Is public Wi-Fi safe?
Public Wi-Fi is generally not safe because open networks can be unsecured, and the data you send and receive can potentially be intercepted and misused by bad actors connected to the same network.
Even when a network uses a password and offers WPA2 or WPA3 encryption, it can still pose security risks. Every person connected to the network shares the same network space, which makes it much easier for attackers to look for weak points.
Most websites today serve their pages over the HTTPS protocol, which encrypts the traffic between your browser and the website you’re visiting so others can’t read it. But not even the HTTPS protocol fully secures and locks down the network. And on unsafe connections, cyberattackers can still use snooping tools or man-in-the-middle attacks to access your unencrypted information.
Risks of using public Wi-Fi
Public Wi-Fi networks may be unsecured or poorly configured, which can create opportunities for attackers to intercept your traffic. There’s also the risk of connecting to a fake hotspot set up to impersonate a legitimate network. When you use public Wi-Fi, you are at risk of:
- Data interception. On unsecured networks, attackers can capture the information you send, from search terms to login details if the connection is not encrypted. One of the more common forms of data interception is the man-in-the-middle attack, during which a hacker positions themselves between your device and the website or service you are trying to reach. This allows them to monitor or alter the data you send in real time.
- Malicious hotspots (evil twin). Cybercriminals may create fake networks that look legitimate, such as “Airport_WiFi” or “CoffeeShop_Free.” Known as an evil twin attack, this setup works much like a rogue access point and tricks users into joining a malicious hotspot that can expose personal information or install malware on the device.
- Malware distribution. If your device lacks updates or has file sharing enabled, hackers can use public networks to deliver malicious software to your device. Because malicious scripts can be run in the background, such attacks usually take place without obvious signs of infection.
- Session hijacking. During a session hijacking attack, criminals try to capture your session cookies to take over your active accounts. Once inside, they can access emails, social media, or other services without needing your password.
Risk level by activity
Some activity is riskier on public Wi-Fi than others because of what attackers could expose if the connection isn’t secure. The table below breaks down common activities and where the risks come from.
| Activity | What’s at risk | Risk level | How to stay protected |
|---|---|---|---|
Reading news / browsing | No personal information is exchanged, so there’s little for an attacker to intercept | Low 🟩 | No special precautions needed |
Checking social media | Login sessions and personal details, if the connection isn’t encrypted | Medium 🟨 | Use a VPN and avoid logging in on unfamiliar networks |
Online shopping | Payment details, especially if a checkout page is spoofed or you’re redirected to a fake site | High 🟧 | Use a VPN, confirm the site is HTTPS, and check the URL before entering payment info |
Mobile banking | Account credentials and financial data, both prime targets for phishing and session hijacking | Very high 🟥 | Avoid where possible. If unavoidable, use a VPN and enable 2FA |
Signs of an unsafe Wi-Fi network
Not all public hotspots are trustworthy. Watch out for these warning signs:
No password required. Open networks allow anyone to connect, making it easier for attackers to monitor traffic or set traps.
Generic or suspicious names. Networks with vague names like “FREE_WIFI” or ones that imitate official networks may be designed to lure users.
Duplicate networks. Two versions of the same Wi-Fi name could indicate a fake hotspot set up to intercept data.
Unusual login pages. Redirects requesting personal details, unnecessary permissions, or payment information are a strong warning.
Security warnings. Browser alerts about invalid or insecure certificates suggest the connection may have been tampered with.
Unexpected pop-ups or ads. Immediate prompts to install software or click on pop-ups can indicate a compromised network.
If aspects of the hotspot connection seem off, disconnect immediately and avoid entering personal information or passwords.
How to safely use public Wi-Fi
You can’t control how a public network is secured, but you can control your device settings, how you browse, and what security tools you have running. That puts the responsibility for security on your side of the connection, and the steps below cover what you can do to protect it and use public Wi-Fi more securely.
- 1.Use a VPN for public Wi-Fi. A VPN (which stands for virtual private network) creates a secure, encrypted tunnel for your online traffic, rendering it unreadable to hackers even if they intercept your connection. It’s one reason to use a VPN on public Wi-Fi as an added precaution.
- 2.Verify the network name before connecting. Confirm the exact network name with staff in public spaces such as cafés, hotels, or airports. Even then, a malicious hotspot can mimic the name, so treat every public network with caution.
- 3.Stick to HTTPS websites only. Seeing HTTPS in the address bar is a good sign — this protocol protects the traffic between your browser and the website. So stick to sites that serve their pages over HTTPS. But also remember that the HTTPS protocol isn’t a green light to trust the website blindly. Lookalike sites can use HTTPS too, which makes checking the actual web address just as important before you hit “enter.”
- 4.Avoid sensitive tasks. Skip online banking, shopping, or accessing work accounts while on public Wi-Fi. These actions expose high-value information that attackers often target on unsecured networks.
- 5.Turn off auto-connect and file sharing. Auto-connect can link your device to unknown networks without notice. File sharing should remain off in public spaces because it can create openings attackers can exploit.
- 6.Enable your firewall. A firewall acts as an extra barrier between your device and potential threats on the network, reducing the risk of unauthorized access.
- 7.Use two-factor authentication. Two-factor authentication (2FA) protects your accounts even if someone intercepts your password. A one-time code or authentication app adds a strong layer of defense.
- 8.Forget the network when you’re done. After disconnecting, remove the network from your saved Wi-Fi list to prevent your device from reconnecting automatically in the future.
Public Wi-Fi vs. mobile hotspot safety
Mobile hotspots generally have the security edge over public Wi-Fi because cellular connections use built-in network encryption. That makes them the safer of the two, though not completely risk free.
| | Public Wi-Fi | Mobile hotspot |
|---|---|---|
Who can connect | Anyone nearby can join the network. | Only devices you approve can connect. |
Encryption | Encryption is often weak or absent, and any protection that exists usually relies on a widely shared password. | Connections use the cellular network’s built-in encryption. |
Common risks | Data interception, evil twin hotspots, and man-in-the-middle attacks. | A weak hotspot password or unauthorized devices connecting. |
Best for | Low-risk browsing, ideally with a VPN active. | Banking, shopping, and other sensitive tasks — also with a VPN active. |
Online security starts with a click.
Stay safe with the world’s leading VPN