Connect with us

Published

on

Over the years, travelers have repeatedly been warned to avoid public Wi-Fi in places like airports and coffee shops. Airport Wi-Fi, in particular, is known to be a hacker honeypot, due to what is typically relatively lax security. But even though many people know they should stay away from free Wi-Fi, it proves as irresistible to travelers as it is to hackers, who are now updating an old cybercrime tactic to take advantage.

An arrest in Australia over the summer set off alarm bells in the United States that cybercriminals are finding new ways to profit from what are called “evil twin” attacks. Also classified within a type of cybercrime called “Man in the Middle” attacks, evil twinning occurs when a hacker or hacking group sets up a fake Wi-Fi network, most often in public settings where many users can be expected to connect.

In this instance, an Australian man was charged with conducting a Wi-Fi attack on domestic flights and airports in Perth, Melbourne, and Adelaide. He allegedly set up a fake Wi-Fi network to steal email or social media credentials.

“As the general population becomes more accustomed to free Wi-Fi everywhere, you can expect evil twinning attacks to become more common,” said Matt Radolec, vice president of incident response and cloud operations at data security firm Varonis, adding that no one reads the terms and conditions or checks the URLs on free Wi-Fi.

“It’s almost a game to see how fast you can click “accept” and then ‘sign in’ or ‘connect.’ This is the ploy, especially when visiting a new location; a user might not even know what a legitimate site should look like when presented with a fake site,” Radolec said.

Today’s ‘evil twins’ can more easily hide

One of the dangers of today’s twinning attacks is that the technology is much easier to disguise. An evil twin can be a tiny device and can be tucked behind a display in a coffee shop, and the small device can have a significant impact.

“A device like this can serve up a compelling copy of a valid login page, which could invite unwary device users to enter their username and password, which would then be collected for future exploitation,” said Cincinnati-based IT consultant Brian Alcorn. 

The site doesn’t even have to actually log you in. “Once you’ve entered your information, the deed is done,” Alcorn said, adding that a harried, weary traveler probably would just think the airport Wi-Fi is having issues and not give it another thought.  

People who are not careful with passwords, such as use of pet’s names or favorite sports teams as their password for everything, are even more vulnerable to an evil twin attack. Alcorn says for individuals who reuse username and password combinations online, once the credentials are obtained they can be fed into AI, where its power can quickly give cybercriminals the key.

“You are susceptible to exploitation by someone with less than $500 in equipment and less skill than you might imagine,” Alcorn said. “The attacker just has to be motivated with basic IT skills.”

How to avoid becoming a victim of this cybercrime

When in public places, experts say it’s best to use alternatives to public WiFi networks.

“My favorite way to avoid evil twin attacks is to use your phone’s mobile hotspot if possible,” said Brian Callahan, Director of the Rensselaer Cybersecurity Collaboratory at Rensselaer Polytechnic Institute.

Users would be able to spot an attack if through a phone relying on its mobile data and sharing it via a mobile hotspot.

“You will know the name of that network since you made it, and you can put a strong password that only you know on it to connect,” Callahan said.

If a hotspot isn’t an option, a VPN can also provide some protection, Callahan said, as traffic should be encrypted to and from the VPN.

“So even if someone else can see the data, they can’t do anything about it,” he said.

Airport, airline internet security issues

At many airports, the responsibility for WiFi is outsourced and the airport itself has little if any involvement in safeguarding it. At Dallas Fort Worth International Airport, for example, Boingo is the Wi-Fi provider.

“The airport’s IT team does not have access to their systems, nor can we see usage and dashboards,” For said an airport spokesman. “The network is isolated from DAL’s systems as it is a separate standalone system with no direct connection to any of the City of Dallas’ networks or systems internally.” 

A spokeswoman for Boingo, which provides service to approximately 60 airports in North America, said it can identify rogue Wi-Fi access points through its network management. “The best way passengers can be protected is by using Passpoint, which uses encryption to automatically connect users to authenticated Wi-Fi for a safe online experience,” she said, adding that Boingo has offered Passpoint since 2012 to enhance Wi-Fi security and eliminate the risk of connecting to malicious hotspots.

