You have been told that using café Wi-Fi lets strangers read your email.
In 2026, that is largely no longer true.
HTTPS now covers over 95% of web traffic (Axis Intelligence, 2026).
The US Federal Trade Commission updated its own public Wi-Fi guidance in March 2026 to acknowledge exactly that.
But this is not an article telling you to relax.
The old risk faded. A different one did not, and almost nobody talks about it. 📡
🎁 Compare Security Tool Trials →
🧾 Principais conclusões em resumo
| Medir | Figura | Fonte |
|---|---|---|
| Web traffic encrypted by HTTPS | Over 95% | Axis Intelligence (2026) |
| FTC guidance updated | March 2026 | Axis Intelligence (2026) |
| Main remaining threat | Evil twin networks | CyberShieldTips (2026) |
| Victim interaction required | Nenhum | CyberShieldTips (2026) |
| Hotel Wi-Fi targeting known since | At least 2007 | DarkHotel APT reporting |
| Still-real risks | Fake portals, metadata, tracking | Windscribe (2026) |

🔐 What Changed, and Why
A decade ago, most websites sent data in plain text.
Anyone on the same network could read it with free software.
That is the world the warnings were written for, and it no longer exists.
📊 Share of web traffic encrypted
What HTTPS actually protects
When you see the padlock, the content of your connection is encrypted.
Someone on the same network cannot read your messages, passwords or bank balance.
Sitting next to you in a café no longer gives anyone access to what you are doing.
Why the warnings persisted anyway
Two reasons, one innocent and one not.
Advice ages slowly, and old guidance gets copied endlessly.
And the fear sells VPN subscriptions, so there is little incentive to correct it.
The FTC change matters
Consumer protection agencies are conservative about softening warnings.
When the FTC updates its guidance to acknowledge improved safety, that is meaningful.
It is not a security company saying it. It is a regulator.
👿 The Threat That Did Not Go Away
Here is the part that deserves your attention.
The credible attack in 2026 does not try to break your encryption.
It happens before encryption begins.
It is called an evil twin, and the mechanism is simple.
How an evil twin works
An attacker creates a Wi-Fi network with a name identical to a legitimate one.
“Airport_Free_WiFi” or a hotel’s network name.
Your device connects to theirs instead of the real one.
All your traffic then passes through their equipment.
| Estágio | What happens |
|---|---|
| 1 | Attacker broadcasts a familiar network name |
| 2 | Your device joins automatically |
| 3 | All traffic routes through their hardware |
| 4 | A fake login portal may appear |
| 5 | You enter details believing it is legitimate |
The detail that makes it dangerous
Step two requires nothing from you.
Your phone keeps a list of every network it has ever joined.
By default, many devices rejoin any network matching a saved name.
So your device does the attacker’s work the moment you walk into range (CyberShieldTips, 2026).
Why HTTPS does not fully solve it
Encryption still protects the content of your traffic. That much holds.
But the attacker controls the network itself.
They can see which sites you visit, present fake login pages, and interfere with unencrypted connections.
🔎 Try Security Tools Free First →
📊 Old Threat Versus New Threat
The risk did not disappear. It moved, and the shape changed completely.
📊 Where the danger sits, then and now
Why this distinction matters practically
The old threat was solved by the web itself, without you doing anything.
The new one is solved by a setting on your device.
Neither is solved by buying something, which is why the advice rarely says so.
The advice that did not update
Most published guidance still describes the old threat model (Windscribe, 2026).
It recommends solutions to a problem that HTTPS already handled.
Meanwhile the actual remaining risk gets little attention.
🏨 Why Hotels Are the Worst Case
Hotel networks carry a specific, documented history.
The DarkHotel group has targeted hotel Wi-Fi since at least 2007.
Their targets were business travellers, chosen deliberately.
Why hotels attract this
Guests are predictable, valuable and away from corporate protections.
An executive travelling has their laptop, their accounts and no IT department nearby.
The network name is also known in advance, which makes impersonation easy.
What to do in a hotel specifically
Ask reception for the exact network name. Impersonations are usually near-matches.
Use your phone’s mobile hotspot for anything sensitive.
And treat any “click here to access the internet” page with suspicion.
