Airport Wi‑Fi is safe to use if you join the airport’s real network and protect your traffic. The main risk is a look-alike hotspot set up by someone nearby. Check the official network name on airport signs or the airport’s website, never give a free Wi‑Fi page your card details or account passwords, and use a VPN or mobile data for anything sensitive.

Why airports are a target
Airports bring together thousands of people with time to kill, low phone batteries and a reason to sign in to things: email, banking, airline apps and hotel bookings. Free networks often have generic names, and many phones are set to join networks they have seen before without asking. That combination makes airports a convenient place to set up a fake hotspot.
How a fake hotspot (“evil twin”) works
Someone uses a laptop or a small portable device to broadcast a Wi‑Fi network with the same or a similar name to the airport’s — for example “Airport_Free_WiFi” instead of “Airport Free WiFi”. Phones that have joined a network with that name before, anywhere in the world, may connect automatically.
Once you are connected, the person running the hotspot controls your connection. They can:
- Show you a fake login page that asks for an email password, a social media login or card details.
- Redirect you to look-alike sites designed to collect passwords.
- Watch traffic that isn’t encrypted, plus the names of the sites you visit.
HTTPS limits what they can read from real websites — Google reports that 95–99% of Chrome page loads now use it. The danger is mostly what you are tricked into typing.
How to find the airport’s real network
- Use official sources. Network names are printed on signs, on the airport’s website and in its app. Information desks can confirm them.
- Check the exact spelling. Watch for extra spaces, underscores, “Free” added or removed, or the airport code in a different place.
- Be suspicious of duplicates. Two networks with nearly identical names in the same spot is a warning sign.
- Know what a real login page asks for. Usually accepting terms, sometimes an email address or watching an ad. Not your card details for “free” Wi‑Fi, not a password for another account, and never an app or profile to install.
Waysafe encrypts your connection with one tap and doesn’t keep activity logs. Free trial in the app.
Signs you’re on a fake network
- The login page asks for an account password or card details for free Wi‑Fi.
- Your browser shows certificate or “connection not private” warnings on sites that normally work.
- You are suddenly signed out of apps and asked to log in again through a web page.
- The page asks you to install something — a “security profile”, certificate or app.
If you see any of these, disconnect, forget the network and switch to mobile data.
A two-minute layover routine
- Keep Wi‑Fi off until you need it, so your phone doesn’t join anything on its own.
- Confirm the network name on an official sign or the airport’s site.
- Join and complete the login page, giving only what free Wi‑Fi normally needs.
- Connect your VPN before opening email, banking or work apps.
- Forget the network when you board, so your phone won’t rejoin a copy of it elsewhere.
Related guide: Wi‑Fi login page not showing? Captive portals, explained
Charging points and other airport risks
- Public USB ports. US agencies have warned that tampered USB ports could be used to load malware or copy data (“juice jacking”). Real cases are rare, but the fix is easy: use your own charger in a wall socket, a power bank, or a charge-only cable.
- Bluetooth and AirDrop. Set AirDrop to Contacts Only and turn off Bluetooth discovery to avoid unsolicited files and requests.
- Shoulder surfing. In busy gates, people can read your screen. A privacy filter helps on a laptop.
Frequently asked questions
Is it safe to check email on airport Wi‑Fi?
Yes, on the airport’s real network — email services use HTTPS. For extra safety, connect a VPN first and never enter your email password into a Wi‑Fi login page.
Is airport Wi‑Fi encrypted?
Most free airport networks are open, with no Wi‑Fi password, so the network itself doesn’t encrypt your connection. Your protection comes from HTTPS on the sites you use and from a VPN.
Is my phone’s hotspot safer than airport Wi‑Fi?
Generally yes, because mobile data runs directly to your carrier. If roaming is affordable, it is a good option for banking and work.
What should I do if I typed a password into a fake page?
Disconnect, then change that password from a trusted connection — starting with your email account — and turn on two-step verification. Check the account’s recent activity for sign-ins you don’t recognise.

