is hotel wifi safe hotel wifi security public wifi

Is hotel Wi-Fi safe? What is risky in 2026 and what is not

Adrian Maverick · · 11 min read

Most advice about hotel Wi-Fi was written for an internet that no longer exists, one where most sites sent your password across the room in plain text. The risks that remain are real, but they are different ones, and they need different habits.

Short answer: hotel Wi-Fi is safe enough for most things, because nearly every site and app now encrypts its traffic with HTTPS. What is still risky is joining a fake network, signing in on a page the network opened for you, and leaving your device visible to other guests. A VPN and a 2-minute check cover most of it.

Is hotel Wi-Fi safe to use?

For everyday use, yes. Google reports that 95 to 99 percent of navigations in Chrome use HTTPS, a level reached around 2020. HTTPS scrambles the connection between your device and the site, so someone on the same network cannot read your password or the page. That is why the US Federal Trade Commission now tells consumers that connecting through public Wi-Fi is usually safe.

A hotel is still not your home. In a 2020 public service announcement, the FBI said hotel Wi-Fi carries more risk than a home network: many unrelated guests share one network in a small space, you cannot check how it is set up, small hotels post the password at the desk and rarely change it, and old network equipment is more likely to have security holes.

So the honest verdict has two halves. Reading your encrypted traffic off the air is mostly a solved problem. Tricking you, or reaching your device, is not.

What is actually risky on hotel Wi-Fi in 2026?

Risk How it works Does HTTPS stop it? What does
Evil twin network Someone nearby runs a network with a name close to the hotel's and you join it No. They control which pages you are sent to first Confirming the exact name at the desk, a VPN
Fake or tampered login page The portal, or a hacked gateway, sends you to a page that asks for a work or email sign-in, or offers an "update" No. A fake page on its own domain has its own valid padlock Never signing in on a page the network opened
Other guests reaching your device File sharing, casting, and discovery are left on from home No Public network profile, sharing off, updates installed
DNS and site names The hotel's DNS server sees every site name you look up, and a hacked one can lie Partly. A forged answer for a real HTTPS site triggers a certificate warning Not clicking through warnings, a VPN
Outdated hotel gear Unpatched or badly secured gateways get taken over without the hotel noticing No A VPN, or your phone's hotspot

Two details are worth spelling out.

An evil twin does not need to break anything. CISA describes it as an attacker gathering information about a public access point and then setting up a system to impersonate it. Your phone joins the stronger signal. From then on, a stranger is your internet provider.

The padlock proves a connection is encrypted. It does not prove the site is the one you meant to visit. A fake Microsoft page on a lookalike domain shows a padlock too, and the FTC warns about encrypted fake sites for this reason.

What is overblown?

  • "Hackers can read everything you type." Not on HTTPS sites, and that is nearly all of them. A snooper sees which sites you connect to and how much data moves, not what is inside.
  • "Stealing your session by sniffing the air." This worked when sites only encrypted the login page. Sites that use HTTPS on every page closed it.
  • "Never use a banking app on hotel Wi-Fi." Banking apps encrypt their own traffic and refuse a server that cannot prove its identity. On the hotel's real network, the app is not the weak point.
  • "A Wi-Fi password makes it safe." A password printed on every key card is shared with every guest and anyone in the lobby. It keeps freeloaders off. It does not keep an attacker out.

What you can drop is the fear of being read. What you should keep is suspicion of the network itself: which one you joined, and which pages it shows you.

Has hotel Wi-Fi really been hacked?

Yes, and the cases show where the risk sits.

July 2026. ReliaQuest reported a campaign, running since at least June 2026, in which attackers took over the captive portal gateways of hotels and conference centers in several US cities, India, and Saudi Arabia. They changed the gateway's DNS answers so that guests landed on what looked like a Microsoft 365 sign-in prompt, on domains such as ms365-live[.]com, without clicking any link. The page then used Microsoft's device code sign-in, where approving a prompt authorizes a session someone else started. Because the guest approved it, multi-factor authentication did not help. ReliaQuest assessed, with low to medium confidence, that the gateways were entered through exposed admin interfaces and weak or reused passwords. BleepingComputer covered it the next day.

One point from that report corrects a common tip: setting your device to a public DNS server such as 8.8.8.8 did not help, because the request still left the device unencrypted and the gateway could read it and forge the answer.

2014. Kaspersky documented DarkHotel, a group whose tools dated back to 2007. Executives who logged in to hotel Wi-Fi with their last name and room number were prompted to install what looked like updates for well-known software. The updates were malware.

In both cases nobody cracked HTTPS. The network showed guests something, and the guests trusted it.

Can the hotel see what you browse?

The hotel can see which sites you visit, not what you do on them. Its network sees the site names your device looks up, the times, and the amount of data. On HTTPS sites it cannot see pages, searches, messages, or passwords.

