Public Wi-Fi risk: a realistic guide to cafe, hotel and airport networks

Malware / security. Updated 2026-09-13. About 5 minutes to read.

On public Wi-Fi, the threat is being tricked into typing a password into the wrong page, so never enter account passwords into a Wi-Fi login portal and never click through a browser security warning.

Using public Wi-Fi is far safer than it was ten years ago. The FTC says that because of the widespread use of encryption, connecting through a public Wi-Fi network is usually safe. Almost every site and app you use encrypts traffic, so the person running the hotspot cannot read your passwords or messages.

The real risks are narrower and more human: a fake hotspot with a familiar name, a login page that asks for your email password, clicking through a browser warning, or someone reading your screen. This guide covers what to watch for and what is not worth worrying about.

Why HTTPS already protects most of what you send

When the address bar shows a padlock, the connection between your device and the website is encrypted. A hotspot operator, or someone else on the same network, can see that you connected to a site, but not the pages you read, the password you typed or the card number you entered. Banking, email and messaging apps encrypt their connections the same way.

What encryption cannot do is tell you whether the site is honest. As the FTC puts it, scammers create fake websites and encrypt them too, so your data may be encrypted on its way to the site but it will not be safe from the people running it.

The risks that are real

  • Fake hotspots: anyone can name a network 'Airport Free WiFi' or copy a cafe's network name. Australia's Cyber Security Centre notes that hotspot names are not unique and can be reused by criminals.
  • Captive portal phishing: a login page that asks you to sign in with your Google, Microsoft or Facebook account, or to enter a card for 'free' access, can be a credential harvester.
  • Clicking through certificate warnings: a warning that the connection is not private on a well-known site means something is intercepting it. Stop, do not continue.
  • Auto-join: your phone reconnecting to a saved network name it trusts, even when a stranger is broadcasting it.
  • Open file sharing: AirDrop set to Everyone, or a laptop with file sharing enabled on a network marked private.
  • Shoulder surfing: someone beside you, or a camera, watching you type a PIN or password.
  • Outdated devices: an unpatched phone or laptop is exposed to attacks on any network, public or not.

Connect safely in under a minute

  1. Confirm the exact network name with staff or signage before connecting.
  2. Prefer a network that needs a password from the venue over an open one.
  3. If the login page asks for an email account password, social media login or card details, close it and use your phone's hotspot instead.
  4. Check for the padlock on sites where you sign in, and leave immediately if the browser shows a security warning.
  5. On Windows, choose Public network when asked. On iPhone, set AirDrop to Contacts Only.
  6. When you leave, forget the network in your Wi-Fi settings and turn off auto-join for public hotspots.

Do you need a VPN on public Wi-Fi?

A VPN is useful but not essential. It hides which sites you visit from the hotspot operator, protects the rare app that still sends unencrypted data, and makes a hostile network much less interesting. It does not stop phishing, does not make a fake website safe, and shifts trust to the VPN company, which can see the same metadata the hotspot could.

If you use a VPN, pick a paid provider with a clear no-logs policy, and be wary of free VPN apps, some of which make money from your data. For banking on the move, your phone's mobile data is a simple alternative.

Two-factor authentication, ideally a passkey or authenticator app, protects you even if a password is captured on a fake page. It matters more than the network you use.

Public Wi-Fi myths you can stop worrying about

What the hotspot operator can still see is the names of the sites and services you connect to and how much data you use. If that matters to you, use mobile data or a VPN.

  • 'Someone on the cafe network can read my email.' Not when your email app or webmail uses an encrypted connection, which all major providers do.
  • 'Using incognito mode protects me on public Wi-Fi.' Private browsing only stops history being saved on your device. It does nothing about the network.
  • 'A password-protected network is private.' Everyone who has the password is on the same network. It reduces casual abuse but is not a private connection.
  • 'Turning Bluetooth off makes me safe.' Worth doing when you do not need it, but most real losses on public networks still come from fake login pages.

If you think you used a fake hotspot

  1. Disconnect and forget the network.
  2. Change the password for any account you signed in to while connected, starting with email, from a trusted connection.
  3. Sign out of other sessions in those accounts and turn on two-factor authentication.
  4. If you entered card details on a Wi-Fi login page, call your card issuer and ask for a replacement card.
  5. Check bank and card statements for the next few weeks, and update your device.

Frequently asked questions

Can someone hack my phone just because I joined public Wi-Fi?

It is unlikely on an up-to-date device. Most attacks on public networks rely on tricking you into entering details on a fake page or installing something. Keep your phone updated and avoid unknown login portals.

Is it safe to do online banking on public Wi-Fi?

Using your bank's official app over public Wi-Fi is generally safe because the app encrypts its connection. Using mobile data instead removes the fake hotspot risk entirely, so it is the better choice when available.

Is hotel Wi-Fi safer than cafe Wi-Fi?

Not necessarily. Hotel networks are often shared by hundreds of guests and frequently use login portals. Treat both the same way: confirm the name, avoid entering account passwords into portals, and watch for warnings.

Should I avoid public USB charging ports too?

The safest habit is to use your own charger in a power socket, or a power bank. That removes any risk from a tampered USB port without having to judge each one.

Tools that help

Related guides

Sources