Wi-Fi attacks have changed dramatically over the past 25 years. Early attackers exploited weaknesses in wireless encryption to recover network keys and gain access. As Wi-Fi security improved, attackers shifted their attention to passwords, authentication processes, client behavior, protocol logic, configuration weaknesses, and trusted network identities.
More recent attacks have gone even further. Attackers have used rogue access points to impersonate trusted networks, positioned attack equipment near targeted facilities, and compromised neighboring organizations to gain wireless proximity to targets they could not reach directly.
History matters not because enterprises should expect attackers to revive every old exploit, but because each generation of Wi-Fi attacks shows how adversaries shift to a different layer when defenders close an earlier path. Improving one layer of Wi-Fi protection does not eliminate the attack surface. It changes where attackers look for their next opportunity.
Breaking the Encryption: WEP
The first major lesson in Wi-Fi security came from Wired Equivalent Privacy, better known as WEP. WEP attempted to protect early wireless networks, but weaknesses in its cryptographic design enabled practical attacks.
Attackers could collect wireless traffic and analyze repeated initialization vectors associated with the same encryption key. They could also inject traffic to accelerate the process. As attack techniques improved, readily available hardware and software could quickly recover WEP keys. Once attackers obtained the key, they could potentially join the network, decrypt communications, and transmit traffic as authorized participants.
The weakness had consequences beyond security research. Attackers exploited poorly protected wireless networks during some of the early large-scale retail data breaches, showing how an attack launched from outside a building could ultimately expose internal systems and payment data. The WEP era taught a lesson that still applies today: organizations cannot treat Wi-Fi encryption as proof that a wireless network is secure.
Attacking the Credential: WPA and WPA2
The industry introduced Wi-Fi Protected Access, or WPA, in response to WEP’s weaknesses and later transitioned to the stronger WPA2 standard. As encryption improved, attackers increasingly shifted their focus from breaking encryption algorithms to attacking the credentials and authentication processes that controlled network access. WPA and WPA2 Personal networks always rely on a shared passphrase from which cryptographic key material is derived. All authorized devices generally use the same shared credential to access the network.
During the connection process, the client and access point complete a four-way handshake that establishes the cryptographic keys used for communications. With WPA2 Personal, an attacker who captures the required handshake information can test password guesses offline. That distinction matters because the attacker does not need to submit passwords to the access point repeatedly. Automated tools can test large numbers of candidate passwords against the captured information without interacting with the network again.
Human password habits can make this approach very effective. Attackers can start with credentials exposed in previous data breaches, common passwords, dictionary words, and predictable variations. A sufficiently long, randomly generated passphrase can make offline password guessing impractical. Enterprise authentication offers another important advantage: organizations can authenticate individual users or devices rather than distribute a single shared credential across many endpoints.
Attacking Trust: Evil Twin Access Points
Stronger encryption forced attackers to change tactics. Instead of breaking the legitimate access point, an attacker could attempt to convince the victim to connect to an attacker-controlled network. An evil twin is a rogue access point that impersonates a network the victim may connect to. The attacker may configure the rogue access point with the same network name (service set identifier, or SSID) as a legitimate network and attempt to attract devices searching for that network.
Early Wi-Fi clients made these attacks particularly effective because devices frequently searched for networks they had previously joined. Attack techniques such as KARMA exploited this behavior by listening for those requests and responding as the requested network. Later techniques such as MANA expanded the approach. Attackers could track networks that individual clients attempted to find and create more convincing responses designed to attract those devices.
Operating systems and Wi-Fi vendors have changed client behavior in response to these techniques, including modifications to network discovery and greater use of MAC address randomization. But the underlying concept remains relevant: attackers don’t always need to defeat a trusted network when they can impersonate it. This creates both an authentication problem and a visibility problem. Security teams need to distinguish legitimate corporate Wi-Fi infrastructure from unauthorized or attacker-controlled access points operating nearby.
Why Earlier Security Tactics Were Ineffective
Organizations have historically tried to reduce wireless exposure by hiding network names or restricting access by device MAC address. Neither provides strong security. An access point with a hidden SSID still participates in wireless communications. Clients must exchange information that allows them to locate and connect to the network. Someone monitoring nearby Wi-Fi activity can therefore discover the network name when legitimate clients attempt to connect.
MAC address allowlists have similar limitations. Nearby observers can identify addresses associated with authorized wireless devices and potentially attempt to impersonate one. Organizations should not treat either technique as a substitute for strong authentication, current encryption standards, segmentation, patching, logging, and wireless monitoring.
Attacking Convenience: WPS
Wi-Fi Protected Setup, or WPS, illustrates how convenience features can unintentionally create new security weaknesses. WPS was intended to simplify connecting devices to wireless networks. One implementation used an eight-digit PIN instead of requiring users to enter a potentially complex Wi-Fi password.
