HomeInsightsEvil twin attacks: Could malicious Wi-Fi networks put football fans at risk?

Evil twin attacks: Could malicious Wi-Fi networks put football fans at risk?

-

As football fans prepare to return to stadiums for the Premier League kick-off, connectivity will once again play a central role in the match-day experience.  

Behind the scenes, stadiums are relying on connected systems for everything from ticketing and payments to surveillance and day-to-day operations.  

But as stadiums become more connected, keeping those systems secure is becoming vital. 

According to Markus Nispel, Head of AI Engineering and EMEA CTO at Extreme Networks, large crowds and widespread connectivity don’t automatically make stadiums more vulnerable than other environments. 

“Every aggregation of people is a potential target,” Nispel tells Mobile Europe, but he warns that the amount of data that can be extracted today is “very limited”. 

He argues that modern application-level encryption provides an important extra layer of protection. The bigger risk comes when users are tricked into handing over their information after being redirected to a fake portal. 

One threat attracting attention is the so-called “evil twin” attack, in which a criminal creates a fake Wi-Fi network that appears to be a legitimate network operated by a stadium or other venue.  

Once users connect, the rogue network can redirect their traffic, potentially exposing credentials, personal information and devices to further attacks.  

Markus Nispel, Head of AI Engineering and EMEA CTO at Extreme Networks

Risk has changed as public Wi-Fi has evolved 

Public Wi-Fi has changed considerably over the past decade.  

Not so long ago, getting online through a venue’s Wi-Fi often meant handing over a fair amount of personal information. Visitors might be asked for their email address, phone number and other details before they could connect. 

“Around a decade ago, every venue operator wanted your identity, your credentials for marketing purposes, asking for your personal details,” he says.  

That also gave attackers another way in. A convincing fake network could send users to a rogue login page, where they could unknowingly hand over their personal information. 

Today, many venues are taking a simpler approach. Instead of asking visitors for lots of personal information, guest portals are increasingly designed to get people online quickly and with as little friction as possible. 

The reason is not just security. It is also about the fan experience.  

“The main driver for that was more of a frictionless onboarding experience,” he says.  

“After all, if getting onto the stadium Wi-Fi takes too long, many fans will simply switch to their mobile connection.  

“If customers must type in all sorts of information, usually they just walk away and keep on using different network technologies like cellular,” he explains. 

Manchester United partnered with Extreme Networks in 2023

Who is responsible when something goes wrong?  

An evil twin attack also raises a question for stadium operators: if a fan connects to a malicious network, where does the venue’s responsibility begin and end? 

According to Nispel, the answer is that responsibility is shared. The attacker is ultimately responsible for the attack, but both the venue and the fan have roles to play in reducing the risk.  

However, from a user’s view, basic security protocols remain important, particularly when connecting to public networks.  

“As a user, you should always also use encrypted protocols for any of your activity, whether it’s connecting to websites; we should make sure that certificates are valid,” he notes 

“There is a certain amount of, not responsibility, but ownership from a user perspective.” 

But the blame cannot simply be placed on fans. Stadium operators also need to deploy the controls necessary to identify and respond to malicious activity.  

“The venue operator should make sure that they have mechanisms in place to detect malicious attacks out there,” he continues.  

That includes wireless intrusion detection and prevention, alongside processes for locating and dealing with rogue access points.  

Detection needs to sit at the network layer 

Stadium operators can use wireless intrusion detection and prevention tools to identify rogue access points around the venue.  

But according to Nispel, these systems can do more than simply flag a potential threat, they can also help operators respond. 

He explains: “If a malicious network gets identified, if intrusion prevention is being used, the venue infrastructure itself can try to respond and disassociate those fans from those networks, so they really associate themselves with the proper venue network.

“Wireless intrusion prevention and detection should be something that you’re watching out for, and then you need to have a process in place on how you would basically locate potential rogue access points.”  

Segmentation limits the blast radius 

Nispel says segmentation should be a fundamental part of stadium network design, helping to contain the potential blast radius if one part of the infrastructure is compromised. 

“Segmentation is extremely important, and we are promoting that and deploying that as part of our venue design blueprint everywhere,” he says.  

According to Nispel, segmentation limits the potential impact of a compromise, claiming it is the first layer of defence to contain the blast radius.  

However, even where multiple services share physical infrastructure, they can be logically separated and protected by appropriate firewall controls.  

“Payment, for example, is usually logically separated—even if it’s on the same physical network- so you can’t transition from one segment to another. They’re completely firewalled from each other,” he adds. 

“You can also drive that even further, whether it’s ticketing systems, whether it’s your stadium operational network, security and surveillance.” 

AI is part of the arms race 

AI is also becoming increasingly important in cybersecurity, particularly in threat detection. But Nispel does not believe it will allow defenders to permanently stay ahead of attackers.  

“I would call it an arms race, like it is with traditional technologies,” he says. 

Attackers can use the same technologies to develop and adapt their methods.  

For stadium operators, AI should therefore be viewed as another tool rather than a silver bullet, working alongside established measures such as network segmentation, encryption, authentication and intrusion detection. 

IN RELATED NEWS