Evil Twin Attack
An evil twin attack uses a rogue Wi-Fi access point that mimics a legitimate network to intercept traffic and steal credentials from users who connect.
An evil twin attack sets up a rogue Wi-Fi access point that impersonates a legitimate one — same network name (SSID), often a stronger signal — so that victims connect to the attacker's hardware instead of the real network. Once a device joins, the attacker sits in the middle of its traffic, able to serve fake login portals, intercept unencrypted data, and harvest credentials.
How it works
The attacker needs only commodity hardware — a laptop, a portable hotspot, or a purpose-built device like a Wi-Fi Pineapple — and a plausible location: an airport, hotel, coffee shop, conference venue, or an office lobby. The attack typically unfolds in four steps:
- Clone the network. The attacker broadcasts an SSID identical or nearly identical to the legitimate one ("Airport_Free_WiFi", "Hotel Guest"). Devices set to auto-join known networks may connect without the user touching anything.
- Force the switch. A deauthentication burst can knock nearby users off the real access point; their devices then reconnect to the strongest matching signal — the evil twin.
- Present a captive portal. The victim sees a familiar-looking login page asking for email credentials, a loyalty account, or a payment card to "activate" the connection. This is where most credential theft happens.
- Intercept and manipulate. As an on-path attacker, the operator can log unencrypted traffic, redirect victims to phishing pages, and in combination with adversary-in-the-middle tooling, capture session tokens even where MFA is in place.
Evil twins are a favorite tool in physical penetration tests and real intrusions alike because they attack the trust employees place in familiar network names — a form of spoofing aimed at infrastructure rather than people.
How to defend against it
- Treat public Wi-Fi as hostile. Corporate devices should tunnel through a VPN automatically, and sensitive services should be reachable only over TLS.
- Disable auto-join for open networks on managed devices, and periodically prune saved networks.
- Prefer mobile hotspots over venue Wi-Fi for travel-heavy roles like sales and executives.
- Never enter corporate credentials into a captive portal. A Wi-Fi login page asking for your Microsoft 365 password is an attack, full stop — a rule worth reinforcing through security awareness training.
- Monitor your own airspace. Wireless intrusion detection can spot rogue SSIDs mimicking corporate networks near your offices.
Related terms
NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.
Book a demo