Man-in-the-middle attack
An attack where the attacker secretly inserts themselves into a conversation and can intercept or alter data.
In a man-in-the-middle (MitM) attack, the attacker secretly inserts themselves into a conversation between two parties and can intercept or alter data. Typical scenario: open Wi-Fi with a spoofed access point.
Protection: verify HTTPS connections (valid certificate), only bank from trusted networks – or via a VPN.
Why this matters in 2026
Classic MitM attacks on open Wi-Fi have become rare in 2026 because almost every website uses HSTS and HTTPS Strict Transport Security. Real risks remain: compromised routers (default passwords), spoofed Wi-Fi hotspots with similar SSIDs ("Free_Airport_WiFi") and tampered DNS servers – a user-side VPN helps against all of them.
How to protect yourself
On public Wi-Fi always enable a VPN (NordVPN, ProtonVPN, Mullvad). Set the browser to "Always use HTTPS". On strange certificate warnings, abort immediately – never click "Continue anyway". Your own router: update the firmware regularly, change default password and default SSID.