📋 What Still Genuinely Leaks
Even with HTTPS, some information escapes. Being precise about this matters.
| Information | Visible on the network? |
|---|---|
| Message and page content | No — encrypted |
| Passwords you type into sites | No — encrypted |
| Which websites you visit | Muitas vezes sim |
| How much data you send | Sim |
| Your device identifier | Yes, enabling tracking |
| Apps that skip encryption | Yes, and some still do |
That third row is what people mean by metadata.
The network cannot read your messages, but it can see who you are talking to.
Why metadata still matters
Knowing you visited a medical site, a legal service or a job board reveals a lot.
The content stays private. The pattern does not.
This is the strongest genuine argument for a VPN on public networks.
How to check an app quickly
You cannot inspect an app’s encryption directly without technical tools.
But two signals help. Prefer apps from established developers with regular updates.
An app last updated three years ago is unlikely to follow current practice.
The app problem
Browsers are now excellent about encryption. Apps are inconsistent.
Some smaller apps still send data without proper protection.
You have no easy way to check, which is a real limitation.
✅ What Actually Protects You
Ranked by how much risk each removes, cheapest first.
| Ação | Custo | Risk removed |
|---|---|---|
| Turn off auto-join for open networks | Livre | Most of the evil twin risk |
| Delete saved public networks | Livre | Removes the matching list |
| Use mobile data for anything sensitive | Geralmente grátis | Bypasses the problem entirely |
| Autenticação multifator em todos os lugares | Livre | Stolen passwords become useless |
| Keep devices updated | Livre | Closes known weaknesses |
| A reputable VPN | Paid | Hides metadata from the network |
Note that five of six cost nothing.
The most effective single step is switching off automatic joining.
How to turn off auto-join
On most phones it sits in Wi-Fi settings, per network or as a global option.
Look for “auto-join”, “connect automatically” or “ask to join networks”.
Two minutes, once, and the main attack mechanism stops working.
Turn Wi-Fi off when you are not using it
A phone with Wi-Fi enabled broadcasts requests for saved networks as you walk around.
That is how it reconnects at home without you doing anything.
It also announces which networks you have visited to anyone listening.
Switching Wi-Fi off in transit stops both the broadcasting and the automatic joining.
Clear your saved networks
Your device may hold dozens of remembered hotspots.
Each one is a name an attacker can impersonate.
Delete the ones you will never use again, particularly airports and hotels.
Update before you travel, not during
Device updates close the weaknesses attackers rely on once they control a network.
Downloading a large update over an untrusted connection is the wrong moment.
Update at home, on a network you control, before the trip.
Where a VPN genuinely helps
It hides which sites you visit from whoever runs the network.
On an untrusted network, that is a real benefit.
Nosso VPN adoption analysis covers what it does and does not cover.
📶 Which Networks Deserve Most Caution
Not all public networks carry the same risk, and the ranking is not obvious.
📊 Relative risk by location type
Why airports rank highest
Network names are known in advance and identical worldwide.
Thousands of devices arrive with those names already saved.
An attacker needs only to broadcast a name millions of phones already trust.
Why your local café ranks lower
Fewer transient users, and staff who would notice unfamiliar equipment.
The network name is also less widely saved on strangers’ devices.
None of this makes it risk-free, only less attractive as a target.
The pattern behind the ranking
Risk follows predictability and value, exactly as with hotel targeting (FastestPass, 2026).
Where an attacker can guess the network name and expect valuable users, effort pays.
⚖️ Reading the Risk Honestly
Two failure modes dominate advice in this area, and both are wrong.
| Position | Problem |
|---|---|
| “Public Wi-Fi will get you hacked” | Outdated, sells products |
| “Public Wi-Fi is completely fine now” | Ignores evil twins and portals |
| “Encryption handles everything” | Misses metadata and fake networks |
| “Only a VPN can save you” | Overstates what a VPN does |
The accurate position is less satisfying and more useful.
The content of what you do is safe. The network you joined might not be what it claims.
Proportionate behaviour
Checking a news site on café Wi-Fi is fine.
Logging into a bank on a network you cannot verify is worth avoiding.
Not because encryption fails, but because you cannot be sure whose network it is.
Why fear-based advice backfires
Telling people public Wi-Fi is lethal has a predictable result.
They use it anyway, because they need to, and ignore all the advice together.
Overstated warnings train people to discount accurate ones.
Precise guidance about one real mechanism gets followed. Blanket alarm does not.
The simplest rule
Ask whether you can verify the network’s owner.