Eight digits theoretically provide 100 million possible combinations. However, the WPS authentication process validated portions of the PIN separately, while the final digit served as a checksum. That design dramatically reduced the number of combinations an attacker needed to test. The number of effective combinations is only 11,000, and attackers can brute-force it in minutes to hours. Other attacks on the random number generation in specific implementations can be completed in minutes.
Some implementations also lacked effective rate limiting, allowing automated tools to attempt PIN combinations rapidly. It would take an attacker minutes to hours to crack a PIN and join the network. WPS exposed a recurring cybersecurity problem. A strong underlying security architecture can still become vulnerable when a simpler authentication mechanism creates an alternative path around it.
Attacking the Protocol: KRACK
The 2017 Key Reinstallation Attack, commonly known as KRACK, demonstrated that attackers could target the protocol logic surrounding encryption rather than the encryption algorithm itself. KRACK targeted how Wi-Fi clients installed encryption keys during the four-way handshake. Under certain conditions, an attacker could cause a client to reinstall an existing key and reset associated counters that should not have been reused.
Depending on the implementation and encryption mode, the resulting behavior could support replay, packet manipulation, or related attacks. KRACK reinforced an important lesson: strong cryptography alone does not make a protocol secure. The software and state machines that establish and manage cryptographic keys must also handle unexpected and deliberately manipulated conditions correctly. Additionally, assuming the specifications are cryptographically sound, the vendor must implement them correctly and avoid introducing flaws. A vendor deploying a flawed chipset can have wide-reaching effects.
PMKID Attacks Changed the Password-Cracking Process
Another attack technique involving the Pairwise Master Key Identifier (PMKID) further demonstrated how implementation and protocol behavior can create unexpected opportunities. Traditional WPA2 Personal password attacks generally required attackers to capture information from a client completing the authentication process. Some access points, however, exposed a PMKID that attackers could use for offline password guessing. That meant an attacker did not need to wait for a legitimate client to complete a four-way handshake before beginning the attack.
The fundamental target remained the Wi-Fi password. A sufficiently strong, unpredictable passphrase made successful guessing much harder, but the technique removed one operational requirement of earlier attacks. For enterprises, attacks against shared credentials provide another reason to limit broadly distributed pre-shared keys and use stronger individual authentication where appropriate.
Attacking Proximity
Most Wi-Fi attacks face one apparent limitation: the attacker needs to be close enough to communicate with the target wirelessly. That requirement poses an obstacle, but attackers can circumvent it. Attackers can operate from vehicles, neighboring buildings, public areas, or other locations within Wi-Fi range. They can position wireless attack equipment closer to otherwise difficult-to-reach networks. They can also use high-gain directional antennas and high-powered adapters to increase their range. Physical distance therefore changes the difficulty of a Wi-Fi attack without necessarily eliminating the possibility. A more sophisticated technique takes this concept further.
Nearest Neighbor Attacks: Turning Someone Else’s Device into a Wireless Bridge
The “Nearest Neighbor Attack” demonstrates how an adversary can overcome Wi-Fi’s proximity requirement without physically approaching the ultimate target. In an attack disclosed by Volexity in 2024, the Russian state-sponsored threat actor GruesomeLarch, publicly associated with APT28 and Forest Blizzard, used compromised systems at neighboring organizations to reach its ultimate target’s enterprise Wi-Fi network.
The attackers possessed a set of usernames and passwords (possibly from a credential dump) for their intended target. They used a password spray attack against an externally facing employee web portal to confirm working combinations. However, they encountered MFA when attempting to use those credentials against the Internet-facing employee portal. They identified another possibility: the target’s corporate Wi-Fi authentication could accept the credentials without requiring the same MFA control. The problem was physical distance. The attackers were nowhere near the target’s wireless network.
Instead of approaching the target, they compromised nearby organizations. After gaining control of computers at neighboring businesses, the attackers identified systems with Wi-Fi adapters within RF range of the target network. A system connected to its own network via Ethernet could still have an available Wi-Fi interface. The attackers could then use the compromised computer as a remote wireless platform, effectively borrowing its physical location to communicate with the target’s Wi-Fi network. When the target reconfigured the Enterprise Wi-Fi network to stop the attack, the attackers pivoted to the open Guest network. Then they exploited poor network segmentation to re-enter the target network.
This technique changes the conventional understanding of wireless proximity. The attacker does not necessarily need to stand in the parking lot, enter the building, or place equipment next to the target. The attacker needs control of something that already has the required proximity. The nearest neighbor attack is particularly instructive because the attackers did not need to break Wi-Fi encryption. They combined valid credentials, an authentication gap, compromised endpoints, poor network segmentation, and wireless proximity to reach the target network.
It also illustrates how Wi-Fi security intersects with identity, endpoint security, MFA, network architecture, and the surrounding wireless environment. An organization can secure its Internet-facing authentication paths while leaving another authentication path available via Wi-Fi. The investigation also highlighted the value of wireless telemetry. Wireless controller and authentication logs ultimately helped investigators connect the attacker’s activity to specific accounts, devices, and access points.
