CYBER WELFARE

Protect your Digital Privacy

Attacks on mobile hotspots: what someone nearby can do with your connection

When you switch on your phone’s hotspot — the feature that turns your smartphone into a small Wi-Fi access point and shares its mobile data connection with other devices — you create a wireless network that travels with you. On the train, in a café, in a waiting room.

That network is visible to anyone nearby. Without the password, nobody gets in; but if the password is short, predictable or has changed hands too many times, the door is left ajar.

This post describes the attacks that take advantage of that half-open door, from the most mundane to the most ingenious. It is the threat-side companion to the recommendation on your mobile hotspot password: choose a strong one and change it regularly.

One useful clarification: this post describes how these attacks work from the point of view of the person on the receiving end, so that you can recognise them and defend against them. It contains no operational instructions.

The starting point

It is Monday morning, you are on the train and you need to send a file from your laptop. You switch on the hotspot. The network name is the one your phone picked on day one, and the password has not changed in two years: you read it out to a colleague, then to your son, then to a friend on holiday.

There are dozens of phones and laptops in the carriage, and your hotspot appears on every one of their lists.

Most of the time, nothing happens. But when something does, you rarely notice: your data allowance goes down a little faster, and your laptop stays connected to a network you believe is yours alone.

Why a weak or never-changed password increases the risk

All the attacks that follow share one thing: they exploit a network that moves around with you, and a password that, over time, has become less secret than you think.

Three features make a hotspot different from your home network:

  • It moves. A hotspot is switched on in different places every day, in front of different people.
  • It gets shared quickly. The password is read out, shown on screen, sent in a chat. Every time you share it, you create a copy you no longer control.
  • It stays the same for a long time. Many people never change it, or keep the one the phone suggested.

A long password is hard to guess; changing it after lending it out resets the number of people who know it to zero.

1. Guessing a weak password

In plain terms. Someone nearby tries to guess your hotspot password.

How it works. Short passwords — a word with a few numbers, a date, a run of keys along the keyboard — appear on lists of common combinations. Sometimes there is no need to try on the spot at all: it is enough to observe the network briefly and then test combinations at leisure, somewhere else. That is why length matters more than symbols.

Why a weak password makes it easier. With a long, random password, there are simply too many combinations to try.

Possible impact. Access to your network and, from there, to almost every attack that follows.

What should make you suspicious. Unknown devices on the list of connected devices, notifications of new connections when you have not given the password to anyone.

How to protect yourself. A password of at least 16 characters — a phrase of several words works well — that is different from all your others: the reasons are explained in the recommendation on sixteen character passwords. If your phone allows it, choose the most recent protection available, such as WPA3 (the current encryption standard for Wi-Fi networks), which will be the subject of a dedicated recommendation in future.

2. Using your connection from nearby (freeloading)

In plain terms. Someone uses your hotspot to get online for free, without asking. This is known as freeloading.

How it works. The most common case requires no skill at all: someone who was given the password months ago finds it saved on their device, which reconnects on its own as soon as your hotspot is within range. At other times the password is guessed, or glimpsed over your shoulder.

Why a never-changed password makes it easier. Devices remember networks and passwords until someone deletes them. A password that never changes keeps working for everyone who ever received it.

Possible impact. Your data allowance used up faster, a slower connection, extra charges once you go over your plan’s limit.

What should make you suspicious. Higher data usage than usual, a familiar device that should not be there, a hotspot slower than expected.

How to protect yourself. Change the password periodically and after every occasional share; switch the hotspot off when you do not need it; if your phone allows it, limit the number of devices that can connect. The concrete signs to look for are gathered in the guide to unknown devices on your hotspot.

3. Eavesdropping on an open or poorly protected network

In plain terms. If your hotspot has no password, or uses outdated protection, someone nearby can observe part of what passes through it.

How it works. On a protected network, data travels encrypted, meaning it can only be read by whoever holds the key. On an open network that layer is missing. Today most websites and apps use their own encryption anyway — HTTPS, shown by the padlock in the address bar — so the content itself usually stays protected. But not everything: the names of the sites you visit, traffic from older apps and the information devices exchange with each other on the network can remain visible.

Why a network without a password makes it easier. Without a password, anyone can join and observe from the inside. The password is not just a lock on the front door: it is also the basis of the key the network uses to encrypt traffic.

Possible impact. Exposure of your browsing habits, data from poorly protected apps, information about your devices.

What should make you suspicious. Almost nothing: someone who only listens leaves no trace. The only signal comes beforehand: a hotspot with no password.

How to protect yourself. Never leave your hotspot open, not even “just for five minutes”. For sensitive tasks, the same precautions apply as on public networks, as explained in the recommendation on sensitive data on public Wi-Fi.

4. The twin network (evil twin)

In plain terms. Someone creates a network with the same name as your hotspot, or almost the same, hoping that someone will connect to it by mistake. In security jargon this is called an evil twin.

How it works. Every Wi-Fi network has a name, the SSID, which appears in the list of available networks. Devices tend to reconnect on their own to networks they remember; if the remembered network was open, the name is effectively the only thing they check. People fall for it too: between “Work-Phone” and “Work-Phone 2”, anyone in a hurry will not notice the difference.

Why an open network or an obvious name makes it easier. A password-protected network forces the fake twin to know the same password in order to fool devices that connect automatically. With no password, or with an obvious name, that obstacle shrinks considerably.

Possible impact. Your traffic passes through someone else’s device: it can be observed, and some pages can be replaced with imitations that ask for your login details.

What should make you suspicious. Two networks with the same name; your laptop connected “to your hotspot” while your phone shows no connected devices; unexpected sign-in pages; browser warnings about invalid certificates (the site cannot prove its identity).

