Free WiFi in airports, cafés, hotels, malls, and other public places can be useful when mobile data is unavailable. However, connecting to an unsecured network may also expose personal information, passwords, financial details, and private messages.
Cybersecurity company Kaspersky is urging Filipinos to be more careful when using public WiFi, particularly when logging into personal accounts or transmitting sensitive information.
“Free WiFi feels convenient, but it often comes at a hidden cost. Cybercriminals know that public networks require no authentication, making it easy for them to intercept data without users ever realizing it,” said Choon Hong Chee, head of consumer channel for Asia-Pacific at Kaspersky.
The warning follows public WiFi safety guidance issued by the Department of Information and Communications Technology (DICT), which cautioned that users of unsecured connections could become easier targets for hackers.
Avoid banking and other sensitive transactions
One of the safest precautions is to avoid accessing banking apps, digital wallets, online payment services, or other sensitive accounts while connected to public WiFi.
Information transmitted through an unsecured network may be vulnerable to interception, particularly when the website, application, or connection lacks adequate protection.
Users should also avoid making online purchases, submitting confidential documents, or sending information such as passwords, identification details, account numbers, and recovery codes.
“The DICT’s warning echoes exactly what we have been seeing in our own threat research. The moment you connect to an unsecured network, you may be exposing your passwords, banking details, and personal messages to anyone monitoring that connection,” Chee added.
Confirm that the network is legitimate
Before connecting, ask the establishment for the exact name of its official WiFi network. Cybercriminals can create fraudulent hotspots with names that resemble those of nearby hotels, cafés, airports, or businesses. Connecting to one of these networks may allow an attacker to monitor traffic or direct users to malicious websites.
Users should avoid networks with suspicious names, unexpected login pages, or requests for excessive personal information. Turning off the device’s automatic WiFi connection feature can also prevent it from joining unfamiliar networks without the user noticing.
Use a trusted VPN
A virtual private network, or VPN, encrypts internet traffic between the device and the VPN service. This added layer of protection can make it more difficult for someone monitoring the public network to read transmitted information. However, users should select a reputable VPN provider and understand its privacy policy, data-handling practices, and subscription terms.
A VPN does not eliminate every online risk. Users must still avoid suspicious links, fraudulent websites, unsafe downloads, and requests for sensitive information.
Strengthen account security
Strong and unique passwords can help limit the damage if one account is compromised.
Users should avoid reusing the same password across banking, email, social media, shopping, and work accounts. A trusted password manager can generate and store unique credentials more securely than saving them in a photo gallery or an unprotected notes application.
Two-factor authentication should also be enabled whenever available. This requires an additional verification step beyond the password, such as a temporary code, authentication app, passkey, or security key.
Kaspersky advises users not to log into accounts that lack two-factor authentication while connected to public WiFi unless absolutely necessary.
Keep devices and security software updated
Operating-system, browser, application, and cybersecurity updates often include patches for newly discovered vulnerabilities.
Installing updates promptly can reduce the risk of attackers exploiting known security weaknesses. Users should also keep their firewall enabled and run regular security scans using reputable cybersecurity software.
Downloading applications or updates while connected to an unfamiliar network should be avoided unless the source and connection are verified.
Turn off file sharing and nearby connections
File-sharing functions can make a device more visible to others connected to the same network.
Kaspersky recommends disabling file sharing and turning off AirDrop when these functions are not needed. Bluetooth and near-field communication, or NFC, may also be switched off in crowded public places to reduce unnecessary wireless exposure.
These functions can be enabled again when the user needs them in a trusted environment.
Be cautious with public USB chargers and QR codes
Public charging stations may present risks when a USB connection can transmit both power and data. A wall charger, personal power bank, or charge-only cable provides greater control over the connection.
Users should also examine QR codes before opening them. Codes placed in public areas can be replaced or covered with malicious versions that direct users to fraudulent login, payment, or download pages.
Before entering information, check the destination address and confirm that it belongs to the expected organization.
Use mobile data when possible
When sensitive information must be accessed outside the home or office, a personal mobile-data connection or secured mobile hotspot is generally preferable to an unfamiliar public network.
Travelers may also arrange a local SIM, roaming package, or eSIM before departure rather than relying entirely on free public WiFi.
Public WiFi should be used only when necessary, particularly when a secure alternative is available.
Log out and forget the network after use
After using a public network, users should log out of accounts they accessed and disconnect from the WiFi service.
The network can then be removed from the device’s saved connections to prevent automatic reconnection later.
Users who suspect that they entered information through an unsafe connection should change the affected passwords using a trusted network, review account activity, enable two-factor authentication, and contact the appropriate bank or service provider when financial information may have been exposed.
In Summary
Public WiFi offers convenient internet access, but unsecured or fraudulent networks may expose users to data interception, credential theft, malicious websites, and malware.
Before connecting, confirm the network name with the establishment, disable automatic connection, and avoid banking, online payments, and other sensitive activities. A trusted VPN, unique passwords, two-factor authentication, updated software, an active firewall, and disabled file sharing can provide additional protection.
For important transactions, a personal mobile-data connection or secured hotspot remains the safer option.