A Wi-Fi Security Briefing from Anaptyx

Every time someone opens their laptop in a coffee shop, city hall lobby, public library or downtown park and taps "Connect" on a Wi-Fi network that looks familiar, they are making a trust decision. Most of the time that trust is well placed. Increasingly, it isn't. As public Wi-Fi becomes a standard amenity in municipal buildings, transit hubs, libraries, and downtown districts, it has also become one of the most exploitable attack surfaces in local government IT. The technique responsible for much of that exploitation has a deceptively simple name: the evil twin attack.

What Is an Evil Twin Attack?

An evil twin attack works by impersonation. An attacker sets up a wireless access point that broadcasts the same network name, or SSID, as a legitimate public Wi-Fi network — "CityHall-Guest," "Library-Free-WiFi," "DowntownFreeWiFi" — and positions it within range of unsuspecting users. Because most devices are configured to automatically reconnect to networks they recognize by name, and because the human eye has no way to distinguish one SSID from another, a device will often join the attacker's access point without any indication that anything is wrong.

Some evil twin attacks go a step further by using a deauthentication attack, sending forged signals that knock a victim's device off the legitimate network, so it is forced to search for and reconnect to any available network with a matching name — conveniently, the attacker's. Once a device is connected to the rogue access point, the attacker sits in the middle of every session that device initiates. Login credentials, session cookies, email traffic, and any unencrypted data can be captured. In more sophisticated versions of the attack, the rogue access point presents a convincing captive portal — a fake login page asking for a name, email address, or even payment card details — that looks identical to the real network's sign-in screen.

What makes evil twin attacks particularly dangerous is that they require no vulnerability in the target network itself. The legitimate network can be perfectly configured and still lose users to a nearby impersonator. It is a social and technical attack rolled into one, exploiting the fact that Wi-Fi trust is based entirely on a broadcast name that anyone with inexpensive hardware can copy.

Rogue Access Points and the Municipal Network Problem

Municipal Wi-Fi presents a uniquely attractive target for this kind of attack, and the reasons go beyond simple opportunism. Local government networks tend to serve a high volume of transient, unauthenticated users in physical spaces that are, by design, open to the public. A city council chamber, a permitting office, a public library, or a downtown Wi-Fi zone cannot restrict who walks in and opens a laptop. That openness, which is the whole point of the service, is also what makes it difficult to detect when an unauthorized access point appears nearby.

The consequences of a successful rogue access point on a municipal network extend well past an individual user's stolen password. Residents use these networks to pay utility bills, apply for permits, access benefits portals, and communicate with government staff — all of which can involve personally identifiable information, financial data, or credentials that unlock other municipal systems. City employees, contractors, and elected officials also frequently rely on public-facing guest networks for quick tasks, creating a path from a compromised guest connection toward more sensitive internal systems if the network is not properly isolated. And because municipal Wi-Fi is a visible, branded public service, a successful evil twin incident carries a reputational cost that private businesses rarely face in the same way: it becomes a matter of public trust in the local government itself, often reported in local news and raised at council meetings.

Municipal environments also tend to have physical characteristics that work in an attacker's favor. Government buildings, parks, and public plazas are open, frequently visited, and rarely monitored for unauthorized RF activity. A rogue access point can be placed in a backpack, a parked car, or a nearby building and left running for hours without drawing attention. Unlike a private office network protected by badge access and a receptionist, a public municipal Wi-Fi zone offers an attacker a low-risk vantage point with a steady stream of unsuspecting users.

Why Consumer-Grade Gear Leaves the Door Open

Many public and municipal Wi-Fi deployments still run on equipment provided or recommended by a local internet service provider: an off-the-shelf router or access point intended for home or small-office use, connected with default or minimally adjusted settings. This equipment is not built with rogue access point detection, network segmentation, or wireless intrusion monitoring in mind — because it was never designed to serve hundreds of anonymous public users a day. It was designed to serve a household.

