top of page

How Safe Is Public Wi-Fi? Risks, Hacks, and Simple Ways to Protect Yourself

Jamie Barnikel
Sep 3
6 min read

Free Wi-Fi feels harmless. You open your laptop in a café, join the network at a station, or tap into airport Wi-Fi while waiting for a flight. A few seconds later, your phone is checking email, syncing photos, refreshing apps, and sharing more than you might realise.


Public and wide “open” Wi-Fi networks are convenient, but they are often built for access, not safety. The risk is not just that someone might see what website you visit. In the wrong setting, attackers can intercept data, imitate trusted networks, track devices, and collect details that help with fraud or identity theft.



Why open Wi-Fi is so easy to abuse


Many public networks have little or no encryption. If a network does not ask for a password, or if everyone uses the same password printed on a wall, it offers weak protection against anyone nearby who knows what they are doing.


A home Wi-Fi network usually has encryption between your device and the router. On a truly open public network, that protection may be missing. Even on networks with a shared password, other people on the same network may still be able to probe for exposed devices or exploit poor settings.


Attackers commonly use a few methods.


Eavesdropping


On weak networks, an attacker may monitor traffic moving between devices and the router. Modern websites that use HTTPS protect the content of most pages, but not everything is hidden. Domain names, app activity, device details, and unprotected connections can still reveal a lot.


Evil twin networks


An attacker creates a fake hotspot with a believable name, such as “Hotel Guest WiFi” or “Airport Free WiFi”. Devices and people often connect without checking. Once connected, traffic passes through equipment controlled by the attacker.


Man-in-the-middle attacks


The attacker sits between the user and the service they are trying to reach. They may redirect pages, capture logins on fake forms, or tamper with downloads.


Device probing


Phones and laptops on the same network can be scanned for open sharing settings, outdated software, or exposed services. A single old app or weak configuration can become an entry point.


What hackers can learn from public Wi-Fi


The most obvious targets are passwords, payment details, and account logins. Those are not the only risks.


A phone constantly sends and receives background data. Email apps refresh. Cloud storage checks for updates. Messaging apps sync. Weather, maps, transport, and shopping apps may contact servers while the screen is locked.


On a risky network, attackers may be able to collect or infer:


  • Websites and services being contacted

  • Device names, model details, and operating system clues

  • Email addresses used in captive portal sign-ins

  • Session cookies from poorly protected services

  • Location clues based on the network name and timing

  • App activity patterns, such as banking, travel, or health-related services

  • Unencrypted data from older apps or misconfigured websites


Movement tracking is also possible. Phones look for networks they recognise and may broadcast signals as they search. Modern devices use MAC address randomisation to reduce tracking, but it is not perfect, especially if Bluetooth, location services, captive portals, or app permissions combine into a broader fingerprint.


A shopping centre, airport, hotel, or town-wide Wi-Fi network can also collect valuable metadata. Even without reading message content, a network operator or attacker may learn when a device arrived, where it moved, and how long it stayed.


Wide-angle view of travellers using phones under an airport Wi-Fi sign
Large public networks can expose more background activity than most people expect.

Real incidents show the danger is not theoretical


Public Wi-Fi attacks are not just scary hypotheticals. Several well-known cases and demonstrations have shown how exposed users can be.


In 2010, the browser extension Firesheep showed how easily attackers on open Wi-Fi could hijack web sessions from people using poorly protected websites. It did not require advanced hacking from the user running it. The tool became widely discussed because it made a hidden weakness visible to the public.


Security researchers have also run controlled experiments by setting up fake free hotspots at busy events. People connected quickly, often accepting terms without reading them. In some tests, researchers could see device names, visited domains, and identifying details. These were demonstrations, not criminal data theft, but they showed how normal behaviour can expose private information.


A more serious example is the “Darkhotel” campaign, reported by security researchers in the mid-2010s. Attackers targeted hotel networks and used them to compromise selected travellers, including high-value business guests. Victims were tricked into installing malicious software through what looked like normal updates. The case showed how hotel Wi-Fi can become part of a larger attack chain.


There have also been repeated warnings from police and cyber security agencies about rogue hotspots in public places. The pattern is simple: a criminal creates a convincing network name, waits for people to connect, and then harvests useful data. Even if one stolen password does not seem serious, attackers often try the same login on email, banking, shopping, and social accounts.


Why your phone may connect without you noticing


Phones are designed to make connectivity easy. That convenience can work against you.


If auto-join is enabled, a phone may reconnect to a known network name when it sees something similar. Attackers can exploit that by copying the name of a common public hotspot. Some devices also switch between mobile data and Wi-Fi to save battery or improve speed, which can happen quietly in the background.


Captive portals add another risk. These are the pages that ask for an email address, room number, postcode, or agreement before access. Some are legitimate. Others are fake. A convincing login page can trick people into giving away personal details or reusing a password.


Bluetooth and location settings can add more signals. Nearby devices, beacons, and Wi-Fi access points help phones estimate location. Apps with broad permissions may combine this with account data. The result is a detailed picture of where someone has been, even when they never typed anything into a suspicious website.


Close-up of a phone showing Wi-Fi and location settings
Auto-join and location settings can reveal more than expected.

Simple ways to stay safer on public Wi-Fi


Public Wi-Fi is not always avoidable. The goal is to reduce risk, especially when travelling or handling sensitive accounts.


Use these habits whenever you connect.


  • Use a VPN

    A trusted VPN encrypts traffic between your device and the VPN provider. This makes it much harder for someone on the same network to read or tamper with your connection.


  • Avoid sensitive tasks

    Do not log in to banking, tax, work admin, or medical accounts on open Wi-Fi unless you have strong protection in place.


  • Check the network name

    Ask staff for the exact Wi-Fi name. Attackers rely on people choosing the first familiar-looking option.


  • Turn off auto-join

    Disable automatic connection to public networks. Remove old hotspots you no longer use.


  • Use mobile data for important logins

    A mobile network is often safer than unknown public Wi-Fi for banking or account recovery.


  • Keep software updated

    Updates fix security holes that attackers may try to use on shared networks.


  • Enable multi-factor authentication

    If a password is stolen, a second verification step can stop many account takeovers.


  • Use HTTPS only

    Look for secure connections, but do not rely on the padlock alone. Fake sites can also use HTTPS.


  • Turn off sharing

    Disable file sharing, AirDrop-style discovery, and public folder access when in public.


  • Forget the network afterwards

    This stops your device from reconnecting later without asking.


A password manager also helps. It reduces password reuse and makes fake login pages easier to spot because the manager will not autofill credentials on the wrong domain.


Overhead view of a person checking a VPN connection on a phone in a railway carriage
A VPN adds a strong layer of protection on shared networks.

A useful rule for open networks


Treat public Wi-Fi like a public conversation. It may be fine for reading the news, checking a map, or browsing general information. It is a poor place to share passwords, personal documents, card details, or anything that could cause harm if copied.


The danger is not that every café or airport network is malicious. The danger is that you often cannot tell the safe ones from the risky ones. Attackers take advantage of that uncertainty, along with rushed travel, low batteries, weak signals, and the habit of tapping “join” without thinking.


Public Wi-Fi can be useful, but it deserves caution. Use a VPN, keep auto-join under control, avoid sensitive logins, and remember that your phone may be sharing background data even when you are not actively using it. A few small habits can make the difference between convenient access and an avoidable security problem.


If you're unsure and worried about your connectivity, please pop in and we can take a look at your settings and let you know what is happening already.


 
 
 

Comments


bottom of page