A wireless attack in which an attacker creates a fake access point that mimics a legitimate network name and appearance. Users connect believing it is safe, allowing the attacker to intercept traffic or capture credentials. It is a common deception technique in environments where users rely on familiar Wi-Fi names.
Expanded Definition
An evil twin attack is a wireless impersonation technique in which an attacker sets up a rogue access point that copies a legitimate network name, signal strength, login flow, or captive portal style. The goal is to make nearby users connect to the attacker’s network instead of the real one, so traffic can be observed, redirected, or used to capture credentials. In security terms, it is less about breaking encryption and more about exploiting user trust in familiar Wi-Fi identifiers and weak verification of the access point itself.
Definitions are broadly consistent across cybersecurity practice, but usage can vary when teams distinguish between a simple rogue AP, a deliberate spoofed SSID, and a fully staged man-in-the-middle setup. The operational point is the same: the attacker relies on visual or behavioural similarity rather than network ownership. The most common misapplication is treating any public Wi-Fi risk as an evil twin attack, which occurs when an open hotspot is assumed to be malicious even though no spoofed legitimate network is being impersonated.
Examples and Use Cases
Implementing defences against evil twin attacks rigorously often introduces usability friction, requiring organisations to weigh stronger connection verification against faster access for employees and guests.
- A café user joins “Guest_WiFi” after seeing a stronger signal than the venue’s real access point, then submits email credentials through a malicious captive portal.
- An employee working remotely connects to a cloned corporate SSID in a hotel, allowing the attacker to capture authentication tokens or redirect traffic to phishing pages.
- A conference attendee sees a network name that matches the event Wi-Fi and joins without confirming the access point’s legitimacy, exposing browsing activity to interception.
- A defender tests whether mobile devices trust SSID names alone or enforce stronger network validation such as certificate-based authentication and approved profiles.
- Incident responders correlate suspicious wireless activity with endpoint logs and wireless telemetry, then compare behaviour against guidance in CISA cyber threat advisories for similar access-point impersonation patterns.
Why It Matters for Security Teams
Evil twin attacks matter because they collapse the boundary between physical proximity and network trust. Once a user joins the rogue access point, the attacker may capture credentials, inject phishing content, or harvest session data before any endpoint control notices unusual behaviour. For security teams, the issue is not just wireless hygiene but assurance: organisations need to know whether a device is connected to the network it thinks it joined, and whether users have any reliable way to verify that network.
This term also intersects with identity security because wireless impersonation often becomes a credential theft path rather than a pure network event. In environments that depend on password-only access, a cloned SSID can quickly turn into account compromise, especially when users reuse credentials across services. Controls discussed in NIST SP 800-53 Rev 5 Security and Privacy Controls are relevant where access monitoring, authentication strength, and incident response need to close the gap between wireless access and identity assurance. Organisations typically encounter the real cost only after anomalous logins or data exposure follow a user’s connection to a fake network, at which point evil twin attack response becomes operationally unavoidable.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST SP 800-63 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AA-1 | Identity proofing and authentication strength help limit trust in spoofed wireless access. |
| NIST SP 800-53 Rev 5 | AC-17 | Remote and wireless access controls help reduce exposure to rogue access points. |
| NIST SP 800-63 | AAL2 | Authenticator assurance matters when evil twin attacks target credentials on captive portals. |
Require stronger authentication and network validation before users can trust a Wi-Fi connection.
Related resources from NHI Mgmt Group
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 1, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org