Is Public Wi-Fi Dangerous in 2026? The Risks Most Articles Overlook
Written with AI assistance and reviewed by the NorwegianSpark SA editorial team.
Affiliate disclosure: This article contains affiliate links. If you click a link and buy a subscription, we may earn a commission at no cost to you. Our editorial recommendations are never influenced by commissions — read the full disclosure.
The standard public wi-fi warning describes someone at the next table reading your banking password out of the air. That threat was real, it drove a decade of security advice, and the web changed underneath it.
The United States Federal Trade Commission puts the current position about as plainly as a regulator can. Its consumer page, “Are Public Wi-Fi Networks Safe? What You Need To Know”, dated February 2023 and read by us on 6 September 2026, states: “Because of the widespread use of encryption, connecting through a public Wi-Fi network is usually safe.” The same page does not mention VPNs at all.
That is an awkward fact for an article on a site that writes about VPNs, and it is the honest starting point. The risks on an open network in 2026 are real, they are just not the ones in the marketing — and knowing which is which decides whether a VPN is solving your problem or selling you a feeling.
What changed: encryption stopped being optional
The old attack worked because most web traffic travelled in the clear. Anyone on the same network could read it with free software, and the demonstrations were genuinely alarming because they were genuinely easy.
Encrypted connections changed the economics of that. When a connection is encrypted end to end, someone sitting on the network sees which server you are talking to and how much data moves — not the contents. Browsers now warn on unencrypted pages rather than on encrypted ones, which is the inversion that tells you how completely the default flipped.
So the specific 2010 scenario — passwords and messages plucked out of the air at a café — is largely closed for ordinary web and app traffic. Any article still leading with it is describing a threat model that the platforms fixed, and it is worth noticing that the FTC, which has no product to sell, says so.
What did not change: the metadata
Encryption hides the contents of a connection. It does not hide that the connection happened.
Anyone operating or observing the network can still see the names of the servers your device contacts, roughly when, and how much data each exchange moves. That is a meaningful picture: a list of the services someone uses, in order, with timing. It is not your messages, and it is not nothing.
Your device also leaks a certain amount simply by being present. It has a hardware identifier — modern phones randomise this for unjoined networks, which helps — and it broadcasts the names of networks it has joined before, which is a rough travel history.
This is the category a VPN genuinely addresses, and it is worth stating exactly. A VPN moves that entire metadata picture from the network operator to the VPN provider. It does not delete it. You are choosing who gets to see it, which is a real decision and is why the provider's logging position matters more than any speed figure — see our no-logs policy guide.
The risks that actually replaced the old ones
Four of them, in rough order of how often they matter.
The fake network. Anyone can name a hotspot after the venue. A device that joins it routes everything through equipment the attacker controls, which does not break encryption but does put them in position for everything below. This is the one genuine, common, technical risk on the list.
The sign-in page that is not a sign-in page. Captive portals have trained everyone to expect a browser window demanding details on joining a network. That expectation is the attack: a convincing portal asking for an email and password, or offering an update to install, is doing better than any packet capture ever did.
Automatic rejoining. Phones reconnect silently to network names they have seen before, which means a hostile network only has to use a name your device already trusts. You will not be asked.
The screen and the shoulder. Unglamorous and consistently the most effective attack in a public place. No encryption addresses someone watching you type.
What a VPN does and does not do about each of those
Being specific here is the whole point, because this is where marketing and mechanism part company.
Against the fake network, a VPN helps substantially: once the tunnel is up, the hostile operator sees encrypted traffic to one address and can read none of it. Against the metadata problem it helps by definition, by moving the observer. Those two are the honest case for using one, and they are a good case.
Against the fake sign-in page it does nothing at all. You typed the details in. Against automatic rejoining it does nothing, because the tunnel comes up after the network is joined. Against someone reading your screen it obviously does nothing.
And there is a specific ordering problem worth knowing: a VPN set to connect on startup will block the captive portal from loading, so the sequence has to be join the network, complete the portal, then connect. That gap is real, it is unavoidable, and it is the one window in which the network sees you unprotected.
A VPN on a public network is a sound, proportionate tool for a specific job. It is not a shield and it is not a substitute for the four habits below. Whether you need one at all, more broadly, is the subject of do you really need a VPN.
