How to Safely Use Public Wi-Fi at Cafes and Airports — 6 Habits That Block Hacking
Free Wi-Fi at cafes, airports, and hotels is convenient, but because of the structural fact that your traffic passes through the same space as many other people, security risks come with it. Still, if you understand the principles and keep just a few habits, you can actually block most of the danger. This article isn't fear-mongering that says "never use it" — it's a concrete guide to why it's risky and exactly what to check and how.

Three Attack Principles You Should Know First
The dangers of public Wi-Fi mostly stem from three methods. Packet sniffing is secretly eavesdropping on data passing through the same network; unencrypted traffic is exposed in plain sight, like a postcard. A man-in-the-middle attack is when an attacker secretly wedges in between you and a site to peek at or swap the information going back and forth. An evil twin is a fake access point created with the exact same name as the real venue's Wi-Fi, luring people to connect to it themselves. The habits below are meant to neutralize each of these three.
1. Before Connecting, Check the Network Name First
An evil twin uses a plausible name like "Free_Cafe_WiFi." Before connecting, ask a staff member for the exact network name (SSID). If the same name appears two or more times, or a place that usually had a password has suddenly become open, be suspicious. It's also a warning sign if, right after connecting, an unfamiliar prompt pops up demanding login or payment information.
2. Check the Padlock (HTTPS) in the Address Bar
On login and payment screens, always check that the address starts with https://. The padlock or "secure connection" icon shown at the far left of the browser's address bar is that indicator. HTTPS encrypts the link between your device and the site so that even if someone eavesdrops in the middle, they can't make out the contents. Conversely, on sites without a padlock or showing a "Not Secure" warning, don't enter passwords or card numbers. In particular, if a certificate error warning appears, don't ignore it and click through — it can be a sign of a man-in-the-middle attack.

3. Do Banking and Important Logins on Cellular
For high-stakes tasks like banking apps, brokerage, and government-office logins, handle them on mobile data (LTE/5G) whenever possible. A carrier's data network is encrypted at the cell-tower level, making it far harder to eavesdrop on than public Wi-Fi. If it's not urgent, it's safer to wait until you're back on a trusted network at home or the office.
4. A VPN Adds Another Layer
A VPN wraps all of your traffic in an encrypted tunnel, protecting even apps and traffic that don't use HTTPS. It's especially useful on public Wi-Fi. That said, a VPN provider ends up holding the chokepoint your traffic passes through, so it's important to choose a trustworthy service with a transparent privacy policy. Some free services actually collect and sell your usage records, so check the terms.
5. Turn Off Auto-Connect and File Sharing
If you leave your device set to auto-connect to Wi-Fi names it knows, you can end up connecting to an evil twin using the same name without realizing it. On iPhone you can turn it off under "Settings › Wi-Fi › the network › turn off Auto-Join," and on Android under "Settings › Connections › Wi-Fi › Saved networks › disable auto-connect." Also, at cafes and airports, temporarily turn off file sharing (AirDrop / Nearby Share). That completely blocks connection attempts from strangers.
6. When You're Done, "Forget" the Network
When you finish, remove that Wi-Fi from your saved list (forget the network) so it doesn't automatically reconnect next time. This small habit prevents repeated exposure when you pass through the same place again.

These Situations Are Especially Risky
On the same public Wi-Fi, the size of the risk differs depending on what you do. Be extra careful in the situations below.
- Banking/brokerage login and transfers — if even your security-card numbers or OTP are exposed, it leads directly to financial loss. Switch to cellular.
- Online payments and entering card numbers — check the padlock and the exact site address, and close any unfamiliar payment window.
- Logging in to public-agency or company accounts — if one is breached, the damage can spread to several linked services.
- Reusing the same password in many places — if just one leaks, all of them are at risk.
If You've Already Been Hit, What to Do
If you connected to a suspicious access point or suspect your information leaked, don't give up as if it's too late — take action in order.
- Switch to a safe network immediately — move to cellular or a trusted Wi-Fi, then start taking action.
- Change your important account passwords first — change them in the order of banking, email, and major portals, and also replace them anywhere else you used the same password.
- Turn on two-factor authentication — even if your password leaks, an extra verification step can block the login.
- Check payment and transaction history — review recent card and account activity, and report any abnormal payments to the card company immediately.
- Inspect your device — check whether any unfamiliar apps or profiles were installed, and run an antivirus scan if needed.
- If actual harm occurred — you can seek help from the Korea Internet & Security Agency (KISA) 118 counseling center or the police cybercrime reporting channel.
Frequently Asked Questions (FAQ)
Is password-protected public Wi-Fi safe?
A password makes it harder for just anyone to connect, but it's not completely safe from other users who know the same password. A password posted publicly in a venue is effectively little different from an open network, so it's best to keep up the habit of checking HTTPS.
If I just check HTTPS, do I not need a VPN?
HTTPS protects the contents of website traffic, but some information such as the address of the site you're visiting can still be exposed, and some apps don't use HTTPS. Think of a VPN as a supplement that covers those gaps too. The two aren't substitutes — they're a good combination used together.
My smartphone connects to Wi-Fi automatically — is that okay?
Automatically reconnecting to a name you've connected to before is the default behavior. It's convenient, but there's a risk of connecting to a fake access point using the same name, so it's safer to turn off auto-connect and forget the network after use.
To sum up, the three keys are: check the name, check the HTTPS padlock, and do important logins on cellular. If you treat public Wi-Fi on the premise that "someone may be watching," you can enjoy the convenience just as it is while avoiding most of the risk.
All content is fact-checked under our editorial standards.