Alcorn says evil twin attacks are “definitely” occurring with regularity in the United States, it’s just rare for someone to get caught because they are such stealth attacks.  And sometimes hackers use these attacks as a learning model. “Many evil twin attacks may be experimental by individuals with novice-to-intermediate skills just to see if they can do it and get away with it, even if they don’t use the collected information right away,” he said.

The surprise in Australia wasn’t the evil twinning attack itself, but the arrest.

“This incident isn’t unique, but it is unusual that the suspect was arrested,” said Aaron Walton, threat analyst at Expel, a managed services security company. “Generally, airlines are not equipped and prepared to handle or mediate hacking accusations. The typical lack of arrests and punitive action should motivate travelers to exercise caution with their own data, knowing what a tempting and usually unguarded -target it is — especially at the airport.”

In the Australian case, according to Australian Federal Police, dozens of people had their credentials stolen.

According to a press release from the AFP, “When people tried to connect their devices to the free WiFi networks, they were taken to a fake webpage requiring them to sign in using their email or social media logins. Those details were then allegedly saved to the man’s devices.”  

Once those credentials were harvested, they could be used to extract more information from the victims, including bank account information.

For hackers to be successful, they don’t have to dupe everyone. If they can persuade only a handful of people – statistically easy to do when thousands of harried and hurried people are milling around an airport – they will succeed.

“We expect WI-Fi to be everywhere. When you go to a hotel, or an airport, or a coffee shop, or even just out and about, we expect there to be Wi-Fi and often freely available WI-FI,” Callahan said. “After all, what’s yet another network name in the long list when you’re at an airport? An attacker doesn’t need everyone to connect to their evil twin, only some people who go on to put credentials into websites that can be stolen.”

The next time you’re at the airport, the only way to be 100% sure you’re safe is to bring your own Wi-Fi.

Continue Reading

Technology

Tesla’s stock erases loss for the year, soaring 85% from April low

Published

on

By

Tesla's stock erases loss for the year, soaring 85% from April low

Tesla CEO Elon Musk attends the Saudi-U.S. Investment Forum, in Riyadh, Saudi Arabia, May 13, 2025.

Hamad I Mohammed | Reuters

Tesla’s shares have finally turned positive for the year.

After a dismal first quarter, which was the worst for the stock in any period since 2022, and a brutal start to April, following President Donald Trump’s announcement of sweeping new tariffs, Wall Street has again rallied around the electric vehicle maker.

The stock rose 3.6% on Monday to $410.26, topping its closing price of 2024 by over $6. It’s up 85% since bottoming for the year at $221.86 on April 4. A new filing revealed that CEO Elon Musk purchased about $1 billion worth of shares in the company through his family foundation.

It’s the second straight year Tesla has bounced back after a down first quarter. Last year, the shares fell 29% in the first three months before ending up 63% for 2024.

In recent weeks, analysts have praised the EV maker’s proposed pay plan for Musk, which could amount to a $1 trillion windfall for the world’s richest person over the next decade. The company has also gotten a boost from its new MegaBlocks battery energy storage systems that Tesla ships preassembled to businesses looking to lower their power costs or make greater use of electricity from renewable resources.

Even with the rebound, Tesla is the second-worst performer this year among tech’s megacaps, ahead of only Apple, which is down about 5% in 2025. Tesla is still in the midst of a multi-quarter sales slump due to an aging lineup of EVs and increased competition from lower-cost competitors in China, namely BYD.

Tesla has seen a consumer backlash, in part because of Musk’s political activities, including spending nearly $300 million to propel President Trump back to the White House and his work with the Trump administration to slash the federal workforce.

Tesla leadership has been working to shift investors’ attention to other topics such as robotaxis and humanoid robots.

However, the company has yet to deliver vehicles that are safe to use without a human onboard and ready to take control if needed. And while Musk is touting Tesla’s Optimus robots, which he says will be able to do everything from factory work to babysitting, a product is still a long way from hitting the market.

WATCH: Musk’s share purchase

Elon Musk's Tesla stock purchase is a great vote of confidence, says Sand Hill's Brenda Vingiello

Continue Reading

Technology

Alphabet becomes fourth company to reach $3 trillion market cap

Published

on

By

Alphabet becomes fourth company to reach  trillion market cap

Google CEO Sundar Pichai gestures to the crowd during Google’s annual I/O developers conference in Mountain View, California on May 20, 2025.

