Evil Twin Attack: How Fake Wi-Fi Networks Steal Your Data
An evil twin attack is a Wi-Fi cyberattack where a malicious access point impersonates a legitimate network to trick users into connecting. Attackers can use fake Wi-Fi networks, fraudulent captive portals and phishing pages to steal passwords, authentication codes and other sensitive information. This guide explains how evil twin attacks work, how to recognize the warning signs, what to do after connecting to a suspected fake network, and how individuals and businesses can protect themselves.
An evil twin attack uses a fake Wi-Fi access point designed to look like a trusted public or business network.
Attackers may use fake login pages, captive portals and real-time phishing to steal passwords, personal information and authentication codes.
A familiar Wi-Fi name, strong signal or HTTPS padlock does not prove that a network or website is legitimate.
Reduce your risk by verifying the official Wi-Fi name, disabling automatic connections, using cellular data or a trusted VPN when appropriate, and checking website domains before signing in.
Phishing-resistant authentication, such as passkeys, FIDO2 security keys and WebAuthn, provides stronger protection against sophisticated credential-phishing attacks.
Businesses can reduce exposure through separate guest networks, WPA2/WPA3, wireless monitoring, centrally managed devices and employee security training.
If you suspect an evil twin attack, disconnect immediately and review exposed passwords, active sessions, MFA settings and account activity from a trusted connection.

Public Wi-Fi is convenient. It’s also surprisingly easy to fake.
An evil twin attack happens when a criminal creates a Wi-Fi network designed to look like a legitimate one. It might copy the network name of a hotel, airport, café, conference venue or office or use a name close enough that most people wouldn’t think twice about connecting.
Once someone joins the fake network, the attacker controls the access point sitting between that device and the internet. What they can actually see or manipulate depends on the security protecting the connection, but the fake network can be used to redirect people to malicious websites, display convincing login pages or collect information entered by the victim.
The US Cybersecurity and Infrastructure Security Agency, or CISA, describes an evil twin as a system configured to impersonate a legitimate public access point. NIST also warns that rogue access points can give attackers opportunities to observe or manipulate communications from devices that connect to them.
The uncomfortable part is that, from the user's point of view, everything can look completely normal.
How does an evil twin attack work?
The exact setup varies, but most evil twin attacks follow a fairly simple pattern.
1. The attacker finds a trusted network to copy
First, the attacker identifies the name of a Wi-Fi network people already expect to see.
That could be something like:
Airport_Free_WiFiHotel_GuestConference_WiFiCoffeeShop_GuestCompany_Office
The name you see when choosing a Wi-Fi network is called the service set identifier, or SSID.
The important thing to understand is that an SSID is only a name. It does not prove that the network behind it is legitimate.
Someone with the right equipment can broadcast a network using a familiar name.
2. They create a convincing copy
Next, the attacker sets up another wireless access point using either the exact same name or something close enough to pass at a glance.
A legitimate network called Hotel_Guest, for example, could be imitated with names such as:
Hotel_GuestHotel-GuestHotel_Guest_5GHotel_Guest_FreeHotelGuest
The fake network may even appear to have a better signal than the real one if the attacker is physically closer to you.
That still doesn’t make it genuine. Signal strength tells you how close or strong a network is not whether you should trust it.
3. The victim connects
This is where the attack starts working.
Someone may simply choose the fake network because its name looks right. In other cases, a device may try to reconnect automatically to a remembered Wi-Fi network.
That’s one reason security agencies recommend being cautious with automatic
Wi-Fi connections.
The Federal Trade Commission advises businesses to disable automatic connections to public Wi-Fi on smartphones, while the US National Security Agency recommends disabling wireless features when they are not needed and favouring a personal or corporate hotspot over unfamiliar public Wi-Fi.
4. The internet still works
A good evil twin attack doesn’t necessarily cut off your internet access.
In fact, keeping everything working is part of what makes the attack convincing.
Websites load. Apps continue working. Messages come through.
Meanwhile, your traffic is passing through infrastructure controlled by the attacker before reaching the internet.
