⚙ Build in progress — some links may break, some copy may shift. We'd appreciate the heads-up: [email protected]
version 26.5.1 · Western Australia · Est. 2011·Microsoft Partner & Reseller · HP, Yealink, Ubiquiti, Kyocera
— Stay safe · Public WiFi

When the free WiFi isn't actually free WiFi.

It looks identical, it works the same, and everything you type goes through someone else's computer. The evil twin attack, explained.

An evil twin is a WiFi network set up by someone in (or near) a public venue that uses the same name as the venue's real WiFi — so your phone or laptop can't tell them apart. The attacker's laptop sits between you and the internet, watching everything. Recent attacks have hit airline lounges, big-chain cafes, and conference centres. Five tells, and one habit that beats them all.

<$300
Cost of evil-twin attack gear (a Raspberry Pi + WiFi card)
84%
Of devices that auto-connect to known network names without checking
3
Major Australian evil-twin events publicly reported in 2025
// THE PATTERN

How the attack works. The attacker brings a small device into a cafe that broadcasts a WiFi network with the same name as the real one, but with stronger signal. Your phone, which connected to the real network last week, sees the same network name now with stronger signal — and silently connects to it. Every site you visit is now routed through the attacker's device. They can read what you do, modify what comes back, and serve you fake login pages for any site you visit. You don't know any of this because everything looks normal. They walk out of the cafe twenty minutes later with everyone's credentials.

// TELL #1

Two networks with the same name.

If you tap the WiFi icon and see TWO networks with the same name (or near-identical names: "CafeName" and "CafeName-Free" and "CafeName_Guest"), at least one is wrong. Don't connect to either — ask the venue staff which is the real one. Or just tether.

// TELL #2

No password when there usually is one.

If a venue normally puts the WiFi password on a sign and today the network is open, suspect an evil twin. Real venues rarely change WiFi security overnight. Open is convenient for everyone — including the attacker.

// TELL #3

Different login page than usual.

If you've connected here before and the captive portal (the login splash) looks different — different colours, different fields asked for, asking for email when it used to be free — pause. The captive portal can be the actual attack: capture your email, then phish it next week.

// TELL #4

HTTPS warnings on sites you normally use.

After connecting, if a normally-fine website suddenly shows a certificate warning, the network is intercepting your traffic. Disconnect immediately. Most evil-twin setups are sloppy enough that they break HTTPS on at least some sites.

// TELL #5

The signal is suspiciously strong.

If you walk in and the venue WiFi is showing five bars from the moment you sit down — much stronger than usual — that's because the evil twin device is closer to you than the real router. Real venue WiFi usually has dead spots; suspiciously perfect signal everywhere is unusual.

// THE FIX

Tether from your phone, every time.

Easiest defence: don't use venue WiFi at all. Tethering takes 10 seconds, uses your own LTE, and is mathematically immune to evil-twin attacks (because the attacker isn't on your hotspot's password). The 2GB you'll use over the course of a meeting costs less than a coffee. See the tethering guide.

Related safety reading.

Evil twin is just one of several public-WiFi-specific attacks. Read the lot together.

Travelling team? Talk to us.

If your team works from airports, hotels, and client sites, this is the attack class that targets them. whedo.it bundles always-on VPN, device security baseline, and traveller-aware Conditional Access policies for managed clients with hybrid workforces.

+61 421 346 887
5.0
★★★★★ on Google · loading…
Read all on Google →