
Key Takeaways
Public Wi-Fi Risk
Public Wi-Fi refers to wireless internet connections available in shared spaces like cafés, airports, hotels, and libraries. Because these networks are open to anyone nearby, they lack the security controls of a private home or office network. This makes it easier for bad actors on the same network to intercept unprotected data or trick users into connecting to fraudulent hotspots.
Most modern websites use HTTPS encryption, which protects the content of your traffic — but metadata, device identifiers, and connections to unencrypted services can still be exposed on an open network.
What Actually Happens When You Connect
When you join a public Wi-Fi network, your device begins broadcasting data across a shared radio channel — the same channel used by every other person in that café or airport terminal. Unlike your home router, which you control and can secure with a strong password, a public hotspot is open by design. Anyone within range can see network traffic that isn't protected by encryption.
The most straightforward risk is passive eavesdropping: using freely available software, someone on the same network can capture packets of data flowing across it. If a site or app you're using doesn't encrypt its traffic, the contents of that communication can be readable in plain text — login credentials, form submissions, messages.
Even with HTTPS protecting most modern websites, other information leaks through. Your device's name, the list of sites you're requesting, and app traffic from less-secure services can all be visible to a determined observer on the same network.
HTTPS Protects Content, Not Everything
Most major websites now use HTTPS by default, which is a genuine improvement in public network security. However, HTTPS only encrypts the content of the page — it doesn't hide which sites you visit, and many apps use additional channels that may not enforce encryption. Assuming HTTPS makes a public network fully safe is one of the more common privacy misconceptions.
The Fake Hotspot Trap
Beyond passive eavesdropping, a more deliberate attack involves creating a fraudulent network designed to impersonate a real one. This is sometimes called an evil twin attack. An attacker sets up a hotspot named something like "Airport_Free_WiFi" or "CoffeeShop_Guest" — names plausible enough that travelers connect without questioning them.
Once you're connected to the attacker's network rather than the legitimate one, all your traffic passes through their device first. This is the basis of a man-in-the-middle attack — where a third party sits invisibly between you and the websites you're visiting. They can monitor what you're doing, and in some cases manipulate what you see.
Your device's automatic Wi-Fi connection behavior can make this worse. If your phone is set to connect automatically to networks it recognizes by name, it might join a spoofed network without any prompt from you.
Verify the Network Name Before Connecting
Before joining a Wi-Fi network in a public place, ask a staff member for the exact network name and look for it on a posted sign. Attackers deliberately use names that look legitimate. Spending five seconds confirming the correct SSID (the network's name) can prevent you from connecting to a spoofed hotspot. If in doubt, use your mobile data instead.
What Attackers Can — and Can't — See
It helps to understand precisely where your exposure lies. HTTPS — the encrypted standard used by most reputable websites — protects the actual content you exchange with a site. An attacker can see that you visited a banking website, but cannot read your password or account details if the connection is properly encrypted end-to-end.
What remains more exposed on a public network includes:
- Which domains you're visiting — even over HTTPS, DNS lookups (the system that translates website names into addresses) are often unencrypted
- Unencrypted app traffic — some apps, particularly older ones, still transmit data without HTTPS
- Your device's network identity — MAC addresses and device names can be visible to others on the network
For everyday browsing of news or maps, this exposure is relatively low-stakes. For anything involving passwords, financial accounts, or personal health data, the calculus changes. See our article on common online privacy myths to understand where people often overestimate their protection.
25%
Of public hotspots use no encryption at all
According to Kaspersky's analysis of global Wi-Fi hotspots, roughly one in four public access points operates without any encryption protocol.
40%
Of users access financial accounts on public Wi-Fi
Survey data from cybersecurity researchers has consistently found a large share of public Wi-Fi users performing sensitive tasks they'd be better off reserving for secure connections.
Practical Steps That Meaningfully Reduce Your Risk
You don't need to avoid public Wi-Fi entirely — but a few habits shift the risk considerably in your favor.
- Use a reputable VPN. A VPN (Virtual Private Network) encrypts all traffic between your device and its servers, making eavesdropping on a public network much harder. Our guide to what VPNs protect and don't explains the real-world limits of this tool.
- Switch to mobile data for sensitive tasks. Cellular connections are encrypted at the network level and are harder to spoof or intercept. For banking or medical portals, consider turning off Wi-Fi temporarily. Learn more about when each connection type makes sense in our breakdown of mobile data vs Wi-Fi.
- Disable auto-connect for public networks. Turn off the setting that lets your phone join known open networks automatically. This prevents silent connections to spoofed hotspots.
- Look for HTTPS. Before entering any credentials on a website, confirm the address bar shows a padlock icon and begins with
https://. Avoid submitting sensitive information on pages that don't use it. - Log out of accounts when done. Active sessions can sometimes be hijacked. Logging out after use on a shared network limits that window of exposure.
Strong, unique passwords for each account also reduce the impact if any credential is intercepted — a topic covered in detail in our piece on password habits that leave accounts vulnerable.
