In this article:
In this article:
Public and unsecured Wi-Fi networks are convenient. But are they safe? Learn the 10 hidden dangers of unsecured and public Wi-Fi networks (and what to do).
In this article:
In this article:
When Alec Daniels sat down at his local coffee shop, no one would have taken the 86-year-old for a hacker. But within less than 17 minutes, Alec had taken over the cafe’s public Wi-Fi hotspot and distributed phishing emails to everyone connected to the network [*].
The good news, is that Alec is an ethical hacker (a hobbyist who hacks to highlight cybersecurity vulnerabilities). The bad news? Not every hacker is here to help.
Whether you’re logging on to check your bank statements or working remotely from a cafe, hotel, or airport, using public Wi-Fi poses security risks that few people take seriously. According to a 2022 survey [*]:
Close to 50% of Americans regularly use Wi-Fi hotspots to carry out financial transactions, while 18% use public Wi-Fi to work remotely.
Without proper precautions, hackers can take advantage of public Wi-Fi’s lax security to spy on you, steal your personal information and passwords, or even take over your online accounts.
In this guide, we’ll explain how cybercriminals hack Wi-Fi networks, the true dangers of public Wi-Fi, and what you can do to keep your devices and personal information safe and secure.
{{show-toc}}
The short answer is yes, you can get hacked using public Wi-Fi.
Cybercriminals use a combination of technical know-how and free tools to sneak into unsecured networks and steal sensitive information. This could include passwords, banking information, or personal data that can be used for identity theft.
Here’s how public Wi-Fi networks get hacked:
Most people believe using public Wi-Fi is safe by default. But in reality, many networks use cheap routers and access points which lack essential security measures.
These 10 hidden dangers and unsecured Wi-Fi risks show how finding a secure connection is the exception — not the norm.
One of the greatest risks of using public Wi-Fi is having your identity stolen. If you’re not using a virtual private network (VPN) to hide your information, hackers could easily discover enough information about you to create targeted cyberattacks and phishing emails, search for your passwords on the Dark Web, or break into your online accounts.
At a minimum, hackers can snoop you over public Wi-Fi and discover:
How to keep your data safe on public Wi-Fi:
Strong encryption is the best way to avoid exposing personal data over public Wi-Fi. To stay safe, use a virtual private network (VPN) when connecting to any Wi-Fi hotspot — including your own.
{{hacker-view-widget}}
Using a public hotspot without protection makes it easy for attackers to sneak malicious software (malware) into your device.
Scammers can inject an infected ad into a seemingly safe website, trick you into filling out a phishing form, or even fool you into installing a fake app that records everything you type.
How to protect your devices against malware:
Anti-malware and a VPN service are essential security layers that provide protection for your entire digital life. These tools work 24/7 to keep your device and data safe as you move from one Wi-Fi network to another.
📚 Related: Have I Been Hacked? How To Recognize & Recover From a Hack →
Some hackers use specialized tools that search for passwords you’ve saved in your browser or typed into websites, apps, or emails while using public Wi-Fi.
Leaking your passwords is one of the most damaging public Wi-Fi risks because it gives malicious hackers direct access to your accounts. The fallout is even worse with business login data. For example, tech giant Cisco got hacked when an employee’s personal Google account login credentials were compromised [*].
How to protect your passwords:
A VPN will help hide your passwords from snooping scammers. However, it’s also a good idea to securely store all of your credentials in a password manager. A password manager automatically fills in your login data into websites, hiding it from eavesdropping hackers.
Public Wi-Fi networks are notoriously vulnerable to surveillance by bad actors looking for sensitive documents such as confidential contracts, invoices, and two-factor authentication (2FA) codes.
Your personal finances and job security could also be at risk if you use public Wi-Fi. An online session over public Wi-Fi can lead to an NDA (non-disclosure agreement) breach or to endangering your colleagues’ work.
How to keep your sensitive documents safe:
Whether you’re an employee or a business owner, it’s extremely important to be aware of security risks associated with using public Wi-Fi. A strong cybersecurity suite that protects you and your employees is essential. So is avoiding sending, receiving, and talking about confidential information over open hotspots.
In Business Email Compromise (BEC) scams, fraudsters target your work email and send fake messages pretending to be someone you know. They may ask you to change payment information or send wire transfers to fake “clients.”
BEC scams can target anyone – from small local businesses to large corporations. In 2021, they caused $6.9 billion in losses [*].
How to protect yourself:
Scammers will spend significant time and money to try and trick you. It’s essential that you learn how to tell if an email is from a scammer.
Digital security education helps you become more cautious. It also trains you to develop safer reflexes, such as double-checking transactions. And, if the worst happens, having financial fraud and credit protection with included identity theft insurance can be life-saving.
📚 Related: How Does Identity Theft Insurance Work? Do You Need It?→
Cyberattacks against open Wi-Fi networks also seek entry points into data storage platforms. Once bad actors have access to your sensitive data, they can blackmail you for its release.
Ransomware attacks grew 80% in 2022, putting businesses and individuals at heightened risk [*].