That gives them an opportunity to attempt surveillance, redirection or phishing.
It does not automatically mean they can read everything you do. Properly encrypted traffic is still protected, and what an attacker can access depends heavily on the protocols and security controls being used.
5. The attacker tries to steal information
One of the most effective techniques is a fake captive portal.
A captive portal is the page that sometimes appears when you connect to hotel, airport or café Wi-Fi and asks you to accept terms or sign in before getting internet access.
An attacker can create their own version.
The fake page might ask for:
An email address and password
Social media credentials
Workplace login details
A hotel room number
Payment card information
A phone number
A one-time authentication code
Anything entered into an attacker-controlled page can be recorded.
In more advanced attacks, those credentials may be used against the real service almost immediately.
Is an evil twin attack the same as a man-in-the-middle attack?
Not quite.
The two are closely related, which is why they’re often discussed together, but they describe different things.
An evil twin is the fake Wi-Fi access point itself, the network created to impersonate one you trust.
A man-in-the-middle attack, also commonly called an adversary-in-the-middle attack, describes the attacker's position between two parties that are trying to communicate.
An evil twin can give an attacker the position they need to attempt a man-in-the-middle attack.
But connecting to an evil twin does not suddenly make every encrypted conversation readable.
Here’s the difference:
Term | What it means |
Evil twin | A Wi-Fi access point created to imitate a trusted network |
Rogue access point | Any unauthorised wireless access point operating on or around a network |
Man-in-the-middle attack | An attacker intercepts or manipulates communication between two parties |
Captive-portal phishing | A fake network login page designed to collect information |
DNS manipulation | Interference with domain-name resolution to influence where traffic is sent |
Evil twin vs. rogue access point
These terms are often used as if they mean the same thing, but there is a useful distinction.
A rogue access point is any unauthorised wireless access point.
It could be malicious. But it could also be something as simple as an employee connecting a personal router to a company network without permission.
An evil twin is more deliberate.
It is a rogue access point specifically created to resemble a trusted network so that people connect to it voluntarily.
NIST identifies rogue wireless devices as a security risk because they can bypass normal network controls and potentially give attackers opportunities to observe or interfere with communications.
What can an evil twin attacker actually steal?
This is where a lot of public Wi-Fi advice becomes exaggerated.
Connecting to a malicious network does not automatically expose every password, message and account on your device.
What an attacker can obtain depends on what you do after connecting, which services you use and how those services protect their traffic.
Credentials entered into fake pages
This is one of the clearest risks.
If a fake portal asks for your email address and password and you type them in, you are giving those details directly to the attacker.
HTTPS doesn’t necessarily save you in this situation.
A fraudulent website can have its own valid HTTPS certificate. Your connection to that site may genuinely be encrypted but it is encrypted between you and the criminal's website.
The attacker owns the destination, so they can still see whatever you submit.
The FTC has specifically warned that scammers can create encrypted fake websites.
That means the padlock in your browser tells you something important, but limited: the connection to that domain is encrypted. It does not prove that the person or organisation behind the domain is trustworthy.
Unencrypted network traffic
Traffic that does not use HTTPS, a VPN or another encrypted protocol may be visible to someone controlling the network.
This is less common than it once was because most major websites now use HTTPS.
The FTC has noted that widespread encryption has made ordinary public Wi-Fi considerably safer than it was in the past.
Still, not everything on the internet is perfectly configured.
Older websites, legacy protocols, misconfigured services and certain connected devices may still transmit information without adequate protection.
Browsing and connection information
Encryption can protect the content of your communication without necessarily hiding every piece of information about the connection itself.
Depending on the technologies being used, a network operator may still be able to observe details such as:
When your device connected
How long it stayed connected
How much data was transferred
Certain network destinations
DNS requests when they are not protected
That does not mean they can automatically read the contents of your emails, private messages or HTTPS webpages.
Session information
Some sophisticated phishing systems go further than simply stealing a password.
An adversary-in-the-middle phishing setup may relay a victim's interaction to a legitimate service in real time and attempt to capture authentication or session information in the process.
