Malware / security. Updated 2026-09-13. About 5 minutes to read.
On public Wi-Fi, the threat is being tricked into typing a password into the wrong page, so never enter account passwords into a Wi-Fi login portal and never click through a browser security warning.
Using public Wi-Fi is far safer than it was ten years ago. The FTC says that because of the widespread use of encryption, connecting through a public Wi-Fi network is usually safe. Almost every site and app you use encrypts traffic, so the person running the hotspot cannot read your passwords or messages.
The real risks are narrower and more human: a fake hotspot with a familiar name, a login page that asks for your email password, clicking through a browser warning, or someone reading your screen. This guide covers what to watch for and what is not worth worrying about.
When the address bar shows a padlock, the connection between your device and the website is encrypted. A hotspot operator, or someone else on the same network, can see that you connected to a site, but not the pages you read, the password you typed or the card number you entered. Banking, email and messaging apps encrypt their connections the same way.
What encryption cannot do is tell you whether the site is honest. As the FTC puts it, scammers create fake websites and encrypt them too, so your data may be encrypted on its way to the site but it will not be safe from the people running it.
A VPN is useful but not essential. It hides which sites you visit from the hotspot operator, protects the rare app that still sends unencrypted data, and makes a hostile network much less interesting. It does not stop phishing, does not make a fake website safe, and shifts trust to the VPN company, which can see the same metadata the hotspot could.
If you use a VPN, pick a paid provider with a clear no-logs policy, and be wary of free VPN apps, some of which make money from your data. For banking on the move, your phone's mobile data is a simple alternative.
Two-factor authentication, ideally a passkey or authenticator app, protects you even if a password is captured on a fake page. It matters more than the network you use.
What the hotspot operator can still see is the names of the sites and services you connect to and how much data you use. If that matters to you, use mobile data or a VPN.
It is unlikely on an up-to-date device. Most attacks on public networks rely on tricking you into entering details on a fake page or installing something. Keep your phone updated and avoid unknown login portals.
Using your bank's official app over public Wi-Fi is generally safe because the app encrypts its connection. Using mobile data instead removes the fake hotspot risk entirely, so it is the better choice when available.
Not necessarily. Hotel networks are often shared by hundreds of guests and frequently use login portals. Treat both the same way: confirm the name, avoid entering account passwords into portals, and watch for warnings.
The safest habit is to use your own charger in a power socket, or a power bank. That removes any risk from a tampered USB port without having to judge each one.