← See all resources
Evil Twin Attack
Network Attacks • Attack Types

Evil Twin Attack

How attackers create fake WiFi hotspots to intercept traffic and credentials.

Tags

WiFiEvil TwinMITMWireless
Download infographic

File: SecPro-ataque-evil-twin.png

What is an Evil Twin attack?

The Evil Twin is a rogue WiFi access point that impersonates a legitimate network by copying its name (SSID). Victims connect believing it's the real network — at a café, airport or office — and all their traffic passes through the attacker's device, which can spy on it, modify it, or steal credentials.

How is it carried out?

The attacker clones the target network's SSID and sometimes forces users off the legitimate network (deauth) so they reconnect to the twin, which usually broadcasts with a stronger signal. With a fake captive portal it can ask for the WiFi password or service credentials, phishing over the connection itself.

How to protect yourself?

Always use a VPN on public networks, verify the network's authenticity before connecting, disable auto-connect to known WiFi, and prefer HTTPS sites. In corporate environments, WPA2/WPA3-Enterprise with 802.1X and rogue access point detection systems (WIPS).

More from Network Attacks • Attack Types

Explore more infographics

View full catalog

Need help with your cybersecurity? 💬