This requires more than just running a fake Wi-Fi network.
The attacker generally needs an additional phishing or proxy system, and the victim still has to interact with the attacker-controlled page.
Two-factor authentication codes
Two-factor authentication is much better than relying on a password alone, but not every form of 2FA is immune to phishing.
If a fake page asks for a one-time code and you enter it, the attacker may be able to relay your password to the real service, trigger the authentication request and then immediately use the code you provide.
CISA guidance continues to document adversary-in-the-middle techniques that can target passwords and some traditional two-factor authentication methods.
Phishing-resistant authentication works differently.
Technologies based on FIDO and WebAuthn can cryptographically tie authentication to the legitimate website, making them much harder to use on an impersonating domain.
NIST's 2025 Digital Identity Guidelines require phishing-resistant options in certain higher-assurance environments and encourage their use where practical.
How to protect yourself from evil twin attacks
You don't need to stop using Wi-Fi altogether.
What matters is making it harder for a fake network to fool you and limiting what happens if you accidentally connect to one.
Use cellular data for sensitive tasks
If you’re checking your bank account, accessing confidential work systems or handling sensitive information, cellular data or a personal hotspot is generally a safer choice than unfamiliar public Wi-Fi.
The NSA recommends avoiding public Wi-Fi when possible and using a personal or corporate hotspot protected by strong authentication and encryption.
Confirm the real network name
Before connecting, ask a member of staff what the official network is called.
You can also confirm:
The exact Wi-Fi name
Whether a password is required
Whether a captive portal should appear
What information that portal normally asks for
And don’t rely entirely on a poster, sticker or piece of printed signage. Those can be altered too.
Turn off automatic Wi-Fi connections
Your phone or laptop should not be joining unfamiliar networks without you noticing.
Disable settings that automatically connect your device to open or remembered public Wi-Fi networks.
The FTC specifically recommends preventing smartphones from automatically connecting to public Wi-Fi.
Forget public networks when you're finished
Once you leave the hotel, airport, café or venue, there’s usually little reason to keep its network saved.
Removing it from your device's remembered networks makes it less likely that your phone or laptop will try to connect automatically to another network broadcasting the same name later.
Keep your device updated
Updates aren't just about new features.
They can include fixes for certificate validation, browser security, wireless vulnerabilities and other weaknesses that affect how safely your device communicates.
The FTC recommends keeping operating systems, browsers, mobile devices and security software up to date, ideally using automatic updates.
Use HTTPS but check the domain too
HTTPS is important, but don't stop at the padlock.
Look carefully at the actual domain before entering a password or payment information.
For important services, opening the official app or using a bookmark you already trust is generally safer than following a page that suddenly appears after connecting to Wi-Fi.
Use a reputable VPN
A VPN can add another layer of protection on unfamiliar networks by encrypting traffic between your device and the VPN provider.
If you're using a company device, stick to the VPN approved by your organisation.
Be careful with random free VPN services.
A VPN provider may be in a position to handle a significant amount of your network traffic, so its reputation, technical protections, privacy policy and business model matter.
And remember: a VPN protects the connection. It does not make a fake login page legitimate.
Use a different password for every account
Password reuse turns one stolen password into a much larger problem.
If the credentials you enter into a fake portal are also used for your email, social media or workplace account, an attacker may try the same password elsewhere.
A password manager makes it much easier to generate and store unique passwords for every service.
Enable multi-factor authentication
Multi-factor authentication gives an attacker another barrier to overcome if your password is exposed.
Where available, stronger phishing-resistant options include:
Passkeys
FIDO2 security keys
WebAuthn authentication
Appropriate certificate-based authentication
NIST's current authentication guidance recognises qualifying cryptographic authentication methods as phishing-resistant.
Be suspicious of unusual login requests
A public Wi-Fi network should not need the password to your unrelated email, workplace, bank or social media account.
If a portal suddenly asks for credentials that don't make sense for the service you're trying to access, stop.
Verify the request independently before entering anything.
Turn Wi-Fi off when you're not using it
This one is simple.