A hotel differs from a cafe in one way: the login page usually asks for your room number and last name, so that record is tied to you by name. Private browsing does not change this, and neither does clearing your history. The same site-name leak exists with your home provider, and our guide to what your ISP can see explains each place the name escapes. A VPN hides the names from the hotel.

Is hotel Wi-Fi safe for banking or for work?

Banking: on the hotel's real network, using your bank's own app or a bookmarked HTTPS address, the connection is encrypted end to end between you and the bank. The FBI's 2020 notice still advises avoiding banking on hotel Wi-Fi if possible, and the cautious choice costs nothing: switch to mobile data for those two minutes.

Work: treat it as untrusted. The 2026 campaign went after work accounts. Use your employer's VPN if you have one, follow your employer's rules, and approve a sign-in prompt only when you started it yourself.

How to use hotel Wi-Fi safely

  1. Get the exact network name from the front desk. Not from the list on your phone. CISA's advice is to confirm the name and password of a public hotspot before you use it. If two names look alike, ask which is real.
  2. Read the login page with suspicion. A hotel portal asks for a room number, a last name, or an access code. It has no reason to ask for your email or work password, or to make you install anything. If it does, disconnect.
  3. Run the 2-minute check. Once you are online, open a new tab and type the address of a site you know, starting with https. It should load with no certificate warning. A warning on a site that normally works means something sits between you and it. Do not click through. Disconnect and use mobile data.
  4. Never sign in on a page the network opened for you. If a sign-in page appears by itself, close it. Open the app, or type the address you already know.
  5. Hide your device from other guests. On Windows 11, set the network to the Public profile, which hides your PC and turns off file and printer sharing. On a Mac, open System Settings, then General, then Sharing, and switch off what you do not need.
  6. Turn on your VPN as soon as the login page is done. A VPN cannot connect until you are past the portal, so do nothing else in that gap.
  7. Keep your system and browser updated before you travel, and turn on Chrome's "Always use secure connections" setting under Privacy and security, so the browser asks before loading a site without HTTPS.
  8. Turn off auto-join when you leave. Otherwise your device can rejoin a network using that name without asking. Apple's instructions for auto-join and forgetting a network cover iPhone and Mac.

If anything feels wrong, your phone's hotspot is the simplest way out. The FBI's notice recommends it too.

Does a VPN make hotel Wi-Fi safe?

It removes the network from the equation, which is most of the problem. A VPN wraps all your traffic, DNS lookups included, in one encrypted tunnel to a server you chose. The hotel, an evil twin, or a hijacked gateway sees a single encrypted connection and cannot read it or forge answers inside it. ReliaQuest named an always-on, full-tunnel VPN, along with encrypted DNS in strict mode, as the settings that break the 2026 attack.

Two things matter on hotel networks in particular. Hotel Wi-Fi drops often, so the VPN needs a kill switch that blocks traffic while it reconnects. And its DNS has to stay inside the tunnel, or you have a DNS leak that hands the site names straight back to the hotel.

Secria VPN is built for this. It keeps no activity logs: we do not record browsing, DNS queries or traffic contents. It comes with private DNS, a kill switch, and an ML-KEM-1024 post-quantum key exchange on every WireGuard connection. It is $7.99 a month on its own or included in Pro.

A VPN does not stop you from approving a sign-in you did not start, and it moves your trust from the hotel to the VPN company. Choose that company with care. We covered how in are free VPNs safe.

FAQ

Is hotel Wi-Fi safe without a VPN? For browsing HTTPS sites and using mainstream apps on the hotel's real network, mostly yes. Without a VPN the hotel sees the names of the sites you visit, and you depend on your own care to avoid fake networks and fake sign-in pages.

Is hotel Wi-Fi safer if it has a password? Only slightly. Every guest has the same password, and it is often printed on a card or posted at the desk. It keeps outsiders from using the connection, but anyone who knows it can join, and it does not stop someone from copying the network name.

Is hotel Wi-Fi safe on an iPhone? An up-to-date iPhone exposes little to other devices on the network, and mainstream apps use encrypted connections. The remaining risks are the same as on a laptop: a fake network name and a fake sign-in page. Turn off auto-join for the network when you check out.

Is my phone's hotspot safer than hotel Wi-Fi? Yes. A hotspot uses your mobile carrier's network with a password only you know, so there are no other guests on it and no hotel gateway in the path. It is the better choice for banking and work sign-ins if you have the data.

Can someone in another room see my files? Only if your device is sharing them and the hotel does not separate guests from each other, which you cannot check from your room. Set the network to public on Windows, turn off sharing on a Mac, and the question goes away.

Hotel Wi-Fi is fine once you stop taking the network's word for anything. Confirm the name, distrust any page it opens, and bring your own tunnel. If you want that tunnel post-quantum by default, Secria VPN covers five devices on one plan.

Secria fact-checks every post against primary sources. Spotted something wrong or out of date? Email hq@secria.me and we will correct it.