- August 3, 2026
- admin
- 0
Public Wi-Fi While on Holiday: A Convenient Connection That Requires Caution
Summer is a time for holidays, travel and working outside the usual office environment. Free Wi-Fi networks have become almost standard at airports, hotels, restaurants, campsites, shopping centres and other public places. They allow us to check our email, find directions to our accommodation, make an online reservation or access work-related documents without using mobile data.
However, a public Wi-Fi network is not the same as a trusted home or workplace network. Users generally do not know who manages the network, how well it is protected, who else is connected to it or whether the access point displayed on their device is really what it claims to be.
Public Wi-Fi networks should therefore be used with caution, especially when accessing business systems, email, online banking or other sensitive information.
Are All Public Networks Dangerous?
No. Connecting to a public network does not automatically mean that someone will intercept our data or take control of our user account.
Today, most websites use an encrypted HTTPS connection. This type of connection encrypts the data exchanged between the browser and the website being visited. It can be identified by “https” and the padlock symbol in the browser’s address bar. The US Federal Trade Commission explains that, due to the widespread use of encryption, connecting through a public network is generally safer today than it was in the past.
However, HTTPS does not eliminate every risk. For example, an encrypted connection cannot protect us if we visit a fraudulent website operated by an attacker. A malicious website can also use HTTPS and display a padlock symbol. The padlock means that the connection to the website is encrypted, but it does not confirm that the website is legitimate or trustworthy.
When using public networks, we must therefore verify both the network we are connecting to and the websites and services we intend to use.
The Most Common Threat Is a Fake Wi-Fi Network
An attacker can set up their own wireless access point and give it a name that closely resembles the name of a legitimate network. For example, such a network could be named:
- Hotel_Guest_WiFi,
- Airport_Free_WiFi,
- Camping_Guest,
- Cafe_Free,
- Hotel_WiFi_5G.
When presented with several similar options, a user may select the wrong one and unknowingly connect to a network controlled by an attacker. This type of attack is commonly known as an “evil twin” attack.
CISA warns that an attacker can imitate a public access point and convince users to connect through the attacker’s equipment. It therefore recommends confirming the correct name and password of a public network before connecting.
Never guess the correct network name. At a hotel, restaurant or other public venue, verify it with a member of staff or consult an official notice provided by the network operator.
A Password Does Not Necessarily Mean That the Network Is Secure
Users often assume that a network is secure if a password is required to connect. A password may prevent uncontrolled access to the network, but it does not guarantee adequate protection on its own.
If every hotel guest or café customer receives the same password, the network is still shared by many unknown devices. We also do not know whether the network equipment has been configured correctly, is regularly updated or is adequately protected against misuse.
A login page that appears after connecting is not proof that the network is legitimate either. An attacker can create a similar page and ask users to enter their email address, password, telephone number or even payment card details.
If a login page requests more information than would reasonably be necessary to provide network access, it is safer to disconnect.
What Should We Avoid Doing on a Public Network?
When using a public network, avoid activities where the misuse of information could cause significant harm.
This applies particularly to:
- accessing online or mobile banking,
- entering payment card details,
- accessing company information systems without appropriate protection,
- opening confidential business documents,
- managing servers, firewalls or other critical systems,
- changing passwords,
- sending sensitive personal or business information,
- using electronic identities and digital certificates,
- remotely connecting to devices in the workplace.
If we need to perform a sensitive or urgent work-related task, using a mobile data connection or a personal hotspot on a mobile phone is generally a safer option.
How Can We Use Public Wi-Fi More Safely?
Verify the Exact Name of the Network
Before connecting, ask a member of staff which Wi-Fi network is the official one. Be particularly careful if several networks with almost identical names appear in the list.
A stronger signal does not necessarily mean that the access point is legitimate.
Use Mobile Data Whenever Possible
If a suitable mobile connection is available, it is generally a better choice than an unknown public network when accessing sensitive information.
If necessary, a mobile phone can be used as a personal hotspot. Protect the hotspot with a strong, unique password and switch it off when it is no longer required. Security recommendations for mobile hotspots also include the use of WPA2 or WPA3 encryption.
