Free Wi-Fi at a café, station or hotel feels like a harmless convenience, but the same openness that makes it easy to join is what makes it exploitable. Get Safe Online, the UK public-private online safety initiative, sets out the two core risks in plain terms: an unencrypted connection that lets someone else intercept what you send, and a fake hotspot set up specifically to trick you into connecting to it.
Why public Wi-Fi is different from a home network
According to Get Safe Online, “the security risk associated with using public WiFi is that unauthorised people can intercept anything you are doing online. This could include capturing your passwords and reading private emails.” This happens either because the connection between a device and the hotspot is not encrypted, or because “someone creates a spoof hotspot which fools you into thinking that it is the legitimate one.” A hotspot that only asks you to log in, rather than enter an encrypted network key, gives the venue a record that you are online but provides “almost certainly no security through encryption” for the data itself.
A spoof hotspot typically uses a name deliberately close to the genuine one, such as a coffee chain’s actual guest network name with a minor variation, so it appears in the list of available networks alongside, or instead of, the real one. Once connected, anything sent without its own separate encryption can potentially be read by whoever controls that fake access point.
Recognising an encrypted connection
Get Safe Online explains that a genuinely encrypted public hotspot will ask for a specific access “key,” rather than just a simple login screen, something that looks like a long string of letters and numbers rather than a memorable password. Where a network only prompts a login screen with no such key requirement, that alone is a sign there is no meaningful encryption protecting the connection itself, regardless of how official the login page looks.
What to do, and avoid, on public Wi-Fi
Get Safe Online’s practical guidance is specific: “unless you are using a secure web page, do not send or receive private information when using public WiFi.” A secure web page is one using HTTPS, shown by a padlock in the browser’s address bar, which encrypts data between the device and that specific website even over an insecure network; most banking, shopping and email services now use this by default, but it is still worth checking rather than assuming, particularly before entering a password or payment details.
Where possible, Get Safe Online recommends using “well-known, commercial hotspot providers” rather than an unfamiliar or unbranded network, since recognised providers are harder to convincingly spoof and more likely to have basic security measures in place. It also recommends keeping antivirus and firewall software active and updated before connecting to any public network, and for anyone needing to reach a work network remotely, using an encrypted Virtual Private Network (VPN) rather than connecting directly. The National Cyber Security Centre reaches a similar conclusion from a technical angle, noting that “sensitive data sent from your device to online services should be encrypted” via HTTPS or a VPN, and that “a Wi-Fi private network protected by WPA2 will be more secure than a public Wi-Fi service such as is found in a coffee shop or hotel.”
Physical risks are part of public Wi-Fi safety too
Get Safe Online’s guidance extends beyond the network itself: never leave a laptop, phone or tablet unattended in a public space while connected, and stay aware of who is nearby and potentially able to see a screen while sensitive information, a password, a banking app, an email, is on display. Shoulder-surfing in a crowded café or train carriage is a much simpler way to capture a password than intercepting network traffic, and it works regardless of how well the Wi-Fi itself is secured.
Frequently asked questions
Is it ever safe to check my bank balance on public Wi-Fi? Banking sites and apps generally use their own HTTPS encryption independent of the Wi-Fi network, so the connection to the bank itself is typically protected; the added risk on public Wi-Fi comes from spoof hotspots and anyone watching the screen directly, which a VPN and basic vigilance both help against.
How do I know if a hotspot is a fake copy of a real one? There is no foolproof visual test; the safest approach is to ask venue staff directly for the exact network name, since spoof networks rely on guests connecting to a similar-looking name without checking.
Does a padlock in the browser mean the whole connection is safe? The padlock confirms that specific website’s connection is encrypted (HTTPS), not that the wider Wi-Fi network is secure; both matter, and neither guarantees the other.
The bottom line
Public Wi-Fi is not inherently unsafe, but it removes a layer of protection a home network usually provides. Get Safe Online’s core advice covers the practical gap: check for genuine encryption rather than assuming it, stick to HTTPS pages for anything sensitive, prefer well-known commercial hotspot providers, use a VPN for work access, and keep both software and physical awareness switched on while connected.
