← All terms

Evil Twin Attack

An evil twin attack uses a rogue Wi-Fi access point that mimics a legitimate network to intercept traffic and steal credentials from users who connect.

An evil twin attack sets up a rogue Wi-Fi access point that impersonates a legitimate one — same network name (SSID), often a stronger signal — so that victims connect to the attacker's hardware instead of the real network. Once a device joins, the attacker sits in the middle of its traffic, able to serve fake login portals, intercept unencrypted data, and harvest credentials.

How it works

The attacker needs only commodity hardware — a laptop, a portable hotspot, or a purpose-built device like a Wi-Fi Pineapple — and a plausible location: an airport, hotel, coffee shop, conference venue, or an office lobby. The attack typically unfolds in four steps:

  1. Clone the network. The attacker broadcasts an SSID identical or nearly identical to the legitimate one ("Airport_Free_WiFi", "Hotel Guest"). Devices set to auto-join known networks may connect without the user touching anything.
  2. Force the switch. A deauthentication burst can knock nearby users off the real access point; their devices then reconnect to the strongest matching signal — the evil twin.
  3. Present a captive portal. The victim sees a familiar-looking login page asking for email credentials, a loyalty account, or a payment card to "activate" the connection. This is where most credential theft happens.
  4. Intercept and manipulate. As an on-path attacker, the operator can log unencrypted traffic, redirect victims to phishing pages, and in combination with adversary-in-the-middle tooling, capture session tokens even where MFA is in place.

Evil twins are a favorite tool in physical penetration tests and real intrusions alike because they attack the trust employees place in familiar network names — a form of spoofing aimed at infrastructure rather than people.

How to defend against it

  • Treat public Wi-Fi as hostile. Corporate devices should tunnel through a VPN automatically, and sensitive services should be reachable only over TLS.
  • Disable auto-join for open networks on managed devices, and periodically prune saved networks.
  • Prefer mobile hotspots over venue Wi-Fi for travel-heavy roles like sales and executives.
  • Never enter corporate credentials into a captive portal. A Wi-Fi login page asking for your Microsoft 365 password is an attack, full stop — a rule worth reinforcing through security awareness training.
  • Monitor your own airspace. Wireless intrusion detection can spot rogue SSIDs mimicking corporate networks near your offices.

Related terms

Adversary-in-the-Middle (AiTM)An adversary-in-the-middle (AiTM) attack proxies a real login page to steal both credentials and the session token issued after MFA is completed.SpoofingSpoofing is the falsification of an identity signal — sender address, caller ID, domain, or website — to make an attack appear to come from a trusted source.Session HijackingSession hijacking is the theft or takeover of an authenticated session — via stolen cookies or tokens — letting an attacker bypass login and MFA entirely.
See your Human Risk Score

NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.

Book a demo