If you don't need Wi-Fi, disable it.
Doing so reduces automatic connection attempts and your exposure to nearby networks.
The NSA also recommends disabling Wi-Fi, Bluetooth and NFC when those features are not in use.
How businesses can protect employees and visitors
Evil twin attacks aren't only a problem for individual users.
Businesses that provide Wi-Fi or have employees regularly working outside the office should assume that people will occasionally make mistakes.
Security needs to do more than rely on someone noticing a suspicious network name.
Give people one official network name
Employees and visitors should know exactly what your legitimate Wi-Fi network looks like.
Tell them:
The precise SSID
How authentication works
Whether a captive portal is used
What information the portal will ask for
What it will never ask for
Where suspicious networks should be reported
The less ambiguity there is, the easier it becomes to spot an imitation.
Keep guest Wi-Fi away from business systems
Guest traffic should not share unrestricted access with internal company systems.
The FTC recommends separating public or guest Wi-Fi from the organisation's primary business network.
That way, even if something goes wrong on the guest side, exposure to internal systems is reduced.
Use WPA2 or WPA3
Protected business Wi-Fi should use modern authentication and encryption rather than obsolete protocols.
The FTC recommends WPA2 or WPA3 for protected networks and identifies WPA3 as the newer option.
That secures the legitimate network itself.
It does not, however, prevent someone nearby from broadcasting a completely separate network with a similar name.
Monitor the wireless environment
Organisations with higher security requirements can use wireless intrusion detection or prevention tools to look for suspicious activity such as:
Unauthorised access points
SSIDs copying corporate network names
Unusual wireless behaviour
Devices operating outside company policy
These systems are only as useful as their configuration, coverage and response process.
Detecting a suspicious access point doesn't help much if nobody is watching the alerts.
Use certificate-based enterprise authentication
Enterprise Wi-Fi can be configured so that devices authenticate not only the user but also the network they are connecting to.
When implemented correctly, managed certificates and server validation make it much harder for employees to connect to a convincing imitation.
Devices should be configured to verify the correct authentication server rather than accepting any server that happens to present a login prompt.
Manage devices centrally
Mobile-device management gives organisations more control over how company devices connect.
Depending on the setup, administrators can:
Preconfigure approved Wi-Fi networks
Block or limit connections to open networks
Install trusted certificates
Require VPN usage
Remove unsafe configuration profiles
Enforce current operating-system versions
This reduces the number of security decisions employees have to make manually.
Train people with realistic examples
“Be careful on public Wi-Fi” is not particularly useful training.
Show people what the threat actually looks like.
Employees should know how to recognise:
A fake SSID
A suspicious captive portal
A certificate warning
An unexpected re-authentication request
The FTC recommends regular security training and keeping staff informed as new risks and vulnerabilities emerge.
Move towards phishing-resistant authentication
Even well-trained employees can fall for a convincing login page.
That's why authentication design matters.
Passwords and manually typed one-time codes can be stolen by phishing pages.
Phishing-resistant methods reduce how much your security depends on someone spotting every fake page correctly.
NIST's 2025 guidance recommends phishing-resistant authentication where practical and requires it in certain higher-assurance federal environments.
What should you do if you think you connected to an evil twin?
First, disconnect.
But remember: leaving the network does not undo information you've already submitted.
Here’s what to do next.
1. Turn off Wi-Fi
Disconnect from the suspicious network and switch to cellular data or another network you know you can trust.
2. Don't return to the suspicious page
Don't reconnect just to investigate.
Don't enter fake information to “test” the portal either.
You don't need to interact with it further.
3. Write down what happened
Without reconnecting, make a note of anything useful:
The Wi-Fi name you saw
Where you were
Approximately when you connected
What the portal asked for
What information you entered
Any warnings your device displayed
Those details may help the venue, your employer or a security team investigate what happened.
4. Change any exposed passwords
Use a trusted connection and device.
Then change every password you entered while using the suspicious network or portal.
Start with your email account if it was involved, since email is often used to reset passwords for other services.
