Public Wi-Fi Security: What Is Actually Risky in 2026
By Aqui Tem Achadinhos Editorial · Updated September 20, 2026
The advice around public Wi-Fi has not updated since about 2010. The main threats changed; the recommendations mostly did not. Here is the current picture.
What is largely no longer a threat
Passive snooping on the network. Since HTTPS became universal, traffic on a shared network is encrypted end-to-end. A "hacker on the same Wi-Fi" cannot read your banking session the way they could in 2010.
WEP cracking. WEP is effectively extinct.
What genuinely is a threat now
Threat
How it works
Defence
Evil twin networks
A network named "Airport_WiFi_Free" impersonating the real one
Verify the exact network name with staff; use your carrier data instead
Captive portal phishing
Fake login page asking for email/social credentials
Never log in with an existing account to get online
DNS manipulation
Redirects you to a lookalike site
Check the address bar every time; use encrypted DNS
Unencrypted traffic
Any non-HTTPS traffic remains readable
Look for the padlock; avoid non-HTTPS logins entirely
Malware in downloads
"Install this to connect" prompts
Never install software a network asks you to install
What a VPN actually adds on public Wi-Fi
A VPN encrypts your traffic from your device to the VPN server. With HTTPS already protecting most of your traffic, the added benefit is narrower than marketing suggests — but it is real in these cases:
Untrusted DNS — the VPN routes DNS through its own resolver, bypassing local manipulation
Your ISP or network operator seeing which sites you visit — encrypted, so they see only the VPN endpoint
Unencrypted protocols — the minority of traffic still not using HTTPS is protected
Later networks that block sites — useful when a hotel filters content
The practical checklist for travel
Prefer your phone's hotspot over public Wi-Fi when using mobile data is affordable. It is materially more secure and often faster.
Confirm the network name with a staff member rather than picking the first matching SSID.
Never log into an existing account on a captive portal. Use a throwaway email if the portal requires one.
Ignore all software update prompts from networks, however official they look.
Enable 2FA on your important accounts — this defends you even if credentials leak.
Forget the network when you leave, so your device does not auto-reconnect to an imposter later.
Turn off file sharing and AirDrop-style discovery on untrusted networks.
⚠️ The biggest real risk is not technical
Overwhelmingly, the actual damage from public Wi-Fi comes from phishing pages and shoulder surfing — someone watching you type a password on a plane or in a café. A privacy screen and paying attention to the URL bar protect you better than most software.