Delta Air Lines is investigating a cybersecurity incident aboard Flight DL591 from Las Vegas to Atlanta after an unauthorized Wi-Fi network appeared on the aircraft during the flight.
The incident occurred on August 10, shortly after Las Vegas hosted DEF CON 34, one of the world's largest cybersecurity conferences. The timing has drawn particular attention because some passengers aboard the flight were reportedly returning from cybersecurity events in Las Vegas.
Importantly, however, there is currently no evidence that Delta's aircraft systems or the airline's legitimate in-flight Wi-Fi network were hacked.
Delta said its initial investigation determined that the unauthorized network was not provided, operated or supplied by the airline. The carrier also emphasized that flight safety was never in question and that no aircraft operating systems were affected.
Flight DL591 was operating from Harry Reid International Airport in Las Vegas to Hartsfield-Jackson Atlanta International Airport aboard a Boeing 757.
During the flight, the crew became aware of an unauthorized wireless network that reportedly mimicked Delta's onboard Wi-Fi service.
Messages attributed to the flight crew and transmitted through the aircraft's ACARS (Aircraft Communications Addressing and Reporting System) alerted Delta operations to the situation.
One reported message said passengers who had attended a cybersecurity conference in Las Vegas had been able to interfere with the aircraft's Wi-Fi and broadcast another signal.
A subsequent message warned corporate security about a network identified as "Delta WiFi Fast," with the crew expressing concern that it could be used to scam or deceive passengers.
The reports are significant because a fake Wi-Fi access point can potentially be used to impersonate a legitimate network and direct users toward fraudulent login pages or other deceptive services.
After the crew became aware of the unauthorized network, the aircraft's legitimate Wi-Fi functionality was disabled for approximately 30 minutes.
The action was precautionary. There was no emergency declaration to air traffic control, and the flight continued to Atlanta. The aircraft subsequently landed safely.
Delta has stressed that its investigation has not identified a compromise of the airline's systems or aircraft operating systems.
"We are fully investigating to gather a complete set of facts, which will take time," Delta said, adding that it would work with federal law enforcement and aviation regulators as the investigation continues.

This is where the story needs careful qualification.
A number of online reports and social-media discussions have speculated that a Wi-Fi Pineapple or similar portable wireless device may have been used to create the unauthorized network.
Such equipment is capable of performing legitimate security-testing functions, including creating wireless access points that imitate other networks. Similar technology can also be misused for phishing or other attacks.
But there is currently no verified evidence publicly establishing that a Wi-Fi Pineapple was used on DL591.
Neither the available Delta statements nor the reporting from major news organizations cited above identifies a specific device used in the incident.
Therefore, describing the event as "a Wi-Fi Pineapple attack" would go beyond the evidence currently available.
The more accurate description is an unauthorized or rogue Wi-Fi network that appeared aboard the aircraft and prompted the crew to take precautionary action.
The timing has nevertheless made the incident particularly unusual.
DEF CON 34 ran in Las Vegas from August 6–9, 2026, immediately before the DL591 incident on August 10. Reports indicate that the flight carried passengers who had attended cybersecurity conferences in Las Vegas.
The crew's ACARS messages specifically referenced passengers who had been at a cybersecurity conference.
That establishes a reported connection in the crew's observations, but it does not establish that a DEF CON attendee created the rogue network.
Authorities and Delta will need to determine who created it, what equipment was used, what the network was designed to do and whether any passenger information was actually collected.
The incident also highlights a growing challenge as airlines provide increasingly sophisticated connectivity onboard aircraft.
Delta says fast, free Wi-Fi is now available on more than 1,100 aircraft, with the airline working toward connectivity across its fleet by the end of 2026.
As onboard connectivity becomes as normal as Wi-Fi in an airport or hotel, passengers may become accustomed to automatically selecting familiar-looking network names.
That creates an opportunity for rogue access points and phishing attempts.
Passengers should therefore avoid assuming that a familiar network name automatically means the connection is legitimate. They should verify the network through the airline's official instructions, avoid entering sensitive credentials into unexpected login pages and use additional security measures such as multifactor authentication.
Perhaps the most important distinction in this incident is between passenger Wi-Fi and aircraft systems.
The unauthorized network was associated with the passenger connectivity environment. Delta has specifically stated that no aircraft operating systems were affected and flight safety was never in question.
That means this incident should not be characterized as someone "hacking the airplane" or taking control of the aircraft.
Instead, the confirmed picture so far is considerably narrower:
A rogue Wi-Fi network appeared onboard DL591 → the crew identified the issue → Delta's onboard Wi-Fi was temporarily disabled → the flight continued normally → Delta began an investigation.
The identity of the person responsible, the equipment involved and whether any passenger credentials were targeted remain subjects of investigation.
Don't enter card data on an airplane WiFi page unless you've verified the exact network name as written in the flight magazine or on the screen
A network name close to the official one isn't proof it's official; that's exactly the attack tactic
Use a VPN from the moment you connect, because it protects you even if you connect to the wrong network.
Final note: The tools rumored to have been used in such an attack are just speculation for now, and nothing about them has appeared in official statements or coverage. The investigation is still in its early stages.
| Claim | Status |
|---|---|
| DL591 flew Las Vegas–Atlanta on August 10 | Confirmed |
| Unauthorized Wi-Fi network appeared onboard | Confirmed by Delta |
| Network was not operated by Delta | Confirmed by Delta |
| Network called "Delta WiFi Fast" | Reported from crew communications |
| Crew warned corporate security | Reported |
| Onboard Wi-Fi disabled for about 30 minutes | Confirmed/reported |
| Aircraft operating systems were hacked | No — Delta says they were not affected |
| Flight safety was compromised | No |
| Wi-Fi Pineapple was used | Unconfirmed |
| DEF CON attendee definitely created the network | Unconfirmed |
| Passenger data was stolen | Not established |
The DL591 incident was real, and Delta has confirmed that an unauthorized Wi-Fi network appeared aboard the Boeing 757 during the Las Vegas–Atlanta flight.
But the most sensational claims circulating online should be treated cautiously.
There is no confirmed evidence at this stage that the aircraft was "hacked," that Delta's systems were breached, or that a Wi-Fi Pineapple was used.
What is known is that the crew detected a suspicious wireless network, alerted Delta operations, temporarily shut down the legitimate onboard Wi-Fi and continued the flight safely.
The investigation now has to answer the most important questions: Who created the network, what equipment was used, what was its purpose, and did anyone actually provide personal information to it?
Until those questions are answered, "rogue Wi-Fi network" is a more accurate description than "airline hack."