Public Wi-Fi Is Safer Than It Used to Be. Your Work Accounts Still Need Protection.

An employee opens a laptop at an airport, chooses the network that looks like the airport’s free Wi-Fi, and gets a page asking for an email address and password. It feels routine. A few minutes later, that employee may have a connection, but someone else may have their credentials.

For years, warnings about public Wi-Fi focused on a nearby attacker reading everything people sent across the network. According to a new article about the public Wi-Fi security risks of 2026 recently published by SQ magazine, that threat has changed. Most websites now use HTTPS, which encrypts information traveling between a browser and a website. The Federal Trade Commission says widespread encryption makes public Wi-Fi “usually safe.” But “usually safe” is not the same as knowing who operates the network you joined, or whether the page requesting your password is genuine.

Attackers no longer have to read your traffic

A fake hotspot can copy the name of a legitimate network. Once someone connects, it can display a convincing sign-in page and ask for an email or social media password. HTTPS does not help when a person willingly types credentials into a page controlled by an attacker.

This is not merely a theoretical scenario. Australian Federal Police investigated fake free Wi-Fi networks found at airports and on domestic flights. According to the case described in the SQ Magazine article, the operator used fraudulent pages to collect credentials. The attack depended on people trusting the network and its sign-in prompt, not on breaking website encryption.

That distinction matters for businesses. An employee might use the same account to reach email, cloud applications, and internal resources. A stolen password can become the starting point for a much larger incident, especially if the account lacks strong multifactor authentication or access controls.

Encryption protects a connection, not every decision

Seeing HTTPS in a browser is useful. It helps confirm that data is encrypted in transit to the site shown in the address bar. It does not prove that the site itself is trustworthy. The FTC warns that scammers also encrypt fake websites. A convincing page with a lock icon can still collect everything entered into it.

A VPN provides another layer when an employee must use a public network. It encrypts traffic between the device and the VPN service, reducing what someone on that network can observe. The NSA recommends a personal or corporate mobile hotspot instead of public Wi-Fi where practical, and a personal or corporate-provided VPN when public Wi-Fi is necessary. A VPN, however, cannot prevent someone from entering a password into a fraudulent portal.

Businesses therefore need to address two separate questions: How is the employee’s connection protected, and what can that employee’s account reach after signing in?

Make access decisions beyond the hotspot

For an organization supporting remote work, the network an employee happens to use should not determine whether they can reach everything inside the business. A zero trust network access approach can grant access to specific applications and resources based on identity and policy. That limits the reach of a compromised account and reduces the need to expose a broad internal network to every connected user.

ZTNA is not a cure for phishing. If an attacker obtains credentials, the organization still needs multifactor authentication, careful account recovery procedures, monitoring, and a way to revoke access quickly. Its value is in limiting what any successful sign-in can reach. A stolen account with permission to open one approved application presents a different exposure from an account with broad access to the company network.

For employees, the practical habits are straightforward. Confirm a hotspot’s name with the venue rather than trusting a familiar-looking name on a screen. Treat unexpected requests for an email or social media password as a warning sign. Use a trusted mobile hotspot when available. Keep devices updated, enable multifactor authentication, and report suspicious sign-in prompts to IT. The FTC recommends strong passwords, two-factor authentication, and current software as basic protections wherever people connect.

Public Wi-Fi has become safer in one important respect: routine interception of website logins is far harder than it once was. Attackers can still exploit the moment a person chooses a network, trusts a page, or signs in. For businesses, the answer is to protect the connection, help employees recognize deceptive prompts, and keep access to work resources as narrow as their jobs require.