Security Guide

Public Wi-Fi Security: What Is Actually Risky in 2026

By Aqui Tem Achadinhos Editorial · Updated September 20, 2026
Public Wi-Fi Security: What Is Actually Risky in 2026

The advice around public Wi-Fi has not updated since about 2010. The main threats changed; the recommendations mostly did not. Here is the current picture.

What is largely no longer a threat

What genuinely is a threat now

ThreatHow it worksDefence
Evil twin networksA network named "Airport_WiFi_Free" impersonating the real oneVerify the exact network name with staff; use your carrier data instead
Captive portal phishingFake login page asking for email/social credentialsNever log in with an existing account to get online
DNS manipulationRedirects you to a lookalike siteCheck the address bar every time; use encrypted DNS
Unencrypted trafficAny non-HTTPS traffic remains readableLook for the padlock; avoid non-HTTPS logins entirely
Malware in downloads"Install this to connect" promptsNever install software a network asks you to install

What a VPN actually adds on public Wi-Fi

A VPN encrypts your traffic from your device to the VPN server. With HTTPS already protecting most of your traffic, the added benefit is narrower than marketing suggests — but it is real in these cases:

The practical checklist for travel

  1. Prefer your phone's hotspot over public Wi-Fi when using mobile data is affordable. It is materially more secure and often faster.
  2. Confirm the network name with a staff member rather than picking the first matching SSID.
  3. Never log into an existing account on a captive portal. Use a throwaway email if the portal requires one.
  4. Ignore all software update prompts from networks, however official they look.
  5. Enable 2FA on your important accounts — this defends you even if credentials leak.
  6. Forget the network when you leave, so your device does not auto-reconnect to an imposter later.
  7. Turn off file sharing and AirDrop-style discovery on untrusted networks.

⚠️ The biggest real risk is not technical

Overwhelmingly, the actual damage from public Wi-Fi comes from phishing pages and shoulder surfing — someone watching you type a password on a plane or in a café. A privacy screen and paying attention to the URL bar protect you better than most software.

See NordVPN →

Check audited no-logs plans · Affiliate link — we may earn a commission at no extra cost to you.