Stand Against Crime

Account Security · Global

Public Wi-Fi & VPN

Is public Wi-Fi actually dangerous? The honest answer: less than it used to be — but a few real risks remain. Here’s what genuinely protects you, and where a VPN honestly helps.

Updated Aug 2026 · 6 min read

Fake Hotspot

Wi-Fi · open network

Connected to “Airport_Free_WiFi” — a lookalike network set up to watch your traffic

Evil-twin hotspot

You’ll see a lot of scary advice about public Wi-Fi — much of it written to sell you something. So let’s be straight: the web is mostly encrypted now (HTTPS), which quietly killed the old “anyone can read your password on café Wi-Fi” threat. But a few genuine risks remain, and they’re worth understanding before you decide what protection you actually need.

The Real Risks

Fake “evil twin” hotspots

An attacker sets up a hotspot named to look legit — “Airport_Free_WiFi”, “Starbucks_Guest” — so you connect to them instead of the real network. Now they sit between you and the internet. This is the biggest real risk.

Fake login (captive-portal) pages

The “sign in to use this Wi-Fi” page can be faked to phish your email password or card details. It’s phishing wearing a Wi-Fi costume.

Snooping on unencrypted connections

Anything not sent over HTTPS can, in theory, be read on a shared network. In practice most sites are HTTPS now — but not all traffic is.

What’s overblown: The classic fear — “a hacker on the café Wi-Fi will steal your bank password” — is largely outdated. Banking and login pages use HTTPS encryption, so the network can’t read what you send, and browsers now warn loudly on insecure pages. The real dangers are the fake hotspot and the fake login page, not the coffee shop’s router itself.

What Actually Protects You

  1. Stick to HTTPS. Look for the padlock and the correct web address; never dismiss a browser security warning on public Wi-Fi.
  2. Use two-factor authentication, so a stolen password alone can’t open your accounts.
  3. Keep your phone, laptop, and apps updated — most real attacks exploit old software.
  4. For anything sensitive (banking, big payments), prefer your mobile data over an unknown network.
  5. Turn off auto-connect to open networks, and “forget” networks you won’t use again, to avoid silently joining an evil twin.
  6. Check the exact network name with staff before connecting — attackers rely on you guessing.

Where a VPN Genuinely Helps

A VPN routes your traffic through an encrypted tunnel to a server you choose. On a public or untrusted network, that’s a real, useful upgrade:

  • It encrypts ALL your traffic to a trusted server, so the local network — real or fake — can’t read or tamper with what you do. That’s the main win on an untrusted or public network.
  • It hides your browsing from the network owner and your ISP.
  • It’s a solid defence-in-depth layer if you travel a lot or often must use sensitive services on public Wi-Fi.

But be honest about the limits:

  • It does NOT stop phishing, malware, or you typing a password into a fake site — a VPN protects the pipe, not your decisions.
  • Free VPNs often make money by logging or selling your data, which defeats the point. Choose a reputable, independently-audited, no-logs provider.

Bottom line: you don’t need a VPN to use public Wi-Fi safely if you stick to HTTPS and use two-factor authentication. But a reputable, no-logs VPN is a worthwhile layer if you travel often or regularly handle sensitive things away from home — just don’t treat it as a cure-all, and never use a “free” one that pays for itself with your data.

VPNs we recommend

Want a no-logs VPN for public Wi-Fi and travel? Two budget-friendly options, both with apps for all your devices: FastestVPN and iProVPN.

Partner links — they may earn us a commission at no cost to you. Learn how we make money.

If You Used Public Wi-Fi and Are Worried

  1. 1

    Once you’re on a network you trust, change the passwords for anything sensitive you accessed, and make each unique.

  2. 2

    Turn on two-factor authentication where you haven’t already.

  3. 3

    Update your device and apps, and review recent account activity for anything unfamiliar.

  4. 4

    If you entered details on a Wi-Fi “login” page, treat that as a possible phishing page and change that password too.

Frequently Asked Questions

Is public Wi-Fi safe to use?

Safer than it used to be, thanks to HTTPS encryption on most sites — but not risk-free. The real dangers are fake “evil twin” hotspots and fake Wi-Fi login pages, not the network itself. Stick to HTTPS, use 2FA, and keep sensitive tasks for a network you trust.

Do I really need a VPN on public Wi-Fi?

Not strictly, if you stay on HTTPS and use 2FA. But a reputable VPN is a genuinely useful extra layer — especially on untrusted networks, when travelling, or if you regularly do sensitive things away from home. It’s protection in depth, not a magic shield.

Are free VPNs okay?

Be careful. Running a VPN costs money, so many free ones monetise by logging or selling your data — the exact opposite of what you wanted. Prefer a reputable paid, no-logs, independently-audited provider.

What is an “evil twin” Wi-Fi network?

A fake hotspot named to look like a real one (e.g. “Airport_Free_WiFi”) that an attacker sets up to intercept your traffic. Verify the exact network name with staff, and turn off auto-connect so your device doesn’t join one on its own.

Can someone really steal my bank password on public Wi-Fi?

It’s much harder than people fear, because banking sites use HTTPS the network can’t read. The bigger risks are a fake login page (phishing) or a fake hotspot — which is why checking the address bar and using 2FA matter more than the network itself.

Related reading: passwords & 2FA, check a suspicious link, or browse all our scam guides.

Informational only — not security advice for a specific situation. Sources: UK NCSC and US CISA / FTC guidance on public Wi-Fi and VPNs, and current HTTPS-adoption data. Verify against primary sources.

Warn someone — share this