Links marked * may earn us a commission at no extra cost to you. We do not provide financial advice. How we make money.

Travel scam

Airport public Wi-Fi scams

By Emma Walsh Updated 8 July 2026 7 min read
Quick Answer

Criminals set up Wi-Fi hotspots with names deliberately similar to an airport's genuine free network, sometimes requiring a login via a fake portal that harvests card details or credentials. How to verify the real network, what a fake portal looks like, and the safe alternatives follow below.

The numbers that matter

Unauthorised transaction refunds
Generally due by the next business day Under the Payment Services Regulations 2017, banks must refund unauthorised card payments promptly, unless they suspect gross negligence or fraud on your part.
Section 75 protection
£100–£30,000 on a credit card Applies if stolen card details are later used fraudulently for a qualifying purchase made on your credit card.
Computer Misuse Act 1990
Unauthorised access is a criminal offence Intercepting data or accessing accounts without permission is prosecutable under this Act, separate from any financial recovery route.
Reporting route
Your bank first, then Action Fraud Contact your bank immediately for account security, then report to Action Fraud for the wider fraud investigation.

How a fake hotspot actually works

The simplest version of this scam uses a network name deliberately close to an airport's genuine free Wi-Fi, banking on travellers connecting to whichever plausible-looking option appears first in their device's list without checking it against official signage. A more sophisticated "evil twin" attack goes further, broadcasting the exact same name as the genuine network, so the fake and real versions become indistinguishable by name alone, and only careful cross-checking against airport staff or signage can tell them apart.

Once you connect, your browsing traffic can be routed through equipment the attacker controls, potentially exposing anything sent without its own encryption. Some fake networks add a login or "terms and conditions" page that asks for an email address and password purely to harvest those credentials, counting on the fact that many people reuse the same password across multiple accounts. Others prompt you to install an app or a certificate to "get online", which can grant far deeper access to the device than a normal Wi-Fi connection ever would.

Why airports are a soft target for this

Airports put travellers in an unusually distracted state: juggling luggage, boarding passes and gate announcements while trying to quickly check emails or message someone before boarding. That distraction, combined with genuinely expecting to need Wi-Fi, primes people to accept the first plausible network rather than pausing to verify it, which is exactly the gap this scam is built to exploit.

Travelling through an unfamiliar airport removes another normal safeguard: at home, you generally know what your usual networks look like and would notice something odd, but in an unfamiliar terminal there is no baseline to judge against. The time pressure of waiting for a flight, wanting to make the most of a layover, or needing to confirm onward travel plans further reduces the normal caution most people apply to unfamiliar networks.

What UK law actually covers if your data or money is taken

If a criminal intercepts your login details on a fake network and later uses them to make unauthorised transactions from your account, the Payment Services Regulations 2017 generally require your bank to refund unauthorised payments promptly, typically by the end of the next business day, unless it has reasonable grounds to suspect fraud or gross negligence on your part. If stolen card details are used fraudulently for a purchase between £100 and £30,000 on a credit card, Section 75 of the Consumer Credit Act 1974 offers a separate, additional route.

Separately, unauthorised interception or access to your data or accounts is itself a criminal offence under the Computer Misuse Act 1990. This matters for reporting and for potential prosecution of the people responsible, but it operates independently of, and does not by itself guarantee, getting your money back — that recovery runs through your bank and, where relevant, your card issuer.

Verifying a network before you connect

Confirm the exact official network name from airport signage or by asking staff directly, rather than trusting whichever similarly-named option appears in your device's list, and be immediately suspicious of any network that asks for an email address and password rather than simply accepting the connection. Turn off auto-connect to open Wi-Fi networks in your phone's settings, so your device does not join something automatically without your active decision.

Avoid logging into banking, email, or other sensitive accounts on any public network, even one that appears to be genuine, and use a VPN or your mobile data for anything sensitive while travelling if that option is available to you. Never install an app or accept a certificate purely to gain internet access; a legitimate public Wi-Fi network does not require this.

The first hour after you realise you have connected to something suspicious

Disconnect from the network immediately and avoid logging into anything else on it while you assess what happened. If you entered a password on the network, particularly one you also use elsewhere, change it as soon as you are back on a trusted connection, along with any other account where you reused the same password.

Check your bank app and email account for unusual activity over the following days, not just immediately, since fraudulent use of harvested details is not always instant. If any financial account looks affected, contact your bank's fraud team straight away, and note the exact network name and approximate time you connected, since this detail is useful for any report you make afterwards.

Recovering from data or account compromise

For unauthorised card or bank transactions, report to your bank as soon as you notice them; the Payment Services Regulations 2017 generally require prompt reimbursement for genuinely unauthorised payments, though this is not automatic in every case and depends on the circumstances, including whether the bank considers you to have acted with gross negligence. Reporting promptly, with as much detail as you can provide, generally supports a stronger claim than reporting after a long delay.

Beyond the immediate financial transaction, change any reused passwords across other accounts, enable two-factor authentication wherever it is available, and report the incident to Action Fraud so it feeds into the wider national picture. If you are concerned about identity theft rather than just a single fraudulent payment, it is worth asking your bank about further monitoring options.

How airport Wi-Fi scams are evolving

The equipment needed to run an evil twin attack has become cheaper and more automated, lowering the barrier to setting one up convincingly in a busy public space like an airport terminal. Fake captive portal login pages, the screen you see immediately after connecting, are also becoming closer visual matches for genuine airport or airline branding, removing one of the more obvious tell-tale signs that used to help travellers spot a fake.