If yes, normal caution applies. If no, use mobile data for anything that matters.
📱 Mobile Data Is the Underrated Answer
The simplest protection is often the one people forget they own.
Mobile data does not route through anyone else’s network equipment.
| Public Wi-Fi | Mobile data | |
|---|---|---|
| Who runs the network | Unknown | Your carrier |
| Evil twin risk | Real | Nenhum |
| Fake login portals | Possível | Nenhum |
| Velocidade | Often faster | Usually adequate |
| Custo | Livre | Uses your allowance |
The evil twin row is the decisive one.
The entire attack described in this article is impossible on mobile data.
The tethering option
Your phone can share its connection with a laptop.
That gives a computer the same protection, without joining any public network.
For sensitive work while travelling, this is usually the right choice (SpeedTestHQ, 2026).
When Wi-Fi still makes sense
Large downloads, video calls, or anywhere your data allowance is tight.
Use Wi-Fi for volume and mobile data for anything sensitive.
That split costs nothing and removes most of the decision.
Roaming changes the calculation
Abroad, mobile data may be expensive or unavailable.
That is precisely when hotel and airport Wi-Fi becomes tempting.
It is also when the risk is highest, which is worth planning around before you travel.
🧪 How to Verify a Network
A few seconds of checking removes most of the remaining risk.
Ask a member of staff for the exact name. Impersonations rely on near-matches.
Be suspicious of two networks with similar names in the same place.
Treat an unexpected login page as a warning, not a formality.
Two networks, similar names
This is the clearest warning sign you will ever get.
If you see “CafeWiFi” and “Cafe_WiFi” in the same room, one of them is not the café’s.
Do not guess. Ask which is correct, or use mobile data instead.
Attackers rely on you picking whichever has the stronger signal, which they can control.
The captive portal problem
Many legitimate networks show a login page. So do fake ones.
The rule that works: never enter a password you use elsewhere into one.
A portal asking for your email is normal. One asking for your bank details is not.
Watch for downgrade prompts
If a familiar site suddenly warns about its certificate, stop.
That warning is your browser doing exactly its job.
Certificate warnings on public Wi-Fi should never be clicked through.
💼 What Businesses Should Do Differently
For an individual this is a personal choice. For a business it is policy.
Staff travelling with company data face the exact scenario DarkHotel exploited.
| Controle | Custo | Effect |
|---|---|---|
| Disable auto-join on company devices | Livre | Removes the main mechanism |
| Require mobile data for sensitive work | Data allowance | Bypasses public networks |
| Multi-factor sign-in on everything | Livre | Stolen credentials become useless |
| Company VPN for remote access | Moderado | Protects internal systems |
| Brief travelling staff | Ten minutes | Often skipped entirely |
The last row is the cheapest and most neglected.
Most staff have never been told which network name to expect at a hotel.
Why this connects to breach costs
Stolen credentials remain among the most common ways attackers get in.
A fake login portal on a hotel network is a credential-harvesting tool.
Nosso breach cost analysis shows what follows when that succeeds.
The proportionate response
Do not ban public Wi-Fi. Staff will use it anyway and stop telling you.
Configure devices sensibly and explain the one attack that matters.
Policies people actually follow beat policies that sound strict (Axis Intelligence, 2026).
🔬 How Solid Is the Evidence?
| Source type | Reliability | Caveat |
|---|---|---|
| FTC guidance | High — regulator | US-focused |
| HTTPS adoption measurement | Alto | Browser data, well established |
| Evil twin demonstrations | Well documented | Frequency is not measured |
| VPN company research | Prático | Sells the solution |
The third row is the honest gap in this topic.
Evil twin attacks are proven possible and easy. Nobody publishes how often they actually happen.
Anyone claiming a precise figure is estimating.
Why the frequency is unknown
A successful evil twin leaves little trace.
Victims usually never learn it happened.
So incident counts capture only the cases that were investigated.
What this means for you
Judge on cost of protection rather than probability of attack.
Turning off auto-join costs two minutes and removes most exposure.
At that price, the frequency question barely matters.
🚫 O que esses dados não revelam
It does not measure attack frequency. Nobody reliably does.
It is largely US-based. Guidance and network norms differ.
It cannot cover every app. Some still handle encryption poorly.
HTTPS share is not 100%. A small slice of traffic remains exposed.
Much writing here is vendor-published. Fear and product sales align.
