The Guardia Civil has issued a warning over the dangers of connecting to free public WiFi networks in Spain.
In a message shared on social media on Tuesday, the force warned that criminals can create convincing copies of legitimate networks in cafes, train stations, airports and shopping centres.
These fraudulent connections often use names that are almost identical to the venue’s official network, making them difficult to spot at first glance.
‘Free WiFi. Perfect… or not?’ the Guardia Civil wrote.
It added: ‘Just because WiFi is free does not mean you should pay for it with your data.’
The warning is particularly relevant for tourists and foreign residents who may rely on public internet connections to avoid roaming charges or poor mobile coverage.
How the scam works
The technique is commonly known as an ‘evil twin’ attack.
A criminal creates a wireless network designed to imitate a genuine connection nearby.
For example, while a hotel’s official network might be called ‘Hotel_Guest’, the fraudulent version could appear as ‘Hotel_Guests’, ‘Hotel_Free_WiFi’ or another small variation.
Because the false network is controlled by the attacker, they may be able to monitor certain information passing through it or direct victims towards fake websites.
Spain’s National Cybersecurity Institute, known as INCIBE, says such networks are frequently created in busy places where free public WiFi is already available.
The objective can be to steal banking details, email passwords or social media credentials, or to lead users towards fraudulent websites and malicious downloads.
Some fake networks also display a convincing-looking login page asking the user to enter an email address, password, telephone number or payment-card information before being granted access.
Guardia Civil tips
Before connecting, the Guardia Civil says users should ask a member of staff to confirm the precise name of the venue’s official network.
The force advises people to avoid open networks of unknown origin, particularly when several connections with nearly identical names appear on their device.
Users should not access online banking, make purchases or enter passwords and other sensitive information if they have any doubts about the connection.
For important transactions, the Guardia Civil recommends switching off WiFi and using the phone’s 4G or 5G mobile-data connection instead.
INCIBE additionally recommends using a reputable virtual private network, or VPN, when a public connection cannot be avoided. A VPN encrypts the connection between the device and the VPN provider, making it harder for someone on the same network to intercept the user’s activity.
Once finished, users are advised to disconnect from the network and remove it from the list of saved connections on their phone, tablet or laptop.
Automatic connection to open networks should also be disabled. Otherwise, a device could reconnect to a similarly named network in the future without its owner actively selecting it.
Phones and computers should be kept updated, while two-step verification should be enabled on important accounts wherever possible.
Although seeing ‘https’ and a padlock in the browser remains important, it does not by itself guarantee that a website is genuine. Fraudsters can also obtain security certificates for convincing copies of banking, email and shopping websites, so the address itself should always be checked carefully.
Anyone who believes they may have entered information while connected to a fraudulent network should immediately disconnect from it and use a trusted connection to change the passwords of any affected accounts.
If banking or card details were entered, the relevant bank should be contacted as quickly as possible. Recent transactions should also be checked for any activity that is not recognised.
Spain’s cybersecurity helpline can be reached by calling 017, a free and confidential service operated by INCIBE for members of the public and businesses seeking advice about online threats.