A related and increasingly common tactic pairs fake Wi-Fi with QR codes displayed near gates or seating areas, inviting travellers to "scan to connect" to a network that leads to a phishing page rather than genuine internet access. Treating an unexpected QR code with the same suspicion as an unfamiliar network name is a sensible extension of the same underlying caution.

Who is most at risk and why

Business travellers checking work email or handling sensitive accounts between flights are a frequent target, since compromised work credentials can have consequences well beyond the individual traveller. Frequent flyers who have simply grown used to connecting to airport Wi-Fi as a matter of routine are also at risk, precisely because habit tends to reduce the moment of active checking that catches a fake network before you connect.

International travellers relying on airport Wi-Fi because roaming data is expensive or unavailable on their plan are particularly exposed, since they may feel they have little choice but to connect to whatever is available. Anyone transiting an unfamiliar airport, where they have no prior sense of what the official network name or signage should look like, faces the same heightened risk for the same underlying reason.

How it works

  • A fake hotspot is broadcast with a name closely mimicking the airport's genuine free Wi-Fi network
  • Connecting may route your browsing through the attacker's equipment, potentially exposing unencrypted traffic
  • Some fake networks show a login or "terms and conditions" page asking for an email address and password, harvesting credentials that are often reused across other accounts
  • Attackers may also use "evil twin" attacks that clone a legitimate network exactly, making the fake and real versions indistinguishable by name alone

Red flags

  • Multiple similarly-named Wi-Fi networks showing in your device's list at the airport
  • A login page asking for an email and password rather than just accepting the connection
  • Being asked to download an app or a certificate to access the internet
  • No official signage confirming the exact network name to use

How to protect yourself

  • Check airport signage or ask staff for the exact official network name before connecting
  • Avoid logging into banking, email, or other sensitive accounts on any public Wi-Fi network
  • Use a VPN if you need to access sensitive accounts while travelling
  • Turn off auto-connect to open Wi-Fi networks in your phone's settings
  • Consider using your mobile data instead of public Wi-Fi for anything sensitive, if you have signal or roaming

If it happens to you

  • If you entered a password on a suspicious network, change that password immediately (and anywhere else you reused it) once on a trusted connection
  • Monitor your bank and email accounts for unusual activity in the days that follow
  • Report the incident to Action Fraud (actionfraud.police.uk) and consult the National Cyber Security Centre's guidance for further steps

Frequently Asked Questions

Is any public Wi-Fi at an airport actually safe to use?

Official airport Wi-Fi, confirmed via signage or staff, is generally fine for casual browsing, but no public network should be treated as fully secure. Avoid logging into sensitive accounts on any public Wi-Fi, and use a VPN or mobile data if you need to.

What is an "evil twin" Wi-Fi attack?

It is a fake hotspot broadcasting the exact same name as a genuine network, making it indistinguishable by name alone. This is why relying on the network name to judge safety is not enough — treat all public Wi-Fi as unsecured by default.

Should I ever enter my email and password on an airport Wi-Fi login page?

Be very cautious. A genuine public network login page usually just asks you to accept terms and conditions, not to enter an email address and password. If a login page asks for full account credentials rather than a simple acceptance, treat it as a likely warning sign and avoid entering real details.

Does a VPN make public Wi-Fi completely safe?

A VPN encrypts your traffic between your device and the VPN provider, which meaningfully reduces the risk of interception on an untrusted network, but it does not make every risk disappear. It will not protect you if you enter credentials directly into a fake login or phishing page, so the other precautions still matter alongside it.

How quickly should I report a suspected fake hotspot?

As soon as possible. If any account or payment details may have been exposed, contact your bank first for account security, then report the network to Action Fraud. Prompt reporting generally supports a stronger position if you later need to dispute an unauthorised transaction.

Can criminals see what I am doing if I do not log into anything?

Simply being connected to a malicious network can expose unencrypted traffic, even without actively logging into an account, though the risk is generally lower than actively entering credentials on a fake page. Avoiding sensitive activity altogether on an unverified network remains the safest approach.

Is mobile data always safer than public Wi-Fi?

Generally, yes, since your mobile provider's network does not carry the same fake-hotspot risk as an open public Wi-Fi network. If you have signal or affordable roaming available, using mobile data for anything sensitive while travelling is a reasonable default precaution.

What should I check in my phone's Wi-Fi settings before travelling?

Turn off auto-connect to open or unknown networks, so your device does not join something automatically without you actively choosing to. It is also worth removing or forgetting old public network names you no longer use, which reduces the chance of automatically reconnecting to a network that has since been compromised.

Can a fake Wi-Fi network install anything on my phone just by connecting?

Simply connecting to a network does not normally install anything by itself, but being prompted to install an app or accept a certificate to "get online" is a genuine risk and should always be refused. A legitimate public Wi-Fi network does not require you to install anything to access the internet.

This page is general safety guidance, not legal or financial advice, and scam tactics evolve constantly. If you are the victim of fraud, contact your bank immediately and report it to Action Fraud.

Written by Emma Walsh

Editor, Hotels & Europe

Emma reviews boutique and independent hotels across Europe, alongside British Airways and Oneworld product reviews. She writes FlightLogic's Avios redemption guides.

87+Reviews
410K+Miles Flown
22Countries
5 yrsCovering Travel

← Back to all travel scams