Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Cybercrime

Australian Man Sentenced to Prison for Wi-Fi Attacks at Airports and on Flights

Michael Clapsis has been sentenced to 7 years and 4 months in prison for stealing sensitive information.

Hacker sentenced to prison

An Australian man has been sentenced to prison after he was caught launching Wi-Fi attacks at airports and on flights, the Australian Federal Police (AFP) announced. 

The police’s press release does not name the hacker, but he has been identified by Australian media as Michael Clapsis.

Clapsis, 44, pleaded guilty and has been sentenced to seven years and four months in prison. He will be eligible for parole after five years.

The AFP announced charges against Clapsis in June 2024. The man was caught launching evil twin attacks against individuals who wanted to connect to Wi-Fi networks at airports in Perth, Melbourne and Adelaide, as well as on some domestic flights.

Specifically, according to the AFP, the man used a Wi-Fi Pineapple, a device designed for conducting wireless network pentesting. 

The hacking device passively monitored for requests initiated by users looking for free Wi-Fi networks. When such a request was detected, the device created a rogue access point with the name of the targeted network, which resulted in the victim connecting to the attacker’s network.

Advertisement. Scroll to continue reading.

The victim was then presented with a fake login page asking them to enter their email or social media credentials. 

An investigation was launched after an airline employee discovered a suspicious Wi-Fi network during a flight. 

Later that month, police searched Clapsis’s hand luggage when he landed in Perth, seizing the wireless hacking device, a laptop, and a mobile phone. The man’s home was also searched by investigators. 

“Forensic analysis of data and the seized devices identified thousands of intimate images and videos, personal credentials belonging to other people, and records of fraudulent WiFi pages,” the AFP said. 

Authorities also noted that, the day after the search warrant was executed, the suspect deleted files from an online storage account and unsuccessfully attempted to remotely wipe his mobile phone. 

Days later, Clapsis accessed his employer’s laptop, attempting to access confidential meetings between the company and the AFP regarding the investigation.

Related: Developer Who Hacked Former Employer’s Systems Sentenced to Prison

Related: Scattered Spider Hacker Sentenced to Prison

Related: Hacktivist Sentenced to 20 Months of Prison in UK

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we break down why email-layer defenses alone can't keep pace with the modern phishing ecosystem, how agentic AI is changing the capacity equation for security teams, and more.

Register

This year's summit will help organizations learn how to utilize tools, controls, and design models needed to properly secure cloud environments. Interact with leading solution providers and other end users facing similar challenges in securing a variety of cloud deployments.

Register

People on the Move

Fable Security has appointed Jacob Berry as Chief Information Security Officer.

iCOUNTER has named Ali Waezzadah as Chief Information Security Officer.

Roger Hale has joined 1Kosmos as Chief Information Security Officer.

More People On The Move

Expert Insights

Four decades of incident response experience suggest that exploits are often the symptom, not the root cause, of today’s cybersecurity failures.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.