How to protect yourself. A custom network name that gives nothing personal away (no first name and surname); a password that is always on; removing open networks you no longer use from your devices; checking the list before you connect.

5. Scanning connected devices

In plain terms. Whoever has got into your hotspot also looks at the other devices connected to it, such as your laptop or tablet.

How it works. Devices connected to the same network can “see” one another. With ordinary network diagnostic tools it is possible to list the devices present and see which services they expose: a shared folder, a feature left switched on. This kind of reconnaissance is called scanning: it is not an attack yet, but it is often the first step towards one.

Why a weak password makes it easier. Scanning requires being inside the network. The password is the only barrier between a stranger in the carriage and your laptop.

Possible impact. Access to files shared by mistake, exploitation of devices that are not up to date, gathering of information useful for further attempts.

What should make you suspicious. Names of devices you do not recognise on the list of connected devices; warnings from your laptop’s firewall (the protection that filters incoming connections) about unusual connections.

How to protect yourself. On your laptop, treat the hotspot as a public network: file sharing off, firewall on, system up to date.

6. Misusing your connection for illegal activity

In plain terms. Someone uses your hotspot not just to get online for free, but for activities they would rather not have traced back to them.

How it works. To the outside world, traffic from your hotspot leaves through your mobile line, which is linked to your SIM card and your contract. Someone who wants to stay anonymous may prefer someone else’s connection: to download protected content, send abusive messages or attempt unauthorised access to services.

Why a weak or widely shared password makes it easier. The more people know the password, the harder it is to work out who did what.

Possible impact. Requests for explanations addressed to you, restrictions on your line, time spent proving you had nothing to do with it. The effects on several levels are described in the post on the consequences of an open hotspot; the legal aspects depend on the country and on the specific case.

What should make you suspicious. Spikes in traffic at times when you were not using your phone, messages from your mobile provider about unusual use of your line.

How to protect yourself. A strong password, changed after every share, and a hotspot that is switched off when you do not need it.

7. Manipulation to obtain the password (social engineering)

In plain terms. Instead of guessing the password, someone asks for it — or watches you enter it — with a plausible excuse. This is called social engineering: getting something by working on people’s trust rather than on technology.

How it works. “Could I borrow your hotspot for a minute? I’ve run out of data.” A friendly person in a waiting room, a fake technician. Sometimes it is enough to glance at the screen while you show the password, or to photograph the QR code some phones generate to share it. The gesture seems harmless, and almost always it is.

Why a never-changed password makes it easier. A password lent once stays valid until you change it. Someone who obtained it under a pretext can come back whenever they like.

Possible impact. All the impacts of the previous attacks, starting from access you granted yourself.

What should make you suspicious. Insistence, haste, requests from people you do not know, more interest in the password than in the connection.

How to protect yourself. If you share, do so deliberately and change the password as soon as the person has finished. Do not show the password in plain view to anyone who does not need to see it. Keep it somewhere safe, for example in a password manager (an app that creates, stores and fills in your passwords for you): the method is explained in the recommendation on storing passwords safely.

Summary table

AttackMain riskWhat should make you suspiciousEffective defences
Guessed passwordAccess through a short passwordUnknown devicesLong, unique password, WPA3
FreeloadingConnection used by past guestsData allowance running out earlyRegular changes, device limit, hotspot off
EavesdroppingTraffic observed on an open networkAlmost nothingPassword always on
Evil twinConnecting to a fake networkTwo networks with the same nameCustom name, password
ScanningDevices exposed to strangersFirewall warningsFile sharing off, firewall
Misuse of your lineOther people’s activity in your nameTraffic spikesChange after every share
Social engineeringPassword obtained under a pretextInsistence, hasteDeliberate sharing

What they have in common

Seven different attacks, three defences that cut across almost all of them:

  1. A long, unique password — it makes guessing impractical and takes the ground from under the evil twin.
  2. Regular changes, and a change after every share — it resets to zero the number of people who can get in.
  3. A hotspot that is on only when you need it — it reduces the time during which the network is visible and reachable.

These are not advanced measures, and they cover most real-world cases. To put them into practice, there is the guide on how to secure your hotspot.

Protection checklist

  • ☐ The hotspot password is at least 16 characters long and different from all your others
  • ☐ The password is changed periodically and after every occasional share
  • ☐ The network name is customised, with no first name, surname or phone model
  • ☐ The hotspot is never left open, not even for a few minutes
  • ☐ The hotspot is switched off when you do not need it
  • ☐ The list of connected devices is checked from time to time
  • ☐ File sharing is off and the firewall is on when your laptop uses the hotspot
  • ☐ The password is kept somewhere safe and never shown to anyone who does not need to see it

How this connects to the Cyber Welfare Framework

PillarWhat this content contributes
AwarenessUnderstanding that a hotspot is a network visible to anyone nearby, and that a shared password stops being secret over time
SkillsRecognising the mechanism of each attack from its signals, and telling a genuine network from a twin
Secure BehaviourChanging the password after every share and switching the hotspot on only when you need it

Reference level: FL3 — Autonomous, with elements of FL2 — Beginner in the sections on the password and on freeloading.

Conclusion

The attacks described here are rarely aimed at you in particular. They exploit a common situation: a network switched on among strangers, protected by a password that many people have come to know along the way.

That is why the most effective defence is also the simplest: a long, unique password, changed regularly, and a hotspot that goes off when you do not need it. Sharing your connection is still perfectly possible; you simply decide for how long.

To see where to start, the digital resilience self-assessment helps you take stock.

Something to think about. If you had to list everyone who knows your hotspot password today, could you say for certain where the list ends?

Related resources

Short pieces from the Resources section, for anyone who wants to focus on a single aspect:

Related content

Start with the first step: the Cyber Welfare Programme guides you free of charge, one recommendation at a time.