Camille Cohen | Afp | Getty Images

Alphabet has joined the $3 trillion club.

Shares of the search giant jumped more than 4% on Monday, pushing the company into territory occupied only by Nvidia, Microsoft and Apple.

The stock got a big lift in early September from an antitrust ruling by a judge, whose penalties came in lighter than shareholders feared. The U.S. Department of Justice wanted Google to be forced to divest its Chrome browser, and last year a district court ruled that the company held an illegal monopoly in search and related advertising.

But Judge Amit Mehta decided against the most severe consequences proposed by the DOJ, which sent shares soaring to a record. After the big rally, President Donald Trump congratulated the company and called it “a very good day.”

Read more CNBC tech news

Alphabet shares are now up more than 30% this year, compared to the 15% gain for the Nasdaq.

The $3 trillion milestone comes roughly 20 years after Google’s IPO and a little more than 10 years after the creation of Alphabet as a holding company, with Google its prime subsidiary.

CEO Sundar Pichai was named CEO of Alphabet in 2019, replacing co-founder Larry Page. Pichai’s latest challenge has been the surge of new competition due to the rise of artificial intelligence, which the company has had to manage through while also fending off an aggressive set of regulators in the U.S. and Europe.

The rise of Perplexity and OpenAI ended up helping Google land the recent favorable antitrust ruling. The company’s hopes of becoming a major AI player largely ride with Gemini, Google’s flagship suite of AI models.

WATCH: EU fines Google almost $3 billion

EU fines Google almost $3 billion over AdTech practices, reports say

Continue Reading

Technology

Bessent: TikTok deal ‘framework’ reached with China, Trump and Xi will finalize it Friday

Published

on

By

Bessent: TikTok deal 'framework' reached with China, Trump and Xi will finalize it Friday

Samuel Boivin | Nurphoto | Getty Images

The U.S. and China have reached a ‘framework’ deal for social media platform TikTok, Treasury Secretary Scott Bessent said Monday.

“It’s between two private parties, but the commercial terms have been agreed upon,” he said from U.S.-China talks in Madrid.

Both President Donald Trump and Chinese President Xi Jinping will meet Friday to discuss the terms. Trump also said in a Truth Social post Monday that a deal was reached “on a ‘certain’ company that young people in our Country very much wanted to save.”

Bessent indicated that the framework could pivot the platform to U.S.-controlled ownership.

TikTok did not immediately respond to a request for comment.

The comments came during the latest round of trade discussions between the U.S. and China. Relations have soured between the two countries in recent months from Trump’s tariffs and other trade restrictions.

At the same time, TikTok parent company ByteDance faces a Sept. 17 deadline to divest the platform’s U.S. business or face being shut down in the country.

U.S. Trade Representative Jamieson Greer said Monday that the deadline may need to be pushed back to get the deal signed, but there won’t be ongoing extensions.

Read more CNBC tech news

Congress passed a law last year prohibiting app store operators like Apple and Google from distributing TikTok in the U.S. due to its “foreign adversary-controlled application” status.

But Trump postponed the shutdown in January, signing an executive order in January that gave ByteDance 75 more days to make a deal. Further extensions came by way of executive orders in April and in June.

Commerce Secretary Howard Lutnick said in July that TikTok would shutter for Americans if China doesn’t give the U.S. more autonomy over the popular short-form video app.

As for who controls the platform, Trump told Fox News in June that he had a group of “very wealthy people” ready to buy the app and could reveal their identities in two weeks. The reveal never came.

He has previously said he’d be open to Oracle Chairman Larry Ellison or Tesla CEO Elon Musk buying TikTok in the U.S. Artificial intelligence startup Perplexity has submitted a bid for an acquisition, as has businessman Frank McCourt’s Project Liberty internet advocacy group, CNBC reported in January.

Trump told CNBC in an interview last year that he believed the platform was a national security threat, although the White House started a TikTok account in August.

White House launches TikTok account

Continue Reading

Trending