Why you need a VPN on public Wi-Fi

TL;DR, the essentials
- On an open public Wi-Fi network, you share the connection with strangers. The two most concrete threats in 2026 are the evil twin hotspot and the interception of unencrypted traffic.
- A VPN builds an encrypted tunnel between your device and a remote server. Even on a rigged network, an attacker only sees an unreadable stream.
- HTTPS already protects most of your browsing, but a VPN plugs the gaps (badly coded apps, DNS lookups, fake networks). It does not make you anonymous, though.
A train station, an airport, a hotel, a coffee shop: everywhere you go, a free public Wi-Fi network is waiting. Convenient, but these open networks are also a favorite playground for bad actors. The good news is that a VPN on public Wi-Fi neutralizes most of the risk, as long as you understand what it actually protects and what it does not. Here are the real threats, exactly how the encryption works, and the smart habits to adopt when you travel.
What are the real risks of public Wi-Fi?
Let’s be honest up front: public Wi-Fi is far safer than it was ten years ago. Today, more than 95% of web traffic runs over HTTPS, browsers warn you about unsecured sites, and banking apps are built to resist hostile networks. The old line, “anyone can steal your password on the coffee shop Wi-Fi,” is largely outdated. But two attack vectors are still very much alive, and that is exactly where a VPN earns its place. Here is how an open network exposes you, step by step.
You join a network you don’t control
On open Wi-Fi, no key encrypts the link between your device and the access point. You share the network segment with everyone else connected, including anyone snooping with easy-to-find monitoring tools.
Part of your traffic can leak in the clear
Anything that isn’t encrypted (some legacy apps, connected devices, DNS lookups) travels in plain view. An observer on the same network can then see which domains you contact, even if they can’t always read the content.
An attacker can slip between you and the internet
Fake hotspot or automatic reconnection to a known network: several techniques let someone position themselves in the middle. That is the exact window a VPN’s encrypted tunnel closes.
Keep this in mind: the danger comes less from the cafe itself than from the possibility that a third party manipulates the network. Let’s break down the two most common techniques.

The evil twin hotspot, the number one threat
This is the most concrete attack in 2026. The idea: an attacker sets up a portable access point and names it exactly like the legitimate network, for example “Airport_Free_WiFi” or “Hotel_Guest”. Your phone, which can’t tell the real from the fake, connects to it, sometimes automatically. All your traffic then flows through the attacker’s machine, which can observe, redirect, or try to trap your connections through a fake captive portal.
The habit that costs nothing
Before you connect, ask a staff member for the exact name of the official network. It’s the simplest and most effective defense against the evil twin. Also disable automatic connection to open networks in your device settings.
Interception and the man-in-the-middle attack
A man-in-the-middle attack refers to any situation where an attacker inserts themselves between you and the service you’re using. On a network they don’t control, they can try to eavesdrop on your exchanges, inject content, or redirect you to a fake page to capture a login. Here again, HTTPS blocks a large share of these attempts, but not all: DNS lookups (which reveal the sites you visit), poorly configured apps, and connected devices remain exploitable weak spots on a rigged network.
Travel often?
Our comparison ranks the 5 best VPNs of 2026, tested for speed, security, and auto-connect on untrusted networks.
If HTTPS already encrypts, is a VPN really useful?
Good question, and the answer is nuanced. HTTPS encrypts the content exchanged with a properly configured site. On that traffic, a VPN adds little extra protection. But it plugs the blind spots HTTPS leaves open:
- It hides your DNS lookups and every domain you contact, invisible to the network operator.
- It protects apps and connected devices that encrypt their traffic poorly, or not at all.
- On an evil twin hotspot, the attacker only captures an encrypted stream to the VPN server, not the details of your activity.
- It encrypts all of the device’s traffic at once, without depending on the quality of each individual app.
VPN and HTTPS are teammates
They aren’t rivals. HTTPS secures the conversation with each site, while the VPN secures and hides the whole connection on a network you don’t control. To understand how the tunnel works in detail, our VPN hub breaks down the mechanics.