The four habits that outperform any purchase
- Ask the venue for the network name. Not the sign on the wall, which anyone can copy. This single question defeats the fake-network attack outright and costs nothing.
- Turn off automatic joining for public networks, and forget the ones you will not use again. Both major mobile systems have the setting, and it removes the silent-rejoin problem.
- Never install anything a network asks you to install, and never enter an account password into a portal page. Portals need a click, an email address at most, and never a system update.
- Turn on two-factor authentication on your email account. It is not a wi-fi measure at all, and it protects you more than every wi-fi measure combined, because email is the reset route to everything else — see credential stuffing.
Where public wi-fi is still genuinely worth avoiding
The answer above is calmer than the standard warning, and it should not be read as an all-clear.
There are situations where the sensible move is mobile data or nothing. When the network belongs to nobody identifiable — an unnamed open hotspot with no venue attached. When you are travelling somewhere network traffic is monitored as a matter of policy, where the questions become legal rather than technical and where VPNs are legal is the place to start. When the device is not yours, which is a different problem entirely and is covered in borrowed and shared computers. And when the work is genuinely sensitive, where the honest answer is that the marginal cost of a mobile hotspot is lower than the tail risk.
The general principle: the danger scales with how little you know about who runs the network, not with the word “public”. A hotel network with a printed name at reception is a different proposition from an unnamed open access point in a station, and treating them identically is why the standard advice gets ignored.
The counter-argument, which deserves a hearing
A reasonable objection to everything above: encryption is widespread rather than universal, coverage is not the same as correct implementation, and a confident all-clear is exactly the kind of advice that ages badly the moment a common library turns out to be broken.
That is fair, and it is why the framing here is about which risks are live rather than about whether public wi-fi is fine. A defence-in-depth argument for using a VPN on untrusted networks — that it costs little and removes a whole class of failure you cannot audit from a café table — is a legitimate position, and it is the one we would take ourselves.
What is not legitimate is the version that sells a VPN as protection against fake sign-in pages, malware, or someone reading your screen, because it is protection against none of those. If a page tells you public wi-fi is dangerous and a VPN makes it safe, it has skipped the entire middle of the argument. The tool is good. The story usually told about it is not.
About the sources on this page
One external source is quoted: the FTC consumer page “Are Public Wi-Fi Networks Safe? What You Need To Know”, dated February 2023, read 6 September 2026. No statistic, breach figure or attack frequency appears here, because the ones in circulation are almost all either undated, vendor-published, or both. Where a number would have to be guessed, the sentence is written without it.
Frequently Asked Questions
Is public Wi-Fi safe now?
The FTC's consumer guidance states that “Because of the widespread use of encryption, connecting through a public Wi-Fi network is usually safe.” The contents of your traffic are generally protected. What remains exposed is metadata — which services you contact and when — plus fake networks, fake sign-in pages, and anyone able to see your screen.
Does a VPN make public Wi-Fi safe?
It addresses two of the four real risks: it stops the network operator reading or profiling your traffic, and it neutralises much of what a fake network gains. It does nothing about a fake sign-in page, nothing about your phone silently rejoining a hostile network, and nothing about someone reading your screen.
Why does the hotel sign-in page not load with my VPN on?
Captive portals must load before the network releases traffic, and a VPN connecting on startup blocks that. Join the network, complete the portal, then connect the VPN. That gap is the one moment the network sees you unprotected.
What is the single most effective thing I can do?
Ask the venue for the exact network name before joining, and turn off automatic joining for public networks. Between them those defeat the fake-network and silent-rejoin problems, which are the two genuinely technical risks left.
Is mobile data safer than public Wi-Fi?
It removes the fake-network and hostile-operator problems, because you are on your carrier's network rather than a stranger's. It does not make you private — your carrier sees the same metadata a wi-fi operator would. It is a change of who is watching, not an absence of watching.
Also worth comparing
Other providers we recommend for this topic. Sponsored links — we may earn a commission at no extra cost to you.
VPNTex is published by NorwegianSpark SA (Org no: 834 984 172). We may earn commissions on qualifying purchases via affiliate links. This does not affect our editorial independence. Full disclosure · Privacy policy

