Many people think a VPN is only needed where something is blocked — in Russia, China, Iran. That's a common misconception. Protection is also needed in countries with a completely free internet — when connecting to public Wi-Fi networks. The coffee machine in a café, a terminal in an airport, a free hotspot in a hotel, a network in a shopping mall — in each of these places your data can be intercepted with no censorship at all.

In this article we'll break down how the risks of public networks work, what scenarios attackers use and why a VPN solves the problem regardless of the country you're in.

Why public Wi-Fi is dangerous by nature

A public access point is an open network that anyone can connect to: other visitors, the venue owner and an attacker nearby alike. A Wi-Fi radio signal isn't confined to the café walls — it's picked up on the street, on the floor above, in a parked car across the road.

The main problem is that you don't control the network. You don't know who administers it, whether someone keeps a connection log, or whether your ISP is swapping out the network. On your home network you can set up encryption and be sure that only you and your household are connected to it. In a café — you can't. Traffic goes through a router that belongs to someone else, and that "someone" is physically able to read it.

Key idea

Censorship blocks access to resources — that's unpleasant but predictable. Public Wi-Fi can steal your data — passwords, correspondence, banking details. The first is a restriction, the second is a direct threat to your money and privacy.

What data can be intercepted

If you've connected to a foreign network without protection, everything that goes over the internet is at risk:

Attack scenarios: how it happens in practice

An attacker doesn't need sophisticated tools. Most attacks on public networks are carried out with programs available to anyone in a couple of minutes. Here are the main scenarios.

1. Traffic interception (sniffing)

The simplest and most common scenario. The attacker connects to the same open network as you and runs a sniffer — a program that "listens" to all traffic in range. On an unencrypted network they see your requests almost as clearly as if you were working at their computer.

In the past, literally everything was intercepted this way: passwords, logins, page contents. Now that most websites have moved to HTTPS, "bare" interception works less often, but it's still dangerous — especially for old websites, apps and devices that don't use encryption.

2. Fake access point (evil twin)

The attacker creates their own network with the same name as the legitimate one — for example, "Cafe_Free_WiFi". Devices often connect automatically to the access point with the stronger signal, and you won't even notice you're working through the attacker's router. All information — passwords, correspondence, files — goes through their equipment in plain text.

This scenario is especially dangerous in airports, hotels and train stations, where people are in a hurry and connect to the first network with a fitting name.

3. Fake bait page (captive portal)

When connecting to public Wi-Fi, an authorization page often appears: "Enter your phone number for access" or "Enter your email". The attacker can replace this page with their own version — with a field for entering your card number, "paying" for an hour of internet or logging into your email. You enter the data, the network "doesn't work", and your details are already in the attacker's hands.

4. Session hijacking

Even if you logged into a website over a secure connection, after login the server issues you a session token — a "pass" that confirms you're authorized. On a public network this token can be intercepted. With it, the attacker enters your account without a password — and you only find out when you notice something odd.

5. Interception via certificate substitution (Man-in-the-Middle)

In an active "man-in-the-middle" attack, the attacker positions themselves between you and the website. They substitute certificates, redirect requests to fake versions of pages and collect everything you enter. The user thinks they're working with the real bank website, when in fact they're on a copy created by the attacker.

Myth: "HTTPS protects everything"

HTTPS encrypts traffic between your browser and the website, but it's not that simple. DNS requests often remain visible, TLS can be "downgraded" to an old version, and some traffic goes without encryption entirely. More reliable than relying on HTTPS on each individual website is to encrypt the whole channel at once. That's exactly what a VPN does.

Real negative scenarios

Attacks on public networks aren't theory from textbooks. Here are typical stories that happen all the time.

Scenario A: a café in a business district. A freelancer works in a coffee shop, connects to a free network and checks email. The email password goes out in plain text (an old mail client without TLS). Within an hour, spam is being sent from their account and emails are being read. Access can be restored, but the correspondence is already compromised.

Scenario B: an airport. A traveler connects to the network "Airport_Free_WiFi_5G" — a fake copy of the real one. On the authorization page they're asked to "confirm their email". The email login and password go to the attacker. A week later they discover that the email password is the same as for other services, and all of them have been hacked.

Scenario C: a hotel. A guest goes online through the hotel network and pays for something with a card, not noticing that the payment page has no HTTPS. The card data is intercepted. A few days later — charges the bank reports by notification.

In all three cases, no country blocked access to resources. The problem was only that the connection went through an unsecured public network.

How a VPN solves the problem

A VPN creates an encrypted tunnel between your device and the VPN server. All your traffic — HTTP and HTTPS, DNS requests, and app traffic alike — is packed into a single encrypted stream and transmitted inside it.

What this gives you in practice in a café or airport:

The rule is simple

An open network without a VPN is like a conversation on speakerphone in a crowded hall. With a VPN you talk into an encrypted handset that no one can hear. The difference between these two situations — is the difference between risk and protection.

What else to remember about public networks

A VPN solves the main task — encrypting the channel — but doesn't cancel common sense. A few additional rules:

Summary

You need a VPN not only where there's censorship. Public Wi-Fi — in a café, airport, hotel, transport — is a high-risk zone in any country in the world. Password interception, fake access points, session hijacking, fake authorization pages — all of this works regardless of the state and its policies.

Plan B is suitable for this task too: the AmneziaWG protocol encrypts all traffic up to the server, and plans start from 49 rubles per month. One subscription works on all your devices — turn on the VPN whenever you connect to any unfamiliar network, and public Wi-Fi will stop being a threat.

Related articles: "Why free VPNs are dangerous", "Online security: 7 habits" and "How to choose a VPN in 2026".