
A personal secretary waiting at Chhatrapati Shivaji Maharaj Terminus in Mumbai connected his phone to the free station WiFi. He did nothing else unusual. Days later, a message that looked like an RTO traffic challan went out from his phone to his contacts, carrying an APK file. One of those contacts was Gobinda Biswas, 56, a General Manager at the Fort branch of Bank of Baroda. He installed it. On 21 July 2026, five unauthorised transactions worth Rs 4,27,264 cleared from his accounts in 28 minutes. He only found out on 3 August, when his credit card statement arrived. The FIR was registered at MRA Marg police station on 4 August.
That is what public WiFi safety India 2026 looks like in practice. Not a hacker in a hoodie draining your account the second you connect, but a quiet compromise at a station, a file that travels through your own contact list, and a loss that surfaces two weeks later at a completely different person.
India now runs one of the largest public WiFi footprints on earth. RailTel RailWire is live at more than 6,100 railway stations and is used by over 10 lakh unique users a day. Under the PM-WANI framework, 4,09,403 public data offices were operational as of 28 February 2026, used by roughly 2.45 crore people. Add every airport, mall, cafe and hotel and the attack surface is enormous. This guide covers the four ways that surface is actually exploited, what data is genuinely at risk, the seven rules that close the gap, and where a VPN helps and where it does not.
If you are connected to public WiFi right now
- 1Close every banking, UPI and payment app before you do anything else
- 2Switch to mobile data if you need to make a payment, then switch back
- 3Do not install any app, update or file that the network prompts you to install
- 4Do not enter an email password or an OTP on a WiFi login page, no genuine one asks
- 5Turn off auto connect and forget the network when you leave the building
- 6If money has already moved, call 1930 today and file at cybercrime.gov.in the same day
Why Public WiFi in India Is a Scammer Paradise
Three conditions have to line up for an attack surface to be worth an attacker time: lots of people, low suspicion and valuable traffic. Indian public WiFi has all three.
The volume is the first part. A single major railway station or airport terminal puts thousands of devices on one shared network every hour, and unlike a home network, none of them belong to each other. The second part is the low suspicion. Free WiFi feels like a service, not a risk. People connect while waiting for a delayed flight or a late train, precisely when they are bored, distracted and most likely to open banking, email and work accounts to kill time.
The third part is what makes India specific. This is a country where the phone is the bank. UPI, net banking, insurance, tax filing, government services and work email all sit on the same handset that just joined a network run by a stranger. In most other markets a compromised laptop session is an inconvenience. Here it sits one step away from a payment rail that moves money instantly and irreversibly.
The authorities have been explicit about it. On 16 August 2026, Maharashtra Cyber issued a public advisory warning that open public WiFi at airports, cafes and railway stations functions as a trap rather than a free service, and that criminals use these networks to intercept traffic, session cookies and login credentials. CERT-In, under its Jaagrookta Diwas awareness push, warned that attackers exploit weaknesses in WiFi protected access to steal passwords and credit card information from users of public WiFi at airports and railway stations, and advised against sensitive activity such as banking or shopping on these networks. In October 2025 the University Grants Commission issued its own alert telling students to avoid using public WiFi for personal or work accounts.
For context on the size of the problem these advisories sit inside, Indians lost an estimated Rs 22,495 crore to cyber fraud in 2025, a 24 percent rise on the previous year, according to Ministry of Home Affairs and Indian Cyber Crime Coordination Centre data. Public WiFi is not the largest single channel in that total. It is one of the quietest entry points into it.
The 4 Ways Hackers Exploit Public WiFi in India
Everything reported under the banner of WiFi hacking India 2026 reduces to four techniques. They are often chained together, and the first one is the reason the other three become possible.

Attack 1: Evil Twin, a Fake Hotspot With the Same Name
An evil twin WiFi attack India works because your phone identifies networks by name, not by owner. An attacker sets up a portable access point broadcasting Airport_Free_WiFi or the exact name of the cafe network, sits within range, and waits. Your phone shows one familiar entry and quietly picks whichever signal is stronger. If you have connected to that name before and auto connect is on, it joins without you touching anything.
From that moment, everything you do passes through hardware the attacker controls. The standard follow up is a captive portal that looks like the venue login page but asks for an email address and password, or an OTP, so the credentials get typed straight into the attacker system.