WPA3 Raises the Barrier
WPA3 addresses several weaknesses associated with earlier Wi-Fi security mechanisms. WPA3-Personal uses Simultaneous Authentication of Equals, or SAE, instead of WPA2-Personal’s PSK-based authentication mechanism. SAE eliminated the offline password-guessing attacks associated with WPA2-Personal. WPA3 also introduced stronger protections for compatible open Wi-Fi environments, allowing wireless communications to receive encryption even when users do not enter a traditional shared password.
Migration, however, creates its own challenges. Organizations may operate WPA2/WPA3 transition environments because older devices lack WPA3 support. Supporting older security modes can preserve exposure associated with those modes. WPA3 significantly strengthens Wi-Fi security, but it does not eliminate vulnerabilities in implementations, configurations, clients, or other wireless environment components. Security teams should evaluate whether compatibility requirements justify maintaining legacy configurations and isolate older devices when business requirements prevent immediate replacement.
Wi-Fi Security Requires More Than Strong Encryption
Nearly three decades of development have made Wi-Fi a mature technology with substantially stronger security than its early implementations. That does not mean organizations should focus primarily on the latest vulnerabilities and protocol exploits.
Everyday configuration problems can create more practical opportunities. Weak shared passwords, obsolete security protocols, poorly segmented networks, unpatched access points, vulnerable clients, and unnecessary legacy compatibility can expose organizations without requiring sophisticated attack techniques.
Logging also deserves attention. Wi-Fi has become a fundamental component of enterprise infrastructure. Still, organizations may not integrate wireless authentication and connection activity into the same monitoring and investigation processes they use for other network systems. That gap particularly matters when an attacker enters through Wi-Fi. Without sufficient wireless telemetry, investigators may see suspicious activity after network access occurs, without understanding how the attacker obtained it.
The evolution of Wi-Fi attacks illustrates why strong encryption alone cannot address every part of the attack surface. Attackers first targeted encryption. They then targeted passwords, client trust, convenience mechanisms, protocol behavior, and eventually physical proximity. This progression means security teams must consider the surrounding Wi-Fi environment rather than focusing solely on the security configuration of authorized access points.
Reducing the Risk of Wi-Fi Attacks
Organizations can reduce Wi-Fi exposure by combining strong wireless security configurations with the broader controls already used to protect enterprise infrastructure. Organizations should use current Wi-Fi security standards supported by their device environments and phase out obsolete protocols and unnecessary legacy compatibility. Enterprise Wi-Fi networks should favor individual or certificate-based authentication over widely distributed shared credentials where appropriate, while strong, unpredictable passphrases remain important wherever shared credentials are necessary.
Segmentation can limit the access available from guest, IoT, legacy, and other wireless environments. Access points, controllers, and wireless clients also require regular security updates because vulnerabilities can exist in both infrastructure and endpoint implementations.
Wireless authentication, connection, and infrastructure telemetry should feed into broader security monitoring and investigation processes. Security teams also need visibility into unauthorized access points, unexpected SSIDs, and other wireless communications that may indicate activity outside the organization’s expected Wi-Fi environment.
Extending Security Visibility to Wi-Fi
Network security controls provide extensive visibility once wireless communications enter managed network infrastructure. Wi-Fi attacks, however, can begin in the RF environment before that traffic reaches a switch, firewall, or other conventional monitoring point.
An evil twin impersonating a corporate SSID illustrates the distinction. The security question is not simply whether traffic entering the corporate network appears malicious. The evil twin and any connected clients never communicate over the monitored infrastructure, making them invisible to the existing network monitoring solution. Security teams first need to recognize that an unauthorized access point is operating nearby and presenting itself as trusted infrastructure.
Bastille provides 100% passive monitoring of the RF spectrum, with Wi-Fi coverage extending to 7.125 GHz, and uses patented algorithms and analysis to identify and locate wireless devices. This visibility gives security teams another telemetry source to identify unauthorized or potentially malicious Wi-Fi activity and investigate wireless events alongside broader security operations.
Wi-Fi Attacks Keep Changing
Wi-Fi security has improved considerably since attackers could quickly compromise networks protected by WEP. Modern encryption, stronger authentication, improved client behavior, and more mature security standards have closed many of the easiest attack paths.
But stronger Wi-Fi security has repeatedly changed the attacker’s strategy rather than eliminating the attack surface. Nearest neighbor attacks provide a particularly striking example, showing that sophisticated adversaries can circumvent the geographic limitations traditionally associated with wireless attacks.
Organizations should therefore treat Wi-Fi as an active component of the enterprise attack surface. Strong authentication, current hardware and software, segmentation, logging, endpoint security, and continuous wireless visibility all help reduce that exposure.
The question is no longer simply whether an organization’s Wi-Fi uses strong encryption. Security teams also need to know what is happening in the wireless environment around it.