The gap this creates is both technical and operational. On the technical side, consumer-grade gear typically lacks wireless intrusion detection capability, meaning there is no system watching for a suspicious SSID broadcasting nearby or flagging abnormal deauthentication traffic. It usually runs on a flat network architecture, where guest traffic and administrative or internal traffic share the same broadcast domain, so a single compromised device has a more direct path toward sensitive systems. And it is frequently left running older WPA2 encryption with a shared passphrase — a configuration vulnerable to offline password-cracking attacks and incapable of giving each user a truly private, individually encrypted session.

On the operational side, the gap is just as significant. Consumer routers and ISP-provided gear are rarely monitored continuously, rarely patched on a defined schedule, and rarely audited for configuration drift. Firmware updates, when they happen at all, depend on someone remembering to check for them. There is no one watching the RF spectrum for a second network impersonating the first. In short: the hardware works, in the narrow sense that it provides internet access, but it was never built to defend against the kind of impersonation and interception that evil twin attacks depend on.

How Managed Segmentation and WPA3 Close the Gap

Closing this gap requires two things working together: a modern security standard on the wireless protocol itself, and disciplined network architecture behind it. Neither one alone is sufficient.

WPA3, the current generation of Wi-Fi security, directly addresses several of the weaknesses evil twin attacks exploit. Its Simultaneous Authentication of Equals handshake replaces the older four-way handshake that made WPA2 networks vulnerable to offline dictionary attacks, meaning a captured handshake is far less useful to an attacker trying to crack a shared password. WPA3 also introduces individualized data encryption for open or guest networks through Opportunistic Wireless Encryption, so that even users on a shared public network without a password have their session traffic encrypted point to point rather than broadcast in the clear. Perhaps most relevant to evil twin attacks specifically, WPA3 mandates Protected Management Frames, which cryptographically sign the management traffic — including deauthentication frames — that attackers rely on to knock devices off a legitimate network and herd them toward a rogue twin. That single feature closes off one of the most common triggers for a successful evil twin attack.

But encryption standards alone cannot detect a rogue access point that mimics a legitimate SSID; they can only make the traffic on the legitimate network harder to intercept. That is where MSP-managed network segmentation completes the picture. A properly segmented municipal network separates guest Wi-Fi traffic from administrative, public safety, and internal systems at the architectural level, so that even if a device is compromised on the guest network, there is no direct path to anything sensitive. Managed segmentation is paired with continuous wireless intrusion detection that actively scans the RF environment for unauthorized access points broadcasting familiar SSIDs, alerting IT staff in real time rather than leaving the discovery to chance or a citizen complaint. It includes centralized authentication and access control, scheduled firmware and security patching, and regular configuration audits to catch the kind of drift that turns a secure setup into a vulnerable one over months of neglect. Consumer-grade ISP equipment simply is not built to do any of this, because it was never designed for the threat model a public municipal network actually faces.

Why Anaptyx-Managed Wi-Fi Is the Standard Municipalities Need

Closing the evil twin gap is not a one-time configuration change; it is an ongoing discipline of monitoring, segmentation, and standards enforcement that most municipalities are not staffed to maintain in-house, and that consumer-grade ISP equipment was never built to support in the first place. Anaptyx has spent 20 years designing and managing Wi-Fi networks specifically for government, municipal, and public-facing environments, which means we understand the operational realities that come with serving thousands of anonymous users a day in open public spaces — from council chambers to libraries to downtown Wi-Fi districts. Our managed Wi-Fi solutions are built around WPA3 encryption, true network segmentation between guest and internal systems, continuous wireless intrusion monitoring to catch rogue access points before residents ever connect to them, and disciplined patch management that closes vulnerabilities as soon as they are known rather than whenever someone happens to notice. For a local government, the choice is not between convenience and security; it is between a network built for a household and a network built, monitored, and defended by a team that has spent two decades doing exactly this work for public agencies. That is the gap Anaptyx exists to close.

Anaptyx holds a 20-year GSA Multiple Awards Schedule 70 IT contract serving federal, state, and local government installations throughout the U.S.

www.anaptyx.com           Call: 1-800-454-5202