The clearest documented example of how far this scales comes from Australia, where an IT worker was investigated after an airline reported a suspicious network mimicking a legitimate access point on a domestic flight. Australian Federal Police searched his luggage at Perth Airport in April 2024 and seized a portable wireless access device, a laptop and a mobile phone. Investigators found data linked to fraudulent free WiFi pages used at the Perth, Melbourne and Adelaide airports as well as on domestic flights. He was later sentenced to seven years and four months, on charges that also covered other offences. The equipment involved fits in hand luggage and costs less than a mid range phone, which is precisely why Maharashtra Cyber puts verifying the exact network name with venue staff at the top of its advisory.
Attack 2: Man in the Middle, Intercepting Your Traffic
A man in the middle attack India is the position an attacker occupies once they control the path, whether through an evil twin, a compromised router or an unsecured network they simply joined alongside you. Every request from your device to a website, and every response back, passes through them first.
Modern HTTPS makes reading the contents of that traffic much harder than it used to be, which is why the padlock in the address bar genuinely matters. But an attacker in the middle can still see which sites and services you connect to, attempt to downgrade or block a secure connection so you retry insecurely, present a fake certificate and hope you click through the warning, and redirect you to a lookalike page for a service you actually use.
The most serious documented version of this in 2026 did not need a fake hotspot at all. Security firm ReliaQuest reported a campaign, active since at least June 2026, in which attackers compromised the WiFi gateway appliances of hotels and conference centres and poisoned DNS on those gateways. Compromised gateways were identified across several United States cities and internationally in India and Saudi Arabia. Guests joined the correct, legitimate hotel network, and were then quietly redirected to credential harvesting pages targeting corporate Microsoft 365 accounts. In some cases attackers did not steal passwords at all but abused a legitimate Microsoft device code authentication flow to obtain valid tokens, bypassing multi factor authentication entirely. Traffic came from finance, legal, healthcare, energy, retail and professional services organisations, which points at travelling employees rather than any one sector.
The lesson is uncomfortable and worth stating plainly: joining the right network is not the same as joining a safe one.
Attack 3: Packet Sniffing, Reading Unencrypted Data
Packet sniffing is the passive version. On an open network with no password, radio traffic between devices and the access point can be captured by anyone within range running freely available software, no compromise of any equipment required. On a network with a single shared password, which is what almost every hotel and cafe uses, the isolation between guests is far weaker than most people assume.
What a sniffer actually gets in 2026 is narrower than the classic warnings suggest, because most major sites and apps now encrypt in transit. What still leaks is meaningful though: the domains you visit, app telemetry sent over plain connections, content from any site still served without HTTPS, data from misconfigured or older applications, and session cookies from anything that transmits them insecurely. A stolen session cookie is the valuable one, because it can let an attacker resume your logged in session without ever knowing your password, which is exactly why logging out properly matters more than closing a tab.
Attack 4: Malware Distribution Through a Compromised Network
This is the one that hurts Indians most, and it is the mechanism behind the Mumbai CSMT case. Rather than reading your traffic, the network is used to put something on your device: a fake system update prompt, an injected download, a redirect to a page pushing an APK file.
The CSMT chain is worth following step by step, because it shows how the loss lands on someone who never touched the WiFi. The secretary connected his phone to the free CSMT network on 18 July 2026 and his device was compromised. A malicious APK, dressed as an official RTO challan, was then automatically forwarded from his phone through messaging apps to more than 200 saved contacts. Gobinda Biswas received it from a trusted colleague, believed it was a genuine traffic challan, and installed it. Five unauthorised transactions worth Rs 4,27,264 followed on 21 July within a 28 minute window. The FIR came on 4 August. Maharashtra Cyber issued its public WiFi advisory less than two weeks later.
Two things make this pattern effective. The APK arrives from a real contact, so it clears the trust check that any stranger message would fail. And the payload is a familiar Indian pretext, a traffic challan, that thousands of people receive legitimately every week. Our mobile app safety guide covers what an APK from outside the Play Store can actually do once installed, and our SMS scam guide covers the challan and delivery pretexts in detail.
What Data Is Actually at Risk on Public WiFi in India
It helps to separate what is realistically exposed from what makes for a scary headline, because the honest version is easier to act on.