If you reused the same password elsewhere, change those accounts too.
5. Sign out active sessions
Go into the account's security settings and look for an option to sign out other devices or terminate active sessions.
Changing your password is important, but it does not always invalidate every existing session immediately.
6. Check your authentication settings
Review your account for unfamiliar changes, including:
Newly added authentication devices
Recovery phone numbers you don't recognise
New backup codes
Changed recovery email addresses
Unknown security keys
Unknown passkeys
Remove anything that shouldn't be there.
7. Review recent account activity
Look for anything unusual, such as:
Unknown logins
Messages you didn't send
Purchases you didn't make
Password reset attempts
New forwarding rules
Unexpected app permissions
File-sharing activity
Profile changes
The sooner you spot unauthorised activity, the sooner you can contain it.
8. Update and scan the device
Make sure the operating system and security software are current.
If you downloaded a file, installed an app, accepted a certificate or added a configuration profile while connected to the suspicious network, an approved security scan may also be appropriate.
9. Report the network
Depending on what happened, report it to the appropriate organisation.
That could include:
The hotel, café, airport or venue
Your employer's security team
Your IT administrator
The service that was impersonated
Relevant authorities if money, identity information or accounts were stolen
10. Watch your financial accounts
If you entered card or banking information, contact the financial institution using an official phone number or website.
Review your recent transactions and follow its fraud-response instructions.
Common myths about evil twin attacks
Public Wi-Fi security is full of half-truths.
Here are a few worth clearing up.
-> Anyone on public Wi-Fi can read all my passwords
Not necessarily.
If you're connecting directly to a legitimate website using properly implemented HTTPS, the Wi-Fi operator should not be able to read your password as it travels across the network.
The bigger risk is being tricked into entering that password into a fake website or using a service that isn't properly encrypted.
-> The padlock means the website is real
False.
The padlock means your connection to that particular domain is encrypted.
It does not prove the domain belongs to the company you think it does.
Criminals can also use HTTPS on fraudulent websites, something the FTC explicitly warns about.
Always check the domain itself.
-> A VPN makes public Wi-Fi completely safe
False.
A VPN protects traffic travelling through its encrypted tunnel.
It cannot tell whether a website is legitimate, stop you from voluntarily submitting credentials to a criminal or guarantee that your device has not already been compromised.
Think of a VPN as one security layer, not a magic shield.
-> Two-factor authentication stops all credential theft
False.
Two-factor authentication makes accounts much harder to compromise, but manually entered one-time codes can still be captured by real-time phishing systems.
Phishing-resistant FIDO and WebAuthn-based authentication provides stronger protection against this type of impersonation.
-> Evil twin attacks only happen in airports and cafés
False.
They can appear anywhere people expect to find Wi-Fi, including:
Hotels
Conferences
Universities
Shopping centres
Transport hubs
Offices
Apartment buildings
Healthcare facilities
Events and exhibitions
The attack doesn't depend on the location.
It depends on whether people recognise the network name and trust it.
A familiar Wi-Fi name doesn't mean a familiar network
That's really the core of an evil twin attack.
The name looks right. The signal is strong. The login page looks professional. Your internet works.
So there’s very little reason to suspect anything is wrong.
Modern encryption has made passive interception of properly protected internet traffic much more difficult than it once was. As a result, the more realistic danger is often deception: fake portals, lookalike websites, unexpected login requests and real-time phishing.
Protecting yourself doesn't require one perfect security tool.
It requires a few good habits working together:
Verify Wi-Fi network names
Disable automatic Wi-Fi connections
Prefer cellular data or a personal hotspot for sensitive tasks
Use HTTPS and check the full domain
Use a trusted VPN on unfamiliar networks
Keep passwords unique
Use phishing-resistant authentication when available
Keep your devices updated
Stop when a connection behaves in a way you weren't expecting
And above all, remember one simple rule:
A familiar Wi-Fi name is not proof that you're connecting to a trusted network.
Leave a comment :
No comments yet. Be the first!


















