Evil twin

The cafe’s free Wi-Fi might not be the cafe’s.

Request a consultation

What it is

An evil twin is a fake Wi-Fi access point that uses the same name (SSID) as a legitimate network, like the one at a cafe, airport or hotel. Whoever connects goes through the attacker’s device, which can watch unprotected traffic or show fake login pages to steal data.

How it works

  1. 1The attacker creates a network with the same or almost the same name as the real one, often with a stronger signal.
  2. 2Sometimes they disconnect devices from the real network to push them to reconnect to the fake one.
  3. 3On connection, a fake portal asks for email, password or card details to “use the free Wi-Fi”.
  4. 4Unencrypted traffic can be read or altered; for HTTPS sites the main risk is convincing you to ignore security warnings.

How to spot it

  • Two networks with the same name, or a known network without a password when it usually has one
  • A portal asking for a credit card, social login or personal data to connect you
  • Invalid certificate warnings on sites you know
  • Sudden disconnections from your usual network

How to defend

  • Turn off auto-connect to open networks and forget the ones you no longer use
  • Ask the venue for the exact network name and password
  • For sensitive tasks use your phone’s hotspot or a reliable VPN
  • Never enter credentials or card data in a Wi-Fi portal
  • Do not ignore certificate warnings and enable multi-factor authentication on your accounts

If you think you have been hit

  • Disconnect from the network immediately
  • Change the passwords of the accounts you used (from a trusted network) and enable multi-factor authentication
  • If you entered card data, tell your bank
  • Check recent sign-ins and devices linked to your accounts

And there are many, many more

The attacks above are only some of the most common: there are hundreds, and new ones appear every week. If the one that concerns you is not among them, write to me: I will tell you whether it really affects you and how to defend.

Contact me

Other attacks

Watch the Shorts on YouTube

Matteo Russo · Updated October 2026

Let's talk
no strings attached

Want to know how exposed you are, train your team, or just ask a question? Write to me: I reply personally.

  1. You writeA couple of lines about your case: person, company, doubt or request.
  2. We talkA short intro call to understand what you really need.
  3. Practical defenseAssessment, consulting or training, with clear, prioritized actions.

Request a consultation

For security, the email address is not written on the page: press the button to reveal it and copy it in one click.

For companies and individuals. No scaremongering, just practical defense.