- Login credentials typed into a fake page. The highest risk item, and it does not depend on breaking any encryption. If a hotspot serves you a convincing login page and you type into it, they have it. This is why a WiFi portal asking for an email password or an OTP is always fraudulent.
- Active session tokens. Cookies that keep you logged in can be captured or replayed, letting an attacker into an account without the password and, in some flows, without a second factor.
- Anything sent over a connection that is not properly encrypted. Older apps, internal tools, some IoT and utility apps, and any site without HTTPS.
- Your browsing and app usage pattern. Even with HTTPS, the operator of the network sees which services you contact and when. That is enough to build a targeted phishing message aimed at exactly the bank you use.
- Your device itself. The CSMT chain shows the real endgame. Once malware is on the phone, encryption on the network stops mattering, because the attacker is reading the screen rather than the wire.
- Your contact list, as a distribution channel. A compromised phone becomes the delivery mechanism for the next 200 victims, which is how one connection at a station turned into a loss at a bank General Manager account.
What is genuinely hard to steal off the network alone is a UPI PIN, because it is entered inside a protected flow on your device rather than transmitted as plain text. That is worth knowing, but it is not reassurance. Every case above reaches the money by a different route. Our bank account fraud guide covers what happens after credentials or a device are compromised.
How to Stay Safe on Public WiFi in India
Here is the practical answer to how to use public WiFi safely India, in the order that matters most.
How to stay safe on public WiFi in India:
- 1Never access banking apps or UPI on public WiFi, use mobile data instead
- 2Verify the exact WiFi network name with staff before connecting, this is the evil twin defence
- 3Use HTTPS websites only, check for the padlock in the browser address bar
- 4Enable your phone mobile hotspot and share it to your laptop rather than using public WiFi
- 5Use a VPN to encrypt your traffic on any public network
- 6Turn off automatic WiFi connection in your phone settings
- 7Log out of all accounts when done on public WiFi, do not just close the browser
Banking on mobile data is always safer than public WiFi.

Four of those seven deserve a line of explanation, because they are the ones people skip.
Rule 1 is the whole guide compressed. Mobile data does not touch the venue network at all, so the state of that network stops being your problem. In India this costs a few rupees of data. A recharge is cheaper than an FIR.
Rule 4 is the underrated one. Tethering your laptop to your own phone hotspot gives you every practical benefit of public WiFi with none of the shared network exposure. For anyone working from airports and hotels regularly, this should be the default rather than the fallback.
Rule 6 closes the door you left open last time. Auto connect means your phone rejoins any network whose name it has saved, including a spoofed one broadcasting that same name in a completely different city. Turn it off, and periodically forget saved public networks. Maharashtra Cyber lists this as one of its four core recommendations.
Rule 7 defeats the session token attack. Closing a browser tab leaves the session alive. Logging out invalidates it, so a captured cookie becomes worthless. Our password safety guide and cyber hygiene guide cover the account level habits that back this up.
One addition the brief does not include but the 2026 cases demand: never install anything while you are on a public network. No update prompt, no APK, no certificate, no profile. If a genuine update is waiting, it will still be waiting on your home WiFi tonight.
Should You Use a VPN in India?
Yes, with a clear understanding of what it does. On VPN India WiFi safety, the honest position is that a VPN is an excellent second layer and a poor first one.

A VPN builds an encrypted tunnel between your device and a server run by the VPN provider. Everything inside that tunnel is unreadable to anyone on the local network, including the operator of an evil twin hotspot. They can see that you are connected to a VPN and how much data is moving. They cannot see which sites you visit or what you send. This is exactly the gap CERT-In was pointing at when it recommended a secure VPN for public network use.
What a VPN does not do is equally important. It does not stop you from typing your password into a fake login page. It does not remove malware already on your device, and it does not prevent you installing an APK. It does not protect you if the compromise is at the venue gateway and you accept a redirect anyway. In the Mumbai CSMT chain, a VPN on the secretary phone would very likely not have changed the outcome, because the damage came from an installed file, not intercepted traffic.
On choosing one, three points matter for Indian users. Reputable free tier: ProtonVPN offers a free plan with no data cap on its basic tier, which is enough for occasional travel use. Paid options with better speeds include NordVPN and ExpressVPN. And the warning that matters most: avoid unknown free VPN apps found through app store searches or social media ads. A VPN provider sees all of your traffic by design, so an untrustworthy one is not a weaker version of a good one, it is the attacker you were trying to avoid, with your permission. Check any VPN download link and its website on our website safety checker before you install it.
