Skip to content
RESEARCH INDEX BREACHROAD / INTELLIGENCE NOTE

Café Wi-Fi does not have to be a trap. Check the network name first

Two similar network names, a quick bank transfer and a laptop left at the table. Use hotel, train and café internet with better judgement.

PUBLIC RESEARCH
AUTHOR
/ CEO of Breachroad · OSCP · PNPT
PUBLISHED
8 September 2026
READING TIME
8 min read
TOPIC
Human Security
Café Wi-Fi does not have to be a trap. Check the network name first

You sit down in a café, open the laptop and see three similar networks: Cafe_Guest, Cafe_Free and Cafe_WiFi_5G. The strongest signal does not mean you chose the genuine one. Anybody can set a network name, and a page asking you to accept terms does not prove who provides the connection.

Public Wi-Fi does not call for panic. Modern applications and websites usually encrypt their connections, but basic decisions still matter. Confirming the network, limiting sensitive activity and looking after the physical device make the biggest difference.

Ask for the exact network name

Check the name and sign-in method on an official sign or ask a member of staff. Do not trust a loose note attached to a table or choose a network merely because it has no password. An imitation access point may differ from the genuine name by one character.

Disable automatic connection to open networks. This stops a phone joining a familiar name remembered from another airport or branch of a café. Select “forget this network” when you finish, especially if this was a one-off visit.

A welcome page may ask you to accept terms, provide a room number or enter a receipt code. Stop if it wants the password for email, banking or a work account. Internet access should not require credentials belonging to another service.

Banking and sensitive documents can wait for mobile data

A public connection may be reasonable for checking a timetable or reading the news. A transfer, password change, contract signature or particularly sensitive work deserves a connection you trust more. Mobile data or a hotspot from your own phone is the simplest alternative.

If your employer requires its VPN, connect before opening company resources. A VPN does not prove that a sign-in page is genuine, and it cannot protect a laptop left unattended. It is one control, not a universal “safe” switch.

Pay attention to browser warnings about certificates and connections. Do not choose “continue anyway”, especially while signing in. A padlock shows that the connection to that address is encrypted, but you should still read the address itself.

The screen and device matter as much as the network

On a crowded train, somebody may simply see a document or sign-in code on your screen. Sit to reduce that view, limit notification previews and lock the screen even when stepping away briefly. Do not ask a stranger to “watch the laptop for a moment”.

Turn off file sharing and device discovery if the system offers a public-network profile. Keep the operating system and browser updated, ideally before travelling. Do not postpone updates simply because they produce no visible new feature.

If you joined the wrong network

Disconnect and select “forget”. If you only read public pages and approved no installation, do not assume the worst immediately. Check that the connection did not add a profile, app or browser extension.

If you entered a password on a page whose address now looks doubtful, change it over mobile data or another trusted network. End active sessions and report the situation to IT if it involved a work account. Contact the bank through its official app or number if you made a payment or supplied card details.

What the source says and what Breachroad recommends

CISA’s public Wi-Fi best-practices guide advises confirming the correct network name, avoiding sensitive activity and using your own hotspot where possible. It also highlights updates, disabling automatic connections and awareness of imitation access points.

Breachroad adds a sense of proportion: using hotel internet does not automatically mean an incident occurred. Match the connection to the task and choose mobile data when money, passwords or company information are at stake.

For broader guidance away from the office, read Remote work security. We help teams make these habits stick through cybersecurity training.

SHARE / COPY