Fake Wi-Fi Hotspot Scam UK: Verify the Network
Ask staff for the exact network name. For sensitive work, mobile data or a trusted, correctly configured VPN reduces exposure to a rogue hotspot.
What an evil twin is
NCSC describes an evil twin as an attacker-owned access point that uses the same or a similar name as a legitimate network, potentially allowing the attacker to intercept or manipulate traffic from connected devices.
The name alone is therefore not enough. Two networks can look identical in a phone’s Wi-Fi list.
HTTPS helps, but does not validate the hotspot
Modern banking, email and shopping services normally use HTTPS/TLS to encrypt traffic between the device and the genuine service. That materially limits what a local network attacker can read or alter.
It does not make a fake hotspot harmless. An attacker can still present a deceptive captive portal, exploit unencrypted or badly configured services, probe exposed local services, or direct the user to a phishing site. A padlock proves the connection to the domain shown in the browser, not that the Wi-Fi belongs to the venue.
Warning signs
- Duplicate or near-duplicate network names.
- A captive portal asking for an email password, banking details or an unrelated account login.
- Certificate or browser security warnings.
- Staff cannot confirm the network name or access method.
- The device reconnects automatically to an unexpected open network.
An open network is not automatically fraudulent; many legitimate venues operate one. Verification matters more than whether a password is present.
Safer connection choices
Ask venue staff to identify the correct network. For sensitive activity, using your own mobile connection instead of an unknown hotspot avoids the rogue-access-point problem. If an organisation provides a trusted, properly configured full-device VPN, it can protect traffic across an untrusted local network; NCSC’s “evil twin” exercise says VPN use can prevent this interception pattern.
Do not install a random “free VPN” in response to a pop-up. A VPN operator can itself see or influence traffic and must be trusted.
If you connected to a suspicious network
Disconnect and forget the network so the device does not automatically rejoin. From a trusted connection, change any password entered into the hotspot or a suspicious page, review account sessions and enable a passkey or two-step verification. If software or a certificate profile was installed, remove it and follow the device vendor’s security guidance.
If money was lost or accounts were compromised, report at reportfraud.police.uk or on 0300 123 2040 in England, Wales or Northern Ireland; in Scotland, call Police Scotland on 101.
Frequently asked questions
Does HTTPS remove all public Wi-Fi risk?
No. It strongly protects traffic to a correctly authenticated HTTPS service, but it does not prove the network or a captive portal is genuine.
Is every password-free hotspot fake?
No. Confirm the network with the venue rather than using the presence or absence of a password as the deciding test.
Does NCSC tell every individual to buy a VPN?
No. NCSC’s detailed VPN guidance is mainly for organisations. Its evil-twin material says a VPN can prevent that attack, while other NCSC advice recommends verifying the hotspot or using mobile tethering.
Sources checked
- NCSC: Connecting securely—micro exercise
- NCSC: VPN guidance
- NCSC: KRACK Wi-Fi guidance
- NCSC: Small Business Guide — avoid unknown Wi-Fi hotspots
- Report Fraud: reporting cyber crime and fraud