Delta Air Lines is investigating an unauthorized Wi-Fi network that appeared on Flight 591 from Las Vegas to Atlanta, according to BleepingComputer. The flight was carrying passengers who had attended DEF CON 34, the hacker conference held in Las Vegas. Delta told BleepingComputer that the network was not provided, operated, or supplied by the airline and was present onboard only briefly. The company said the incident did not affect passenger safety or aircraft operating systems, and that no emergency was declared with air traffic control. The airline said it plans to work with federal law enforcement and aviation regulators as the investigation proceeds. Delta also told BleepingComputer that the aircraft was a Boeing 757 with six crew members and 199 passengers. After the crew learned about the unauthorized wireless network, the aircraft's Wi-Fi functionality was turned off for nearly 30 minutes, BleepingComputer reports. That response addresses the confirmed part of the incident: an unapproved wireless network appeared in the cabin environment during flight. The attack mechanism remains less settled. BleepingComputer says online reports alleged that several passengers returning from DEF CON carried out a Wi-Fi deauthentication attack mid-flight, disconnecting other passengers from the aircraft's in-flight network. Delta's statement, as reported, confirmed the unauthorized network but did not confirm that a deauthentication attack occurred or identify who was responsible. A deauthentication attack abuses Wi-Fi management traffic. As BleepingComputer explains, an attacker can forge frames that appear to come from a legitimate access point and instruct connected devices to disconnect. Repeatedly sending those frames can keep users off the real network and may be used to push them toward a rogue access point, sometimes called an evil twin. Networks using Protected Management Frames can reduce exposure to this kind of spoofed management-frame attack. BleepingComputer also cited Mary Perrault, described as a member of online frequent flyer groups with no formal affiliation to Delta, who said the fake Wi-Fi network displayed a phishing page that collected personal credentials and Google login data. Perrault also said federal authorities and airport police boarded the aircraft after it reached the gate to question suspects and seize portable Wi-Fi hardware. Those details have not been confirmed by Delta in the provided reporting. For now, the verified facts are narrower than the online narrative: Delta acknowledges an unauthorized onboard Wi-Fi network, a temporary shutdown of Wi-Fi, no declared emergency, and no reported effect on aircraft operating systems or passenger safety. The more serious claims — that passengers deliberately used deauthentication to disrupt connectivity and steer users to a credential-harvesting page — remain alleged pending the airline's and authorities' investigation. Who benefits: Airlines, connectivity providers, and security teams that can harden Wi-Fi management traffic and detect rogue access points have a clear operational case to review controls. Passengers benefit most from explicit network guidance and skepticism toward lookalike service set identifiers. Who's exposed: Passengers who connect to unverified in-flight networks are exposed to phishing and credential-harvesting risk if the alleged rogue access point claims are confirmed. Operators of public or semi-public Wi-Fi are exposed to disruption if deauthentication defenses are weak or inconsistently deployed.