Using a VPN in India for privacy and security on public networks is legal. This guide is general safety information, not legal advice.
30 Second Instagram Reel Script
Format: open on the airport hero frame, cut through the four attack tiles and the seven rules card, close on the mobile data rule. Shoot vertical 9:16, burn in Hindi and English captions.
On-screen caption: Free WiFi is not free. Use mobile data for banking and UPI, verify the network name with staff, and never install anything on a public network. Report fraud on 1930 and cybercrime.gov.in.
Frequently Asked Questions
Is it safe to use banking apps on airport WiFi in India?
No. Never access banking, UPI or any financial account on public WiFi, airports included. Use your mobile data connection on 4G or 5G instead. If you have no mobile data left, wait until you do before opening any financial app. This single rule prevents the large majority of public WiFi financial fraud, because it removes the attacker from the path entirely. Mobile data traffic never passes through the venue network, so it does not matter whether that network is genuine, compromised or a fake hotspot with the right name.
What is an evil twin attack on WiFi in India?
An evil twin attack creates a fake WiFi hotspot broadcasting the same name as a legitimate one, for example Airport_Free_WiFi standing next to the real airport network. Your phone shows two identical entries, or often just one, because it silently picks whichever signal is stronger. Once you connect, every request you make routes through the attacker device before it reaches the internet. They can serve fake login pages, capture what you type into them and push malicious downloads. Always confirm the exact network name and any password with venue staff, and treat a network that asks for an email password or an OTP on its login page as fraudulent, because no genuine captive portal needs either.
Should I use a VPN in India for public WiFi?
Yes, if you must use public WiFi at all. A VPN encrypts all traffic between your device and the VPN server, so anyone intercepting on the same network sees only unreadable data rather than which sites you visit or what you send. CERT-In specifically recommends a secure VPN when accessing public networks. ProtonVPN offers a free tier with no data cap on its basic plan. Paid services such as NordVPN and ExpressVPN give better speeds. Avoid unknown free VPN apps found through app store searches or ads, because a VPN sees all of your traffic by design, and several free VPN apps have been caught monetising exactly that. A VPN is a good second layer. It is not a substitute for using mobile data for banking.
Is hotel WiFi safe for banking in India?
No. Hotel WiFi is public WiFi even when it is password protected, because every guest shares the same password and the same network. There is a second and less obvious risk. In 2026 the security firm ReliaQuest documented a campaign in which attackers compromised the WiFi gateway appliances of hotels and conference centres, including in India, and poisoned DNS so that guests connecting to the genuine hotel network were redirected to credential harvesting pages. The guests did nothing wrong and joined the correct network. Use mobile data for banking even in hotels, and use a VPN or your employer secure connection for work.
Can a scammer steal my UPI PIN on public WiFi in India?
Reading a UPI PIN directly off the network is hard, because UPI apps use encrypted connections and the PIN is handled inside a secure element on your phone. The realistic public WiFi risks are indirect and they are worse than they sound: malware or a malicious APK delivered through the network, session hijacking that steals an already logged in session for a less protected app, credential capture through a fake login page served by the hotspot, and data read from any connection that is not properly encrypted. The Mumbai CSMT case in July 2026 followed exactly this indirect path, a compromised phone, a forwarded APK, then five transactions totalling Rs 4,27,264 in 28 minutes. The safe rule stays the same: use mobile data for anything financial.
How do I report a fraud that started on public WiFi in India?
Call 1930, the national cybercrime helpline, immediately if money has moved, then file at cybercrime.gov.in the same day, because the freeze window on the receiving account is measured in hours. Tell the operator where and when you used the public network, since that helps establish the entry point. In Maharashtra you can also complain through mhcyber.gov.in. If a malicious APK or app was installed, put the phone in airplane mode, uninstall it, change the passwords for banking and email from a different clean device, and inform your bank so the account can be watched. Report the venue as well, because a compromised or spoofed hotspot at an airport, station or hotel keeps working on the next traveller until someone flags it.
