DEF CON Attendees Allegedly Launch Mid-Flight Deauthentication Attack on Delta Air Lines Wi-Fi

August 17, 2026


Some miscreants on the way home from Las Vegas to Atlanta opted to perform a deauthorization attack mid-flight and allegedly targeted other passengers for their login credentials. This followed a reported campaign of similar attack attempts on the Wi-Fi network at DEF CON itself.

As we enter the era of highly capable frontier AI agents, a number of security fundamentals have still not been sorted out. As some attendees at the most recent DEF CON demonstrated, public airplane Wi-Fi networks remain on this list.

However, the hackers did not do this at a conference presentation. Rather, some miscreants on the way home from Las Vegas to Atlanta instead opted to perform a deauthorization attack mid-flight and allegedly targeted other passengers for their login credentials. This followed a reported campaign of similar attack attempts at DEF CON itself, which might have also extended to the Vegas airport just prior to the flight.

Deauth attack party at DEF CON continues after closing time

Media reports indicate a group of several were involved in the attack, and brought their own network gear with them onto the plane. Delta flight staff recognized what was happening during the attack and made contact with corporate security about it, sending a message type that is visible to “flight watcher” enthusiasts and thus breaking the story before the plane touched down.

When it did arrive, the suspects were reportedly questioned and had their WiFi hardware seized by police. As the flight staff noted in their communications, some passengers were coming from the DEF CON conference that ran from August 6 to 9 in Vegas. This incident took place on the morning of August 10, but this was a flight that had actually been scheduled to depart the evening of August 9 and was delayed because of a spate of very bad thunderstorms around Atlanta that night.

At least one person posting to a major Reddit discussion thread about the story says they observed similar attempts at the Vegas airport just before the flight, but that has not been confirmed. What has been confirmed by the head of press for DEF CON, Monika Hathaway, is that the conference did have a campaign of similar attacks on its own Wi-Fi networks this year. The perpetrators were not identified at the time.

The boundaries at DEF CON are somewhat fuzzy as to what activities are smiled and frowned upon; things that are technically criminal, such as capturing and displaying the login credentials of others and messing with the operations of local businesses, seem to be on a spectrum from “openly encouraged” to “tacitly accepted.” There is a line in there somewhere though, and the press head confirmed that attacking the conference Wi-Fi network with denial of service and a lookalike hotspot is at least enough to get one removed and banned if they are caught.

Delta Wi-Fi network taken down during flight out of caution

The attack did not reportedly endanger the flight in any way, but after the flight staff caught on to what was happening the plane’s Wi-Fi network was reportedly disabled for about 30 minutes as the flight continued on to its destination.

Some reports indicate the attackers sent forged disconnection packets out to knock other passengers offline and then deployed a controlled hotspot called “Delta WiFi Fast” that they hoped victims would connect to as an alternative. Some of those that did report seeing a login screen that asked for credentials or authorization of a Google login to continue to the Wi-Fi network.

Worse could have been done with the attack, and the fact that it was done so crudely and that a phishing page was deployed points to relative amateurs. The seeming lack of success doing the same thing at DEF CON, presuming it was the same group, also backs up that theory. DEF CON does not require an invitation or credentials to attend, merely about $500 to $600 USD depending on the registration method. Attackers might simply hang about in the area and not even pay to get into the convention center grounds.

Whatever the case, the incident serves as a reminder that even a big and recognizable corporation’s Wi-Fi network may still be lacking in security fundamentals, even as we enter the age of “machine speed” vulnerability discovery.