Is public Wi-Fi safe? Risks of free Wi-Fi and how to use it safely

Most of us have connected to public Wi-Fi at some point, and most of us probably didn’t stop to ask, “Is public Wi-Fi safe?” before joining the network. But for all their convenience, these networks — especially the free ones — are actually likely to harbor security vulnerabilities that could expose your personal data to cybercriminals. It’s why knowing the risks and knowing how to safely use public Wi-Fi are two things you don’t want to be in the dark on.

August 14, 2026

7 min read

Is public Wi-Fi safe? Risks of free Wi-Fi and how to use it safely

Is public Wi-Fi safe?

Public Wi-Fi is generally not safe because open networks can be unsecured, and the data you send and receive can potentially be intercepted and misused by bad actors connected to the same network.

Even when a network uses a password and offers WPA2 or WPA3 encryption, it can still pose security risks. Every person connected to the network shares the same network space, which makes it much easier for attackers to look for weak points.

Most websites today serve their pages over the HTTPS protocol, which encrypts the traffic between your browser and the website you’re visiting so others can’t read it. But not even the HTTPS protocol fully secures and locks down the network. And on unsafe connections, cyberattackers can still use snooping tools or man-in-the-middle attacks to access your unencrypted information.

Risks of using public Wi-Fi

Public Wi-Fi networks may be unsecured or poorly configured, which can create opportunities for attackers to intercept your traffic. There’s also the risk of connecting to a fake hotspot set up to impersonate a legitimate network. When you use public Wi-Fi, you are at risk of:

  • Data interception. On unsecured networks, attackers can capture the information you send, from search terms to login details if the connection is not encrypted. One of the more common forms of data interception is the man-in-the-middle attack, during which a hacker positions themselves between your device and the website or service you are trying to reach. This allows them to monitor or alter the data you send in real time.
  • Malicious hotspots (evil twin). Cybercriminals may create fake networks that look legitimate, such as “Airport_WiFi” or “CoffeeShop_Free.” Known as an evil twin attack, this setup works much like a rogue access point and tricks users into joining a malicious hotspot that can expose personal information or install malware on the device.
  • Malware distribution. If your device lacks updates or has file sharing enabled, hackers can use public networks to deliver malicious software to your device. Because malicious scripts can be run in the background, such attacks usually take place without obvious signs of infection.
  • Session hijacking. During a session hijacking attack, criminals try to capture your session cookies to take over your active accounts. Once inside, they can access emails, social media, or other services without needing your password.

Risk level by activity

Some activity is riskier on public Wi-Fi than others because of what attackers could expose if the connection isn’t secure. The table below breaks down common activities and where the risks come from. 

Activity

What’s at risk

Risk level

How to stay protected

Reading news / browsing

No personal information is exchanged, so there’s little for an attacker to intercept

Low 🟩

No special precautions needed

Checking social media

Login sessions and personal details, if the connection isn’t encrypted

Medium 🟨

Use a VPN and avoid logging in on unfamiliar networks

Online shopping

Payment details, especially if a checkout page is spoofed or you’re redirected to a fake site

High 🟧

Use a VPN, confirm the site is HTTPS, and check the URL before entering payment info

Mobile banking

Account credentials and financial data, both prime targets for phishing and session hijacking

Very high 🟥

Avoid where possible. If unavoidable, use a VPN and enable 2FA

Signs of an unsafe Wi-Fi network

Not all public hotspots are trustworthy. Watch out for these warning signs:

  • No password required. Open networks allow anyone to connect, making it easier for attackers to monitor traffic or set traps.

  • Generic or suspicious names. Networks with vague names like “FREE_WIFI” or ones that imitate official networks may be designed to lure users.

  • Duplicate networks. Two versions of the same Wi-Fi name could indicate a fake hotspot set up to intercept data.

  • Unusual login pages. Redirects requesting personal details, unnecessary permissions, or payment information are a strong warning.

  • Security warnings. Browser alerts about invalid or insecure certificates suggest the connection may have been tampered with.

  • Unexpected pop-ups or ads. Immediate prompts to install software or click on pop-ups can indicate a compromised network.

If aspects of the hotspot connection seem off, disconnect immediately and avoid entering personal information or passwords.

How to safely use public Wi-Fi

You can’t control how a public network is secured, but you can control your device settings, how you browse, and what security tools you have running. That puts the responsibility for security on your side of the connection, and the steps below cover what you can do to protect it and use public Wi-Fi more securely.

  1. 1.Use a VPN for public Wi-Fi. A VPN (which stands for virtual private network) creates a secure, encrypted tunnel for your online traffic, rendering it unreadable to hackers even if they intercept your connection. It’s one reason to use a VPN on public Wi-Fi as an added precaution.
  2. 2.Verify the network name before connecting. Confirm the exact network name with staff in public spaces such as cafés, hotels, or airports. Even then, a malicious hotspot can mimic the name, so treat every public network with caution.
  3. 3.Stick to HTTPS websites only. Seeing HTTPS in the address bar is a good sign — this protocol protects the traffic between your browser and the website. So stick to sites that serve their pages over HTTPS. But also remember that the HTTPS protocol isn’t a green light to trust the website blindly. Lookalike sites can use HTTPS too, which makes checking the actual web address just as important before you hit “enter.”
  4. 4.Avoid sensitive tasks. Skip online banking, shopping, or accessing work accounts while on public Wi-Fi. These actions expose high-value information that attackers often target on unsecured networks.
  5. 5.Turn off auto-connect and file sharing. Auto-connect can link your device to unknown networks without notice. File sharing should remain off in public spaces because it can create openings attackers can exploit.
  6. 6.Enable your firewall. A firewall acts as an extra barrier between your device and potential threats on the network, reducing the risk of unauthorized access.
  7. 7.Use two-factor authentication. Two-factor authentication (2FA) protects your accounts even if someone intercepts your password. A one-time code or authentication app adds a strong layer of defense.
  8. 8.Forget the network when you’re done. After disconnecting, remove the network from your saved Wi-Fi list to prevent your device from reconnecting automatically in the future.

Public Wi-Fi vs. mobile hotspot safety

Mobile hotspots generally have the security edge over public Wi-Fi because cellular connections use built-in network encryption. That makes them the safer of the two, though not completely risk free.

Public Wi-Fi

Mobile hotspot

Who can connect

Anyone nearby can join the network.

Only devices you approve can connect.

Encryption

Encryption is often weak or absent, and any protection that exists usually relies on a widely shared password.

Connections use the cellular network’s built-in encryption.

Common risks

Data interception, evil twin hotspots, and man-in-the-middle attacks.

A weak hotspot password or unauthorized devices connecting.

Best for

Low-risk browsing, ideally with a VPN active.

Banking, shopping, and other sensitive tasks — also with a VPN active.

Online security starts with a click.

Stay safe with the world’s leading VPN

FAQ

Copywriter Dominykas Krimisieras

Dominykas Krimisieras

Dominykas Krimisieras writes for NordVPN about the parts of online life most people ignore. In his work, he wants to make cybersecurity simple enough to understand — and practical enough to act on.