Sources and Credits
- Free Press Journal, Bank of Baroda GM Loses Rs 4.27 Lakh After Fake RTO Challan APK Attack Linked to CSMT Free Wi-Fi: the identity and age of the complainant, the CSMT free WiFi entry point on 18 July 2026, the five transactions totalling Rs 4,27,264 on 21 July, the discovery on 3 August and the FIR at MRA Marg police station on 4 August 2026.
- Ten News, Mumbai CSMT Cyber Scam, Free Wi-Fi Suspected in Malware Attack as Bank Official Loses Rs 4.27 Lakh: the automatic forwarding of the malicious APK from the compromised phone to more than 200 saved contacts through messaging applications.
- Free Press Journal, Free Wi-Fi Costly Trap, Maharashtra Cyber Warns of Hacking and Financial Fraud: the Maharashtra Cyber advisory of 16 August 2026, the interception of traffic, session cookies and login credentials on open public networks, and the four recommendations to verify the network name with venue staff, avoid banking and shopping, use mobile data or a VPN, and disable auto connect.
- Telangana Today, Government Warns Against Using Public Wi-Fi for Sensitive Transactions, CERT-In Issues Digital Safety Advisory: the CERT-In Jaagrookta Diwas advisory, the warning that attackers exploit vulnerabilities in WiFi protected access to steal passwords and credit card information at airports and railway stations, and the recommendation to use a secure VPN and avoid browser autofill.
- India TV, Free WiFi Fraud, Government Issues Alert on Digital Scams: the University Grants Commission alert of October 2025 advising students not to use public WiFi for personal or work accounts, and the recommendation to avoid payment apps on public networks and to use a VPN.
- ReliaQuest Threat Spotlight, DNS Poisoning Tactics Expand to Hospitality Wi-Fi: the campaign active since at least June 2026 compromising hotel and conference centre captive portal gateways, the compromised gateways identified in the United States, India and Saudi Arabia, the DNS poisoning of guests on the legitimate network, the Microsoft 365 credential harvesting, the device code flow abuse that bypasses multi factor authentication, and the affected industry mix.
- CSO Online, Hackers Are Compromising Hotel Wi-Fi Gateways to Hijack Microsoft 365 Accounts: independent reporting on the same hospitality gateway campaign and its targeting of travelling corporate employees.
- Australian Federal Police, WA Man Jailed for Stealing Intimate Material and Using Evil Twin WiFi Networks: the airline report of a suspicious network mimicking a legitimate access point, the Perth Airport search in April 2024, the portable wireless access device seized, the fraudulent free WiFi pages linked to Perth, Melbourne and Adelaide airports and domestic flights, and the sentence handed down.
- BleepingComputer, Australian Charged for Evil Twin WiFi Attack on Plane: the technical description of how the evil twin captive portal harvested email and social media credentials.
- RailTel, Station Wi-Fi Project: RailWire live at more than 6,100 railway stations and described as one of the largest integrated public WiFi networks in the world, accessed by more than 10 lakh unique users daily.
- IMPRI, PM-WANI Framework, Assessing Public Wi-Fi Expansion in India: 4,09,403 public data offices operational as of 28 February 2026 and roughly 2.45 crore users of PM-WANI hotspots.
- DQ India, AI Scams India 2025: the Rs 22,495 crore lost by Indians to cyber fraud in 2025 and the 24 percent year on year rise, drawn from Ministry of Home Affairs and I4C data.
- TechRadar, TSA Warning on Fake USB Charging Ports and Free Wi-Fi Honeypots: the parallel airport threat of tampered USB charging ports, and the advice to carry a power bank and use a standard power outlet instead.
- ProtonVPN: the free tier referenced in the VPN section, with no data cap on its basic plan.
- National Cybercrime Reporting Portal: the official complaint route, and India national cybercrime helpline, 1930.
- CERT-In: the national computer emergency response team, which publishes the digital safety advisories referenced above.
- Maharashtra Cyber: the state cybercrime reporting portal named in the August 2026 advisory.
Free WiFi is not free. Mobile data is cheaper than an FIR.
Every case in this guide started with a connection that felt completely ordinary. Check a suspicious link, app download page or website on RakshaAI before you open it, install it, or trust it.
Check for freeMore from RakshaAI Blog
Stay Protected Online
Use RakshaAI to check websites, phone numbers, and UPI IDs for scams free, instant, no sign-up required.
RakshaAI is a private platform by Ehatech Services Pvt. Ltd. Not affiliated with any government body. Editorial policy


