IDENTITY THEFT PROTECTION CyberArtical Editorial Team

Shopping online and the public Wi-Fi warning that changed

A computer keyboard with a large red key marked Buy Now and a shopping cart icon

If you learned online shopping safety from an article written before about 2020, you were probably told never to buy anything on café or airport Wi-Fi, because somebody nearby could be reading your traffic. The FTC’s current guidance says something close to the opposite, and understanding why matters more than the rule itself, because it tells you where the risk actually sits now.

What the FTC says now

  • “Today, most websites do use encryption to protect your information”, and “connecting through a public Wi-Fi network is usually safe.”
  • The FTC contrasts this with the past: “In the past, if you used a public Wi-Fi network to get online, your information was at risk.”
  • The residual risk is the destination, not the network: scammers “create fake websites and encrypt them to make you think they’re safe when they’re not.”
  • “Your data may be encrypted on its way to the site, but it won’t be safe from scammers operating the site.”
  • The FTC’s current public Wi-Fi article recommends recognising HTTPS, strong passwords, two-factor authentication and spotting fraudulent websites — and does not mention VPNs at all.
  • FBI/IC3: “Do not trust a website just because it has a lock icon or ‘https’ in the browser address bar.”

The advice you have heard

The old warning had a real basis. When much of the web was unencrypted, traffic on a shared network genuinely could be read by others on it, and the standard advice — wait until you are home, or tunnel your traffic — followed sensibly from that.

What changed was the web, not the café. Encryption became close to universal, and the FTC now writes that connecting through a public Wi-Fi network is usually safe, explicitly contrasting that with the past when your information was at risk.

Where the risk went instead

It moved one step along the chain, from the network to the shop. The FTC’s warning is now about fraudulent sites: scammers create fake websites and encrypt them to make you think they’re safe when they’re not, and your data may be encrypted on its way to the site but it won’t be safe from the scammers operating the site.

This is why the padlock cannot carry the weight people put on it. The FBI issued a public service announcement saying not to trust a website just because it has a lock icon or “https” in the address bar, precisely because criminals obtain valid certificates for phishing sites. Encryption tells you the delivery van is locked. It says nothing about who is at the other end.

Worth noting as a checkable detail: the FTC’s public Wi-Fi article does not mention VPNs at all. Its recommendations are recognising HTTPS, strong passwords, two-factor authentication and spotting fraudulent websites.

The risks that are genuinely about being in public

Two of these are not in the FTC’s list, and are offered here as ordinary reasoning rather than as sourced guidance — but they are the parts of the old warning that survive.

The first is the person behind you. Card numbers, security codes and one-time passcodes are all readable over a shoulder, and a phone screen at a café table is a public document.

The second is the device itself. If it is unlocked and you step away from it, everything you were logged into is available to whoever picks it up. That is not a Wi-Fi problem; it is a physical one, and a lock screen is the whole fix.

The third — the fake page — is the FTC’s, and is the one that follows you home. It works just as well on your own broadband.

What to do instead of avoiding the network

  1. Reach the shop by typing its address yourself or using an app you already have, rather than clicking a link in an email, text or advert.
  2. Check the domain carefully. The FBI’s rule covers misspellings and wrong domains; CISA’s example of a near-miss is amazan.com.
  3. Treat the padlock as neutral. Its presence is not evidence, and its absence is a warning.
  4. Turn on two-factor authentication on the accounts holding your payment details, and keep your device locked when it leaves your hand.
  5. Be sceptical of urgency in any message pushing you toward a purchase — CISA lists urgent or emotionally appealing language claiming dire consequences among its phishing indicators.

If a purchase goes wrong

If you handed over card or bank account details to a fraudulent shop, go to IdentityTheft.gov, which produces a personal recovery plan and pre-filled letters for banks, businesses and debt collectors. Report the scam at ReportFraud.ftc.gov, and the fraudulent site at IC3.gov.

Then consider the free credit freeze at Equifax, Experian and TransUnion. It costs nothing, does not affect your credit score, and means nobody can open a new credit account in your name.

Why the old rule persists

Partly because it is easy to give and hard to argue with: telling someone not to bank on hotel Wi-Fi has no obvious downside. Partly because a large industry has an interest in the older threat model remaining current in people’s minds.

The cost of keeping it is not neutral, though. Every minute spent worrying about the network is a minute not spent checking the domain, which is where the FTC now says the danger is.

Sources: FTC — Are public Wi-Fi networks safe? What you need to know · FBI IC3 — PSA on the HTTPS padlock (I-061019-PSA) · CISA — Recognize and report phishing · FTC — What to know about credit freezes and fraud alerts · FTC IdentityTheft.gov

Reviewed 27 August 2026 by the CyberArtical editorial team against primary guidance from the FTC, the FBI and CISA. Security guidance changes over time; where our earlier version of this page said something different, we say so in the article rather than editing it out quietly.

More Stories