Is Hotel Wi-Fi Safe in 2026: What Actually Happens When You Connect

Disclosure: this article may contain affiliate links. If you buy through them, merkart may earn a commission, at no extra cost to you. Recommendations are independent.

The key card sleeve has the network name written on it in biro, and the password is the hotel phone number with the spaces taken out. It is late, the corridor smells faintly of chlorine from the pool two floors down, and you want to know whether the client answered before you sleep. You tap Connect, a page asks for your surname and room number, and half a minute later everything works. The whole sequence takes less thought than choosing which pillow to keep, which is exactly why it is worth slowing down once and looking at what actually happened.

The first seconds after you tap Connect

Your phone joins a network it has never met and immediately trusts it for one specific job: telling your device where things are on the internet. Every hostname you ask for goes to whatever name server that network hands you, unless your phone is configured to do otherwise. At the same moment the network learns your device identifier, roughly how many devices you carry, and the shape of your evening in timestamps.

None of that reads your messages. It is worth being precise about this, because the fear and the reassurance are usually both too broad. The content of almost everything you do now travels encrypted, and browsers keep tightening the screws on the exceptions. Chrome is moving through 2026 towards warning you before it loads a plain unencrypted page at all. A hotel network in 2026 is not a place where a stranger reads your email over your shoulder. It is a place where a stranger can see the outline of your evening.

What the network sees, and what it does not

Think of an envelope. The postal system needs the address, the weight and the postmark to move it, and it never needs the letter. Encryption gives you the same split, and the outside of the envelope is more legible than most people assume.

  • The address you asked for, in two ways: the name lookup, unless your device is using encrypted DNS, and the hostname your browser announces at the start of the connection. That second one is now fixable. Encrypted Client Hello hides it, browsers have shipped support since late 2023, and one large content network turned it on by default across the sites it serves. Coverage is real but partial, which is an honest way of saying it depends on where you are going.
  • The destination address itself, which is less telling than it sounds when thousands of sites sit behind one shared front door, and quite telling when they do not.
  • Timing and volume. A long steady stream at midnight looks like video. A short burst every few minutes looks like a mail client. Nobody needs to decrypt anything to read that.

So the honest summary is narrow and useful: the letters are sealed, the envelopes are not, and the envelopes are enough to describe you.

The sign-in page is the soft spot, not the encryption

The captive portal is the one screen in this whole process that is designed to be typed into, and that makes it the interesting target. Most hotel portals want a room number and a surname. Some want an email address. A few offer to let you sign in with a social account, and that is the offer to refuse every single time. You are handing a login to a web page served by a network you joined nine seconds ago, on hardware maintained by whoever the property last paid to maintain it.

Two small habits cover almost all of it. Read the address bar on the portal page before you type anything, and treat a certificate warning there as a full stop rather than a speed bump. If a portal ever asks for a card number, a passport number or an account password, close it and use your phone data instead. Legitimate hotels do charge for premium tiers, and they take that payment on a proper checkout page, not in a pop-up styled like a captive portal.

The network that is not the hotel network

The other real risk is a name. Nothing stops anyone in the building from broadcasting a network called something close to the property name, with no password and a portal that looks the part. Devices are helpful by default and rejoin anything they recognise, so the trap does not even need you to choose it a second time. The hardware to do this is cheap, sold openly for network testing, and small enough to sit in a jacket pocket.

The defence is unglamorous. Ask at reception which network is theirs rather than guessing from the list. Turn off automatic joining for open networks, so your phone stops volunteering. Tell your device to forget the network when you check out, otherwise it will cheerfully rejoin a name that once worked, in a different city, offered by someone else.

What actually reduces the risk

The measures worth the effort are the ones that survive being tired. Keep a mobile data plan or a travel eSIM that you can fall back on, so that anything involving money has an alternative to the property network. Turn off file sharing and local discovery before you travel, not in the room. Keep the phone updated, because most of the protections described here arrived in an update someone skipped.

Then there is the metadata layer, and this is where a VPN earns its keep. It does not add encryption to traffic that is already encrypted. What it does is move the observation point: the hotel network stops seeing which hostnames you ask for and how your evening is shaped, and your provider sees that instead. That trade is worth making when you trust the provider more than the property, which is the normal case with an audited service like NordVPN (Europe) or NordVPN (US/Canada) (which link works best depends on the region you are in). It is a narrow benefit, precisely stated, and it is still the single change that alters the most in this list.

The five minute version

  • Confirm the network name with reception instead of picking the most plausible one.
  • Never sign in to a portal with a social or email account, and never enter a password there.
  • Check the address bar on the portal page, and stop at any certificate warning.
  • Do banking on mobile data, not on the property network.
  • Forget the network at checkout and switch off auto-join for open networks.

That is the whole thing. Hotel Wi-Fi is not the open wound it is sometimes described as, and it is not the safe room the sign at reception implies either. It is a shared space with thin walls, and the reasonable response to a shared space is not fear but a little order: know whose network you are on, keep the sensitive things off it, and decide in advance who gets to watch the shape of your evening.

Marko Jambrek

Marko Jambrek

Licensed architect in Zagreb, 30 years of practice (sustainable design). Reviews and approves every article on this site before publication. Writes about AI tools through a lens of order and long-term value, tests before recommending.

How I vet what I recommend

The 12-point checklist behind every review on this site. Run any “best of” article through it, including mine. Twelve checks, sent once, yours to keep.

This article may contain affiliate links. We may earn a commission if you click through and make a purchase, at no extra cost to you.