Evil Twin Wi-Fi: How Fake Hotspots Steal Data From Remote Workers

Ulises Paiz

Ulises Paiz, Founder of Ghosxt, has 10+ years in IT infrastructure and cybersecurity, an Active Top Secret Clearance, and 9 certifications including CySA+, Security+, and AZ-104. Before founding Ghosxt, he served as a Senior Solutions Consultant for the DoD and built security programs for 40+ Central Coast businesses. More about Ulises →

Most small business Wi-Fi advice focuses on the office: segment the network, lock down the guest SSID, rotate the password. None of that helps the moment an employee opens a laptop at an airport gate or a coffee shop between meetings. Public Wi-Fi has no real owner checking who's broadcasting what, which is exactly the gap an evil twin attack exploits. It's one of the oldest tricks in wireless hacking, and it still works in 2026 because remote and hybrid work put more employees on unfamiliar networks more often than ever.

How an evil twin attack actually works

An attacker sets up a wireless access point, often just a laptop or a small travel router, and configures it to broadcast the same network name as a legitimate hotspot nearby: "Airport_Free_WiFi," a hotel's guest network, or a coffee shop's SSID. Many devices are configured to auto-join networks they recognize by name, and even a manual connection is easy to trick when the fake signal is stronger than the real one. Once a device joins the evil twin, the attacker controls everything that passes through it. Some attacks stop at simple eavesdropping on unencrypted traffic; more sophisticated versions inject a fake captive portal that asks for an email address and password "to continue," or silently intercept login sessions in a way that mirrors adversary-in-the-middle phishing. No malware has to land on the device, and no phishing email has to be sent. Being on the wrong network is enough.

Why this matters more as small business teams travel and work remote

  • It's a physical-proximity attack with no email trail. There's no phishing message for a spam filter to catch and no attachment for an EDR agent to scan, so it slips past defenses built around inbox and endpoint threats.
  • Business travel puts employees on unfamiliar networks by design. A field tech, a salesperson at a trade show, or an owner working from an airport lounge is exactly the target profile: someone who needs Wi-Fi now and has no way to verify who's really running it.
  • One connection is enough. Unlike a phishing campaign that needs someone to click, an evil twin only needs a device to join the wrong network for a few minutes to expose email, saved logins, or client files in transit.
  • The tools are cheap and require no special access. Evil twin kits are inexpensive, off-the-shelf hardware, meaning this isn't limited to sophisticated attackers; it shows up at any location with enough foot traffic and unsecured Wi-Fi.

What actually stops it

  • An always-on VPN with no split tunneling, configured to connect automatically the moment a device joins any new network, so traffic is encrypted before an evil twin can read it — not just for the apps someone remembers to route through it.
  • DNS filtering that travels with the device, not just the office network, so malicious or spoofed destinations get blocked regardless of which Wi-Fi a laptop happens to be on.
  • A "treat public Wi-Fi as hostile" policy, covering personal hotspots or cellular tethering as the default for sensitive work, with public Wi-Fi reserved for low-risk browsing only.
  • Managed device configuration that disables auto-join for open networks, so a laptop doesn't silently reconnect to a familiar-looking SSID without the user noticing.
  • Phishing-resistant MFA like passkeys, so that even a captive-portal credential-harvesting attempt on the fake network doesn't hand over usable account access.

Where this fits

FAQs about evil twin Wi-Fi attacks

How can I tell if a public Wi-Fi network is an evil twin?

You often can't tell just by looking, which is what makes evil twin hotspots effective. The fake network is set up to broadcast the exact same name as a legitimate one, sometimes with a stronger signal so devices connect to it automatically instead of the real access point. A few signs are worth checking: two networks with the identical name showing up in your Wi-Fi list, a captive portal login page that asks for more information than a coffee shop normally would, or a certificate warning in your browser that you would not expect on a trusted site. None of these are guaranteed to appear, which is why the safest habit is treating every open public network as untrusted rather than trying to spot the fake one.

Does a VPN fully protect me from evil twin Wi-Fi attacks?

A properly configured, always-on VPN closes off most of the risk, because it encrypts your traffic before it ever reaches the hotspot, so the attacker sitting on the fake network only sees scrambled data. The gap is timing and configuration: many VPN clients only activate after a device has already connected to Wi-Fi and pulled down a captive portal page, and split-tunneling setups that exclude certain apps from the VPN leave exactly those apps exposed. A VPN that connects automatically the moment a new network is joined, with no exceptions, is what actually delivers the protection people assume they already have.

Is my business at risk if employees only use public Wi-Fi occasionally while traveling?

Yes, and occasional use is actually the higher-risk pattern. An employee who rarely works from cafes or airports has less practice recognizing a network that looks slightly off, and a single bad connection during a business trip is enough to hand over an email session, a client file, or a set of saved credentials. It only takes one successful interception, not a habit of risky behavior, for an evil twin attack to reach the business. That is why the fix is a standing device policy, not a one-time reminder before a trip.

Not sure what happens to your team's laptops on the road?

30 minutes with a DoD-cleared engineer. We'll check your VPN configuration for split-tunneling gaps, confirm your devices have DNS filtering that works off any network, and map out a device policy that holds up at the airport gate, not just in the office.

Book your free security assessment
Call (831) 204-0501 Book free assessment