In our previous “ABC’s of ‘ishing” posts, we explored how attackers use social media, calendar invites, fake CAPTCHA challenges, and other trusted tools to deceive users. This next installment looks at three phishing techniques that continue to put organizations and individuals at risk: evil twin phishing, domain spoofing, and email phishing.
Each attack uses a different method, but they all rely on the same idea: create something familiar and convincing enough to get someone to connect, click, or log in.
Evil twin phishing
What is Evil twin phishing?
Evil Twin Phishing involves attackers creating a rogue Wi-Fi network that mimics a legitimate one. These fake networks are often set up in public places such as airports, hotels, coffee shops, and conference centers, where people expect free Wi-Fi to be available. Once someone connects, they are often redirected to a fake login page requesting their email, social media, or other account credentials. Depending on how the attack is set up, the attacker may also be able to intercept network traffic or collect other sensitive information.
Real-world example
In Australia, a man used a portable wireless device known as a Wi-Fi Pineapple to create fake networks at airports in Perth, Melbourne, and Adelaide, as well as on domestic flights. The device listened for Wi-Fi networks that nearby phones and laptops had previously connected to. It then created a network with the same name, causing some devices to connect automatically because they believed it was already trusted. Once connected, users were directed to a fake portal and asked to sign in using an email or social media account. The credentials they entered were saved to the attacker’s device and later used to access victims’ online accounts. The man was 42 when he was charged in 2024 and was sentenced in November 2025, at age 44, to seven years and four months in prison.
Evil twin attacks can also pose a risk to government and enterprise networks. In 2020, the U.S. Department of the Interior’s Office of Inspector General reported that a security assessment had successfully used evil twin, eavesdropping, and password-cracking techniques against departmental wireless networks. Using portable test devices that cost less than $200, the assessment team intercepted and decrypted wireless traffic across multiple bureaus. The attacks went undetected, and weak network segmentation allowed the team to identify systems containing sensitive data and supporting mission-critical operations.
Impact
Successful evil twin attacks can lead to:
- Credential theft
- Account takeover
- Exposure of sensitive corporate or personal information
- Unauthorized access to online services
- Interception of network traffic
- Follow-on phishing or fraud
Strategic recommendations
- Verify the name of a public Wi-Fi network with staff before connecting.
- Avoid entering email, social media, or corporate credentials into unexpected Wi-Fi login pages.
- Avoid accessing sensitive accounts over public Wi-Fi. If public Wi-Fi is necessary, use a trusted VPN, but remember that a VPN will not protect you from entering credentials into a fake login portal.
- Disable automatic Wi-Fi connections on laptops and mobile devices.
- Use a personal hotspot instead of public Wi-Fi when possible.
- Require phishing-resistant MFA for sensitive corporate applications.
- Ask employees to forget public networks after they have finished using them.
- A familiar network name does not mean the network itself is legitimate.