How a VPN encrypts and protects your connection
As soon as you turn it on, the VPN app establishes an encrypted tunnel between your device and a remote server. In practice, your data is wrapped in a layer of encryption (AES-256 or ChaCha20 depending on the protocol) before it even leaves your phone or laptop. On public Wi-Fi, the person snooping on the network, or the one running a fake hotspot, only sees an unreadable stream heading to the VPN server. There is no way to extract your passwords, your emails, or your work logins.
Two details make the difference on the move. First, the kill switch: if the tunnel drops (network change, outage), it instantly blocks all connections to prevent any leak in the clear. Second, auto-connect on untrusted networks: on iOS and Android, you can set the VPN to switch on by itself the moment you join an unknown Wi-Fi. That’s essential, because the window of risk sits precisely between the moment you join the network and the moment the VPN starts.
Turn the VPN on before, not after
Open the VPN app before you connect to the Wi-Fi, or enable auto-connect on untrusted networks. That removes the exposure window between plugging in and the tunnel coming up.
Smart habits on public Wi-Fi
The VPN is the centerpiece, but a few simple habits sharply reinforce your security when you’re out and about:
- Check the network name with a staff member before connecting, to rule out the evil twin.
- Disable auto-connect and file sharing while you’re traveling.
- Make your device forget the network once you leave, to avoid silent reconnections.
- Keep your system and apps up to date: many network attacks exploit flaws that are already patched.
- When in doubt, use your mobile hotspot (4G/5G), which is far harder to intercept than open Wi-Fi.
- Turn on a reputable VPN with a kill switch, ideally with auto-connect on untrusted networks.
On a network you don’t control, assume someone can watch, and encrypt everything.
Ready to secure your trips?
We compared prices, speeds, kill switch, and auto-connect across the best offers of the moment.
What a VPN does NOT do on public Wi-Fi
The honesty section, and it matters. A VPN is an excellent network shield, but it has real limits:
- It does not make you anonymous. It hides your activity from the local network and your internet provider, but the VPN provider itself sees your traffic pass through. Hence the importance of a genuinely audited no-log policy.
- It does not replace antivirus or common sense: it won’t protect you if you download a booby-trapped file or enter your credentials on a fake page (phishing).
- A shady free VPN can be worse than nothing: you’d be handing all your traffic to an unknown company. On that front, trust in the provider is everything.
- It doesn’t protect you from risks tied to your own identification: logged into your accounts, you stay identifiable, VPN or not.
Choose your provider carefully
A VPN moves trust from the public network to the VPN provider. Favor a no-log policy audited by an independent firm and avoid opaque free services. To compare on that criterion, see our VPN hub.
The next step
Want to install one for your travels? Check our comparison of the best VPNs of 2026, or explore the rest of our VPN guides and reviews.
Frequently asked questions
Do you really need a VPN on public Wi-Fi?
Yes, it’s the strongest use case for a VPN. On an open network you don’t control, a VPN encrypts all of your traffic and protects you from evil twin hotspots and interception. HTTPS already covers part of the risk, but the VPN plugs the blind spots (DNS lookups, poorly encrypted apps, fake networks) and hides your activity from the local network.
What is an evil twin hotspot?
It’s a Wi-Fi access point created by an attacker and named exactly like a legitimate network, for example an airport or hotel one. Your device connects to it without telling the real one from the fake, and all your traffic then flows through the attacker’s machine. Checking the exact network name with a staff member and turning on a VPN are the best defenses.
Isn’t HTTPS enough to protect me?
HTTPS encrypts the content exchanged with well-configured sites, which covers most of your browsing. But it leaves blind spots: DNS lookups reveal the domains you visit, some apps and connected devices encrypt poorly, and a fake hotspot can try to redirect you. A VPN encrypts all of the device’s traffic at once, on top of HTTPS.
When should you turn on the VPN on a public network?
Ideally before you join the network, or via the auto-connect on untrusted networks feature available on iOS and Android. The exposure window sits between the moment you connect to the Wi-Fi and the moment the VPN tunnel starts. A kill switch also prevents any leak if the VPN connection drops.
Does a free VPN protect you on public Wi-Fi?
Be careful. A VPN shifts trust to its provider, and many opaque free services fund themselves by reselling your data. A shady free VPN can therefore be worse than no VPN at all. Proton VPN Free is an exception, with an audited no-log policy. For regular use on the move, a reputable paid VPN at a few dollars a month is still the better choice.