🏁 Versão curta
HTTPS now covers over 95% of web traffic, and the FTC updated its guidance in March 2026 to reflect it.
The classic warning about strangers reading your email on café Wi-Fi is out of date.
The real remaining risk is joining a network that is not what it claims to be.
Evil twin attacks work because your device rejoins saved network names automatically.
The fix costs nothing: turn off auto-join, delete old saved networks, use mobile data for anything sensitive.
A VPN helps by hiding which sites you visit from the network operator.
But the free steps remove more risk than the paid one.
That last sentence is the reason this article exists.
An enormous amount of security advice is written by people selling security products.
When the best answer is a free setting, it rarely gets top billing.
Check who benefits from the advice before you act on it, in this category especially. 📡
🚀 Browse Security Trials by Category →
❓ Perguntas frequentes
Is public Wi-Fi safe in 2026?
Safer than it was. HTTPS covers over 95% of traffic, so content is encrypted. The risk has shifted to fake networks rather than eavesdropping.
Can someone read my email on café Wi-Fi?
No, not through simple eavesdropping. That threat depended on unencrypted traffic, which is now rare.
What is an evil twin attack?
A fake Wi-Fi network using a name identical to a real one. Your device may join it automatically, routing all traffic through the attacker.
Why does my phone join it without asking?
Devices remember every network they have joined and rejoin matching names by default. That saved list is what the attack exploits.
What is the single best protection?
Turning off automatic joining for open networks. It is free, takes two minutes, and removes most of the exposure.
Do I need a VPN on public Wi-Fi?
It helps by hiding which sites you visit from the network operator. It is useful, but less important than the free steps.
What still leaks even with HTTPS?
Which sites you visit, how much data you send, and your device identifier. Content stays private; the pattern does not.
Are hotel networks worse?
Historically yes. Business travellers have been targeted through hotel Wi-Fi since at least 2007, and network names are known in advance.
Which locations carry the most risk?
Airports rank highest, because network names are predictable worldwide and already saved on millions of devices. Hotels follow (FastestPass, 2026).
Is mobile data actually safer?
Yes, for this specific threat. Evil twin attacks are impossible on mobile data, since you never join an unknown network (SpeedTestHQ, 2026).
Should a business ban public Wi-Fi?
No. Staff will use it anyway and stop reporting it. Configure devices to disable auto-join and brief travellers on the one attack that matters.
What should I never do on public Wi-Fi?
Click through a certificate warning, or enter a password you use elsewhere into a login portal.
📚 Referências
Axis Intelligence. (2026). Is public WiFi safe? Security audit and verdictConsultado em 8 de agosto de 2026, em https://axis-intelligence.com/is-public-wifi-safe/
CyberShieldTips. (2026). Evil twin WiFi attacks: How hackers clone your networkConsultado em 8 de agosto de 2026, em https://cybershieldtips.com/article/evil-twin-attack-public-wifi-2026
Windscribe. (2026). How to use public Wi-Fi safely without the fear-mongeringConsultado em 8 de agosto de 2026, em https://windscribe.com/blog/how-to-use-public-wi-fi-safely/
FastestPass. (2026). Evil twin WiFi attack explained: How it works and how to prevent itConsultado em 8 de agosto de 2026, em https://fastestpass.com/blog/evil-twin-wifi-attack/
SpeedTestHQ. (2026). Public Wi-Fi safety guideConsultado em 8 de agosto de 2026, em https://www.speedtesthq.com/guides/network/public-wifi-safety
Leituras relacionadas neste site
Nosso VPN adoption research covers what a VPN does and does not protect. See also our breach cost analysis for where losses actually occur, and the Diretório de participantes com teste gratuito for security tool trials.
Sobre esta análise
This article deliberately contradicts widely repeated advice, based on HTTPS adoption figures and the FTC’s own updated guidance. It also declines to give an attack-frequency number, because none is reliably measured. Much writing in this category is published by companies selling VPNs, where fear and sales align, and that is stated rather than hidden. Figures were checked on August 8, 2026.
-
Public Wi-Fi Risk, Measured Rather Than Assumed - Setembro 6, 2026 -
Tube Magic’s 30-Day Guarantee: How to Test It Properly - Setembro 6, 2026 -
YouTube SEO Tools in 2026: What Still Moves the Needle - 4 de setembro de 2026
