake and real versions become indistinguishable by name alone, and only careful cross-checking against airport staff or signage can tell them apart.
Once you connect, your browsing traffic can be routed through equipment the attacker controls, potentially exposing anything sent without its own encryption. Some fake networks add a login or "terms and conditions" page that asks for an email address and password purely to harvest those credentials, counting on the fact that many people reuse the same password across multiple accounts. Others prompt you to install an app or a certificate to "get online", which can grant far deeper access to the device than a normal Wi-Fi connection ever would.
Why airports are a soft target for this
Airports put travellers in an unusually distracted state: juggling luggage, boarding passes and gate announcements while trying to quickly check emails or message someone before boarding. That distraction, combined with genuinely expecting to need Wi-Fi, primes people to accept the first plausible network rather than pausing to verify it, which is exactly the gap this scam is built to exploit.
Travelling through an unfamiliar airport removes another normal safeguard: at home, you generally know what your usual networks look like and would notice something odd, but in an unfamiliar terminal there is no baseline to judge against. The time pressure of waiting for a flight, wanting to make the most of a layover, or needing to confirm onward travel plans further reduces the normal caution most people apply to unfamiliar networks.
What UK law actually covers if your data or money is taken
If a criminal intercepts your login details on a fake network and later uses them to make unauthorised transactions from your account, the Payment Services Regulations 2017 generally require your bank to refund unauthorised payments promptly, typically by the end of the next business day, unless it has reasonable grounds to suspect fraud or gross negligence on your part. If stolen card details are used fraudulently for a purchase between £100 and £30,000 on a credit card, Section 75 of the Consumer Credit Act 1974 offers a separate, additional route.
Separately, unauthorised interception or access to your data or accounts is itself a criminal offence under the Computer Misuse Act 1990. This matters for reporting and for potential prosecution of the people responsible, but it operates independently of, and does not by itself guarantee, getting your money back — that recovery runs through your bank and, where relevant, your card issuer.
Verifying a network before you connect
Confirm the exact official network name from airport signage or by asking staff directly, rather than trusting whichever similarly-named option appears in your device's list, and be immediately suspicious of any network that asks for an email address and password rather than simply accepting the connection. Turn off auto-connect to open Wi-Fi networks in your phone's settings, so your device does not join something automatically without your active decision.
Avoid logging into banking, email, or other sensitive accounts on any public network, even one that appears to be genuine, and use a VPN or your mobile data for anything sensitive while travelling if that option is available to you. Never install an app or accept a certificate purely to gain internet access; a legitimate public Wi-Fi network does not require this.
The first hour after you realise you have connected to something suspicious
Disconnect from the network immediately and avoid logging into anything else on it while you assess what happened. If you entered a password on the network, particularly one you also use elsewhere, change it as soon as you are back on a trusted connection, along with any other account where you reused the same password.
Check your bank app and email account for unusual activity over the following days, not just immediately, since fraudulent use of harvested details is not always instant. If any financial account looks affected, contact your bank's fraud team straight away, and note the exact network name and approximate time you connected, since this detail is useful for any report you make afterwards.
Recovering from data or account compromise
For unauthorised card or bank transactions, report to your bank as soon as you notice them; the Payment Services Regulations 2017 generally require prompt reimbursement for genuinely unauthorised payments, though this is not automatic in every case and depends on the circumstances, including whether the bank considers you to have acted with gross negligence. Reporting promptly, with as much detail as you can provide, generally supports a stronger claim than reporting after a long delay.
Beyond the immediate financial transaction, change any reused passwords across other accounts, enable two-factor authentication wherever it is available, and report the incident to Action Fraud so it feeds into the wider national picture. If you are concerned about identity theft rather than just a single fraudulent payment, it is worth asking your bank about further monitoring options.
How airport Wi-Fi scams are evolving
The equipment needed to run an evil twin attack has become cheaper and more automated, lowering the barrier to setting one up convincingly in a busy public space like an airport terminal. Fake captive portal login pages, the screen you see immediately after connecting, are also becoming closer visual matches for genuine airport or airline branding, removing one of the more obvious tell-tale signs that used to help travellers spot a fake.
A related and increasingly common tactic pairs fake Wi-Fi with QR codes displayed near gates or seating areas, inviting travellers to "scan to connect" to a network that leads to a phishing page rather than genuine internet access. Treating an unexpected QR code with the same suspicion as an unfamiliar network name is a sensible extension of the same underlying caution.
Who is most at risk and why
Business travellers checking work email or handling sensitive accounts between flights are a frequent target, since compromised work credentials can have consequences well beyond the individual traveller. Frequent flyers who have simply grown used to connecting to airport Wi-Fi as a matter of routine are also at risk, precisely because habit tends to reduce the moment of active checking that catches a fake network before you connect.
International travellers relying on airport Wi-Fi because roaming data is expensive or unavailable on their plan are particularly exposed, since they may feel they have little choice but to connect to whatever is available. Anyone transiting an unfamiliar airport, where they have no prior sense of what the official network name or signage should look like, faces the same heightened risk for the same underlying reason.
How it works
- A fake hotspot is broadcast with a name closely mimicking the airport's genuine free Wi-Fi network
- Connecting may route your browsing through the attacker's equipment, potentially exposing unencrypted traffic
- Some fake networks show a login or "terms and conditions" page asking for an email address and password, harvesting credentials that are often reused across other accounts
- Attackers may also use "evil twin" attacks that clone a legitimate network exactly, making the fake and real versions indistinguishable by name alone
Red flags
- Multiple similarly-named Wi-Fi networks showing in your device's list at the airport
- A login page asking for an email and password rather than just accepting the connection
- Being asked to download an app or a certificate to access the internet
- No official signage confirming the exact network name to use
How to protect yourself
- Check airport signage or ask staff for the exact official network name before connecting
- Avoid logging into banking, email, or other sensitive accounts on any public Wi-Fi network
- Use a VPN if you need to access sensitive accounts while travelling
- Turn off auto-connect to open Wi-Fi networks in your phone's settings
- Consider using your mobile data instead of public Wi-Fi for anything sensitive, if you have signal or roaming
If it happens to you
- If you entered a password on a suspicious network, change that password immediately (and anywhere else you reused it) once on a trusted connection
- Monitor your bank and email accounts for unusual activity in the days that follow
- Report the incident to Action Fraud (actionfraud.police.uk) and consult the National Cyber Security Centre's guidance for further steps
Also useful: Action Fraud · Information Commissioner's Office · Citizens Advice