How to protect yourself:
First off, don’t log into sensitive file-sharing services over public Wi-Fi. But if you must, make sure you’re using tools like a VPN to encrypt your data. Finally, always keep a backup of your most important data somewhere safe, ideally disconnected from the internet.
📚 Related: How To Protect Against Ransomware (10 Prevention Tips) →
Through session hijacking, malicious hackers take over the connection between your device and the website or app that you’re using. This gives them the same rights that you have as a legitimate, logged-in user. For example, they could break into an online store and use your stored credit card information.
Cybercriminals covet the free rein this type of attack gives them. It allows them to take over your accounts or bypass website security measures without needing a password.
How to avoid session hijacking when on public Wi-Fi:
For safe online shopping, never store your credit card details in your online account, no matter how convenient it seems. And for added security, choose an always-on, all-in-one protection plan that combines device and online security with identity and financial fraud protection.
📚 Related: Is Hotel Wi-Fi Safe? How To Secure Your Devices When Traveling →
Account takeovers happen when bad actors gain unauthorized access to your accounts and take full control of them. This could include your email, bank, or even social media accounts.
Since financial institutions hardened their authentication measures, cybercriminals have been focusing on account takeover tactics that get around these measures, such as tricking you into providing 2FA codes.
How to protect yourself against account takeover fraud on public Wi-Fi:
At a minimum, always use a VPN to encrypt your data whenever you need to log into sensitive accounts (banking, online shopping, email, etc.). It’s even better to keep your VPN on at all times, so you don’t have to worry about using these high-value services.
It also helps to know if your personal data — including passwords and your Social Security number (SSN) — has been leaked in data breaches. This helps you know which of your accounts is at risk and offers you the chance to react promptly.
📚 Related: How To Know If a Website Is Safe →
Phishing is a form of social engineering attack that uses deceptive messages to get victims to release sensitive information. This can include passwords, authentication codes, documents, and more.
By hacking into Wi-Fi hotspots, attackers can intercept network traffic and inject phishing attacks in the form of phishing emails, text messages, and voicemails.
How to avoid phishing attacks over public Wi-Fi:
In 2021, U.S. consumers and businesses lost over $54 million to phishing [*]. So it’s wise to add even more layers to your cybersecurity ecosystem in order to reduce the risk of aggressive phishing attacks.
The Federal Trade Commission (FTC) recommends that you [*]:
📚 Related: How To Prevent Phishing Attacks (17 Easy Tips) →
In the worst case scenario, hackers may even be able to infect your device with malware that gives them remote access — or control — of it. This malware is often hidden inside infected ads on websites that hackers control.
How to protect your devices from remote access malware when on public Wi-Fi:
Multi-layered digital security is the most effective approach to keeping all your devices safe — no matter what you use them for.
An ideal digital security suite must include five essential components:
Aura combines all of these security layers into one single, easy-to-use platform.
If you want to stay completely secure, the best thing you can do is to not use public Wi-Fi connections. But, if you need to log-on or do work while on the go, there are a few ways you can boost your personal public Wi-Fi security.
Here’s what to do before, during, and after using public Wi-Fi to ensure your data and accounts stay safe:
📚 Related: Can Bluetooth Be Hacked? Bluetooth Security Tips for 2023 →
Almost half of surveyed U.S. internet users trust public hotspots to keep their information safe [*]. Yet most owners of establishments that offer free Wi-Fi aren’t more technically skilled than the majority of home users.
Your home network wasn’t set up by a cybersecurity specialist, and your favorite cafe’s Wi-Fi network wasn’t either. If you can’t tell if your home Wi-Fi was hacked, neither can they.
Unless you are connected to a professionally designed and secure network, assume all hotspots are unsafe.
In spite of this harsh reality, there are instances when you will need to use public networks, especially for remote work or emergencies.
Here are 10 ways to check if a Wi-Fi network is safe to use:
💡 Related: 12 Reasons Why You Should Be Using a VPN →
A common misconception is that the “HTTPS” part of a web address automatically marks it as safe to use. This is no longer true — 82% of phishing websites [*] use encryption certificates to make them appear more convincing.
Instead, click on the padlock symbol near the URL to ensure that the site you’re visiting is using a secure connection, and that the security certificate is issued to the company you expect. (For example, any site that claims to be from Apple should have a certificate issued to Apple Inc.)
Remember, cybercriminals are quick to pivot to tactics that people trust. This makes it incredibly difficult to notice the deception without automated tools such as antivirus software.
Online security doesn’t have to be a constant trade-off between safety and convenience.
Despite Wi-Fi hacking and malware threats, using public hotspots is still an option, under one condition: that you have all-in-one protection that takes care of all the devices and data in your digital ecosystem.
For protection against scammers, hackers, and Wi-Fi snoopers, consider signing up for Aura.
Editorial note: Our articles provide educational information for you to increase awareness about digital safety. Aura’s services may not provide the exact features we write about, nor may cover or protect against every type of crime, fraud, or threat discussed in our articles. Please review our Terms during enrollment or setup for more information. Remember that no one can prevent all identity theft or cybercrime.