Delta probes Wi-Fi deauth attack on flight carrying DEF CON attendees

Delta Air Lines is investigating an unauthorized Wi-Fi network that appeared aboard a flight from Las Vegas to Atlanta carrying passengers who had attended the DEF CON hacker convention.

The company told BleepingComputer that the incident occurred on Flight 591 and did not affect the safety of the passengers or aircraft operating systems.

“We will partner with federal law enforcement and aviation regulators to ensure the incident is thoroughly investigated,” a company spokesperson said.

“One initial finding is an unauthorized WiFi network, which was not provided, operated, or supplied by Delta, was present onboard the aircraft for a short time during the flight.”

After learning about the unauthorized wireless network, the cabin crew deactivated the Wi-Fi functionality in the aircraft for nearly 30 minutes.

Wi-Fi Deauth Attack

According to online reports, several passengers returning from the DEF CON 34 hacking conference allegedly carried out a Wi-Fi deauthentication attack mid-flight, disconnecting other passengers from the aircraft’s wireless in-flight network.

In a deauthentication attack, clients connected to a Wi-Fi network receive forged packets pretending to be from the legitimate access point (AP), telling them to disconnect.

An attacker can observe wireless traffic to identify the access point’s MAC address, then forge deauthentication frames with the AP’s address as the source and send them to connected clients.

By repeatedly transmitting forged deauthentication frames, the attacker can repeatedly disconnect clients from the access point, potentially causing a denial-of-service condition. Networks that use Protected Management Frames (PMF) can mitigate this type of spoofed management-frame attack.

Typically, hackers use deauthentication attacks to force clients to reconnect to a rogue AP — for example, an evil twin — in order to intercept traffic or direct targets to malicious pages.

Rogue Wi-Fi Network

Turbine Traveller, an aircraft technician based in Nairobi, says messages sent by the crew of Delta Air Lines Flight 591 via the Aircraft Communications Addressing and Reporting System (ACARS) indicated that some passengers were able to jam the aircraft’s Wi-Fi and broadcast a rogue network named “Delta WiFi Fast”:

“WE HAVE A BUNCH OF PAX [passenger] THAT WERE AT A CYBER CONFERENCE IN LAS… THEY WERE ABLE TO JAM OUR WIFI AND BROADCAST THEIR SIGNAL.”

“WE HAVE A PAX ON THIS HAS CREATED A SCAM WIFI CALLED DELTA WIFI FAST. WE BELIEVE THEY ARE TRYING TO SCAM THE OTHER PAX.”

Mary Perrault, a member of online frequent flyer groups with no formal affiliation to Delta Air Lines, states that the fake Wi-Fi network displayed a phishing page that collected personal credentials and Google login data.

After the aircraft docked at the gate, federal authorities and airport police boarded the aircraft to question the suspects and seize their portable Wi-Fi hardware, Perrault said. The suspects had allegedly been attending the DEF CON 34 hacker conference in Las Vegas.

The Delta Air Lines spokesperson told BleepingComputer that the aircraft was a Boeing 757 carrying six crew members and 199 passengers, and confirmed that no emergency was declared with air traffic control. Delta stated it will continue working with federal law enforcement and aviation regulators as the investigation proceeds.