Wi-Fi Security

Evil Twin Wi-Fi Attack

Hackers set up fake hotspots with names almost identical to real ones. Your device connects — and every unencrypted byte flows straight through their laptop before reaching the internet. Can you spot the fake?

🔒 🔒 Fully local simulation — no real network connections are made.

Live Simulation

You're at an international airport. Your phone is scanning for Wi-Fi.

✈️

Can you spot the fake network? Tap one to connect.

9:41

Wi-Fi

Wi-Fi

Available Networks

BA_BusinessLounge 🔒

What Is an Evil Twin?

Man-in-the-Middle via fake AP

An attacker creates a Wi-Fi access point with the same (or nearly identical) name as a legitimate network. Your device sees a stronger signal and connects automatically — routing all traffic through the attacker's machine.

💡 The attack requires nothing more than a laptop, a $10 USB Wi-Fi adapter, and freely available software.

What the Attacker Sees

All unencrypted traffic

HTTP requests, DNS queries, login credentials on sites without HTTPS, and session cookies. Even on HTTPS sites, a hacker can use SSL stripping to downgrade your connection silently.

💡 Session cookies let attackers impersonate you without needing your password — logging in is optional.

How to Protect Yourself

VPN or cellular data

A VPN encrypts all your traffic before it leaves your device — even if you're connected to an evil twin, the attacker sees only unreadable ciphertext. Cellular data bypasses Wi-Fi entirely.

💡 Also check: does the URL say https://? If there's no padlock, assume it's visible to everyone on the network.

⚠️ Why this attack is so effective

  1. Wi-Fi names (SSIDs) are just text strings — any device can broadcast any name.
  2. Your phone auto-connects to known SSIDs, even if the signal source has changed.
  3. Airports and cafés have dozens of lookalike networks — nobody verifies them manually.
  4. The hacker passes your traffic through to the real internet, so you notice nothing wrong.
  5. Most public Wi-Fi traffic is mixed HTTP/HTTPS — credentials on older or misconfigured sites leak immediately.

Bottom line

You cannot tell a real network from an evil twin by looking at its name or signal strength alone. Treat every public Wi-Fi connection as potentially hostile. Use a reputable VPN, stick to HTTPS sites, and prefer cellular data for banking, email, and anything sensitive.

Common questions

Does HTTPS protect me on an evil twin?

Mostly yes — if you see the padlock and the URL is correct. A determined attacker can use SSL stripping (downgrading HTTPS to HTTP silently), but modern browsers warn against this. Your biggest risk is sites that aren't fully on HTTPS, or apps that don't validate certificates properly.

Will my phone reconnect automatically?

Yes. If you've ever connected to "Airport_Free_WiFi" before, your phone will auto-join any network broadcasting that exact name — including an evil twin. Disable "Auto-Join" for public networks, or turn off Wi-Fi entirely and use cellular in sensitive locations.

Is this attack illegal?

Yes — setting up an evil twin access point is illegal in most jurisdictions under computer fraud and interception laws. It happens anyway because it's trivially easy, anonymous, and difficult to detect mid-attack.

What VPN should I use?

Avoid free VPNs — many log and sell your traffic, which is exactly what you're trying to avoid. Look for a no-log VPN with independent audits (Mullvad, ProtonVPN, and IVPN are well-regarded).