TL;DR: A man-in-the-middle attack is when an attacker secretly intercepts communication between two parties — often over unsecured WiFi — to eavesdrop or alter the data being sent. Avoid entering sensitive information on public WiFi, use a VPN when on networks you don't control, and make sure websites you use show "https" with a valid certificate.
A man-in-the-middle attack is when an attacker secretly intercepts communication between two parties — often over unsecured WiFi — to eavesdrop or alter the data being sent.
How Man-in-the-Middle Attacks Works
On an unsecured public WiFi network, an attacker can position themselves between your device and the internet, capturing unencrypted data like login credentials, or redirecting you to fake versions of real websites.
Warning Signs to Watch For
A website warning about an invalid security certificate, unexpectedly being logged out of accounts on public WiFi, and a network name that looks slightly off or duplicated.
How to Protect Yourself
Avoid entering sensitive information on public WiFi, use a VPN when on networks you don't control, and make sure websites you use show "https" with a valid certificate.
If this looks similar to something else you've seen, it's worth reading What Is Money Mule Scams? How It Works and How to Protect Yourself.
This pattern shows up elsewhere too — see What Is Pig Butchering Scams? How It Works and How to Protect Yourself.
Frequently Asked Questions
What is Man-in-the-Middle Attacks?
A man-in-the-middle attack is when an attacker secretly intercepts communication between two parties — often over unsecured WiFi — to eavesdrop or alter the data being sent.
How does Man-in-the-Middle Attacks typically work?
On an unsecured public WiFi network, an attacker can position themselves between your device and the internet, capturing unencrypted data like login credentials, or redirecting you to fake versions of real websites.
What are the warning signs of Man-in-the-Middle Attacks?
A website warning about an invalid security certificate, unexpectedly being logged out of accounts on public WiFi, and a network name that looks slightly off or duplicated.
How can I protect myself from Man-in-the-Middle Attacks?
Avoid entering sensitive information on public WiFi, use a VPN when on networks you don't control, and make sure websites you use show "https" with a valid certificate.
What should I do if I think I’ve encountered Man-in-the-Middle Attacks?
Stop responding immediately, do not click any links or share information, and report it to the appropriate authority. If money or personal information was already shared, act quickly to secure your accounts and report the incident.