A fake Wi-Fi hotspot imitates a legitimate network so that people connect through equipment controlled by an attacker. You cannot confirm a hotspot from its name or signal strength alone. Ask the venue for the exact network name and sign-in procedure, then stop if the portal or device shows unexpected certificate, credential, payment, or installation requests.

How a fake hotspot works

An attacker can broadcast a name that resembles an airport, hotel, cafĂ©, event, or public service. The name may differ by one character or add words such as “guest,” “free,” or “5G.” It may also copy the real name exactly.

Once a device connects, the hotspot can present a fake sign-in page, redirect unencrypted traffic, collect network metadata, or encourage the user to install software or trust a certificate. Proper HTTPS still protects content when certificate validation succeeds, so attackers often rely on phishing rather than silently reading every connection.

Signs that a hotspot may be fake

  • Staff cannot confirm the network name or login process.
  • Several similar names appear and no official instructions distinguish them.
  • The network opens a portal that imitates email, social media, or a bank login.
  • The portal asks for a one-time code, Social Security number, or full payment-account credentials.
  • The device displays a certificate or privacy warning.
  • Joining requires an unexpected app, configuration profile, root certificate, or remote-access tool.
  • The portal demands an unusual payment method or creates urgent threats.

A password does not prove legitimacy. An attacker can advertise a password beside a fake network or reuse a venue’s public password.

How to verify a network

Ask an employee, event organizer, or official help desk for the exact spelling and whether a password or portal is expected. Use venue signage only when you can tell it belongs to the venue and has not been covered by another sticker.

If the venue has an official app or website, check its access instructions through cellular data. Do not use a search advertisement or information supplied by the suspicious portal as the only confirmation.

Technical details can support that verification but cannot replace it. The security type, access-point identifier, and manufacturer information may help venue staff distinguish equipment. A criminal can still copy a network name, choose the same security mode, or use ordinary networking hardware. Treat a match as supporting evidence, not proof of ownership.

Pay attention to the full login flow. A venue that advertises access with a room number and last name should not suddenly require the password to your email account. A portal that reappears after successful login, redirects to unrelated domains, or changes its request as you decline information deserves another check with staff.

What to do when two networks have the same name

Do not choose based on signal strength. Ask staff which network and login flow to use. If the device has already connected automatically, disconnect, forget both saved entries, and reconnect only after verification.

Organizations that manage enterprise Wi-Fi may use certificates or profiles. Install them only from an authenticated organizational channel and follow the administrator’s documentation.

What to do if you connected to a fake hotspot

Disconnect and forget the network. Remove profiles, certificates, apps, or VPN settings added during the session. Update the device and run a trusted security scan if anything was installed.

Change credentials entered into the portal or any page that displayed a certificate warning. Revoke other sessions and turn on two-factor authentication. Contact financial institutions for payment or banking information and monitor relevant accounts.

Record the network name, location, time, portal address, and screenshots. Notify the venue so staff can investigate the unauthorized signal or signage.

Match recovery to what happened during the connection. If you only opened encrypted public pages and saw no warning, forgetting the network may be enough. If you entered a password, revoke sessions and change that credential. Software installation, certificate approval, remote access, or financial activity requires a device and account review. Avoid resetting every account when the evidence points to a narrower exposure.

Can WiFi Checker identify every fake network?

No. WiFi Checker can provide technical information and alerts about the connection within its scope. Two hotspots can present similar technical details, and software may not know which access point the venue intended to operate.

Use the feature as evidence alongside confirmation from the venue, browser certificate status, and the requests made by the portal.

PSafe’s analysis of fake hotspots

A hotspot name is easy to copy, so verify the exact name and sign-in process with the venue. Any mismatch in the portal, certificate prompts, or installation requests is a reason to disconnect.

Frequently asked questions

Is the strongest Wi-Fi signal usually the real one?

No. Signal strength reflects distance, power, and obstacles. An attacker can deliberately broadcast a stronger signal.

Can a fake hotspot copy the exact network name?

Yes. Network names are not unique identifiers. Confirm the venue’s process and avoid automatic connection.

Does HTTPS protect me on a fake hotspot?

It protects traffic to a correctly validated encrypted destination. It does not stop a fake portal from asking you to submit information voluntarily.

Should I install a certificate to join guest Wi-Fi?

Only when a trusted organization documents the requirement and provides the certificate through an authenticated channel. Stop on an unexplained request.

Is a personal hotspot safer?

It removes the venue network from the connection path when you control the phone and hotspot password. Phishing and account risks still apply. Use a strong hotspot password and turn the connection off when finished.