Rogue Access Point
A rogue access point is an unauthorized Wi-Fi radio on or near your network — planted or naive — that lets attackers bypass the perimeter or harvest traffic.
A rogue access point is a wireless access point operating on or around your network without authorization. It comes in two flavors: an attacker-planted radio (a pocket-sized device hidden behind a printer, or a laptop broadcasting a hotspot) that creates a back door past the firewall, and the naive version — an employee plugging in a cheap home router "so the meeting room has Wi-Fi," a classic piece of shadow IT that opens the same hole with none of the intent.
How it works
Planted rogue APs are usually the payoff of a physical social-engineering step: someone tailgates into the office as a "contractor," finds a live network jack, and leaves behind a device that bridges the internal LAN to a cellular uplink. From there the attacker works remotely at leisure, inside the perimeter.
The related evil twin attack flips the direction: instead of joining your network, the attacker broadcasts a Wi-Fi name your people trust — the corporate SSID or the coffee-shop network — and waits for laptops and phones to auto-connect. Every connection hands the attacker a man-in-the-middle position for credential harvesting and session theft (see adversary-in-the-middle). Either way, the compromise looks like normal wireless traffic, which is why rogue radios routinely survive for months.
How to defend against it
- Scan the air, not just the wire. Wireless intrusion detection (built into most enterprise Wi-Fi) spots unknown SSIDs and radios; pair it with port security (802.1X) so an unauthorized device on a network jack gets nothing.
- Kill the trust in network location. Certificate-based Wi-Fi authentication and a zero-trust posture mean a rogue radio yields far less — being "on the network" should not be a credential.
- Close the physical loop. Rogue APs arrive through doors, so badge discipline, visitor escorts, and the scenarios in a social-engineering tabletop exercise belong in the same program.
- Give employees a sanctioned path. Guest Wi-Fi that actually works removes the reason well-meaning staff install their own — and awareness training should say plainly why a $30 router is a perimeter breach.
Related terms
NOUSEC simulates attacks across 8 channels and turns the results into one number your board can read.
Book a demo