Use Your Company VPN
If your company provides a corporate VPN connection, enable it before accessing work email, documents or internal systems.
A VPN creates an encrypted connection between the device and the VPN server. This reduces the possibility of someone on the local network monitoring or modifying network traffic. The UK’s National Cyber Security Centre warns that connecting mobile devices to public or unsecured networks may allow attackers on the same network to intercept or alter data.
However, a VPN does not provide complete protection. It will not protect us from a fraudulent website, a malicious attachment, the disclosure of login credentials or the approval of a fraudulent multi-factor authentication request.
Check the Address of the Website You Are Visiting
Before entering a username, password or any other information, check:
- whether the web address begins with “https”,
- whether the domain name is spelled correctly,
- whether the address contains any unusual additions or spelling mistakes,
- whether the page was opened using a trusted bookmark or an official application.
If the browser displays a warning about an invalid or untrusted certificate, do not ignore the warning and do not proceed to the website.
Use Multi-Factor Authentication
Multi-factor authentication means that, in addition to a password, an additional form of identity verification is required to sign in. This may, for example, involve approving a request in a mobile application.
This reduces the risk of an account being misused if the password is compromised. Two-factor authentication should be enabled wherever it is available.
Do not automatically approve every sign-in request. If you did not initiate the request yourself, reject it and report the incident to your system administrator or IT support team.
Update Your Device and Applications
Before travelling, install all available security updates for:
- the operating system,
- the web browser,
- antivirus or other security software,
- the VPN client,
- office and communication applications.
Updates address known security vulnerabilities. It is advisable to keep security software, the operating system, the web browser and the mobile operating system up to date, and to enable automatic updates.
Disable Automatic Connections
A phone or laptop may automatically connect to a network that has the same name as one used in the past.
Automatic connections to public networks should therefore be disabled on the device. After using a public network, select the “Forget Network” option to prevent the device from connecting to it automatically in the future.
Disable Sharing
The following features should be disabled when using a public network:
- file and folder sharing,
- network device discovery,
- printer sharing,
- unnecessary remote access services.
In Windows, set the connection as a public network rather than a private network. This applies stricter security settings and restricts certain device discovery features.
What Should You Do If You Suspect That You Have Connected to a Fake Network?
If unusual pages begin to open after connecting, unexpected warnings appear or the network requests suspicious information, disconnect immediately.
Then:
- turn off Wi-Fi,
- remove or forget the suspicious network,
- switch to mobile data or another verified connection,
- notify IT support if you were using a company device or account,
- change any passwords that may have been compromised,
- review recent sign-ins to your accounts,
- revoke any unknown or active sessions,
- scan the device using security software.
If you suspect that a company account has been compromised, changing the password alone is not sufficient. The company should also review sign-in events, active sessions, any newly created email rules and other changes made to the user account.
Security incidents can also be reported to SI-CERT, Slovenia’s national Computer Emergency Response Team. SI-CERT handles incident reports, issues warnings about current threats, analyses malicious code and provides technical advice in cases involving intrusions, infections and other forms of network abuse.
A Short Checklist Before Connecting
Before connecting to a public Wi-Fi network, ask yourself the following questions:
- Have I verified the correct network name with the provider?
- Could I use mobile data instead of Wi-Fi?
- Is my device up to date?
- Is multi-factor authentication enabled?
- Is the VPN enabled when accessing company resources?
- Does the website use HTTPS and the correct domain name?
- Can I postpone the sensitive task until I have access to a more secure connection?
- Is sharing disabled on my device?
- Did I remove the public network from the list of saved connections after using it?
Caution Is More Important Than Convenience
Public Wi-Fi networks are convenient and are not always dangerous, but they should not be treated in the same way as a trusted home or business network.
For reading the news, viewing a map or checking a timetable, public Wi-Fi is usually an acceptable option. When accessing work documents, email, financial services or other sensitive information, however, it is better to use a mobile connection, a company VPN and a properly secured device.
Taking a few extra seconds to verify the network name, web address or connection method can prevent data loss, account compromise and a serious security incident.
Cybercriminals do not take holidays, so make sure that basic security precautions travel with you.
