Category
network security
Topic
Evil Twin attacks on public Wi-Fi networks
Audience
Companies & business travellers
Reading time
approx. 4 minutes

The airport is packed. Security checks are overwhelmed, boarding announcements come thick and fast, and people are sitting everywhere with laptops or smartphones in their hands. Between flights, hundreds of travellers quickly connect to the obvious network: ‘Free Airport WiFi’. For many, it’s routine. A quick check of emails, opening Slack or downloading a document from the Cloud. Yet it is precisely this situation that presents an ideal attack scenario for cybercriminals.

The perfect place to strike: crowded airports

Public Wi-Fi networks are among the most attractive targets for attack. In airports, thousands of devices connect simultaneously, often under time pressure and without paying close attention to the network name.

Attackers exploit this situation by creating what is known as an ‘evil twin’ network – in other words, a fake Wi-Fi network that copies the name of a legitimate network. Typical examples include:

  • Airport_Free_WiFi
  • Airport Free WiFi
  • Airport_WiFi

To a stressed traveller, these networks look almost identical.

Many devices even connect automatically to the strongest signal, which is often the attacker’s device.

The moment of compromise

As soon as a device connects to the rogue access point, the attacker takes control of the connection. Depending on the attack scenario, they can:

1

Display fake login portals

Captive portals that look deceptively real ask for credentials, email addresses or even payment information.

2

Intercept traffic (man-in-the-middle)

All data traffic passes through the attackers’ infrastructure and can be analysed or manipulated.

3

Intercepting session cookies or tokens

Active sessions in web applications can be taken over, often without the attacker even knowing the password.

4

Collecting credentials and personal data

Anything transmitted unencrypted or via compromised connections ends up in the attacker’s hands.

Attackers can use this data later to take over accounts, commit identity theft or carry out further attacks.

Why businesses are particularly vulnerable

The problem does not only affect private users. Business travellers often open the following at airports:

  • corporate email
  • Cloud storage
  • corporate VPNs
  • internal tools or dashboards

If an attacker intercepts session tokens whilst doing so, they often no longer even need the password. Multi-factor authentication has already been successfully completed in the compromised session.

The result could be:

  • Access to company accounts
  • data exfiltration
  • A point of entry for further attacks on the organisation

The underestimated attack surface: business travel

Cybersecurity programmes often focus exclusively on endpoint security, Phishing and Cloud security. Yet travel situations are among the most underestimated risks.

Crowded airports, public Wi-Fi networks and stressed-out users create exactly the conditions that attackers need.

360° awareness

Awareness must not be something that is only considered during a Phishing awareness campaign. It requires a comprehensive perspective and an instinct for dealing with such situations. Many people misjudge the potential risks and give too little thought to everyday situations.

Recommendation: Educate those around you and your employees, and raise awareness. Specific immediate measures: disable automatic Wi-Fi connections; when on the move, use mobile data or a hotspot instead of public Wi-Fi; and only access sensitive data via a VPN.

“The most dangerous attack often doesn’t start in the data center, but in the airport terminal between Gate B12 and a free Wi-Fi hotspot.”
Mint Secure GmbH

How Mint Secure supports you

We help you to comprehensively manage the risks associated with public networks and mobile working:

🎓

Awareness training

Practical training sessions using real-life scenarios, such as ‘Evil Twin’ Wi-Fi networks, so that your team can recognise threats even whilst on the move.

📡

Wi-Fi & Infrastructure Assessments

We check your networks and mobile devices for vulnerabilities, including simulated rogue access point attacks.

🛡️

Directives & Hardening

From mandatory VPN use to device configuration: we develop travel and remote working directives that work in everyday practice.

Ready to get started? We offer a free initial consultation.
Get in touch.

Conclusion

Public Wi-Fi networks at airports are convenient, but they’re also an ideal hunting ground for ‘Evil Twin’ attacks. Anyone who connects to the first available network whilst in a hurry risks having their session tokens stolen, their accounts compromised and the loss of sensitive company data.

The best protection is a combination of technology and awareness: using a VPN, disabling auto-connect features, and having a team that recognises the risk before connecting.

Mint Secure provides consulting and support in establishing awareness and technical safeguards for mobile working.
Talk to us.