Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Cybercrime

Australian Man Sentenced to Prison for Wi-Fi Attacks at Airports and on Flights

Michael Clapsis has been sentenced to 7 years and 4 months in prison for stealing sensitive information.

Hacker sentenced to prison

An Australian man has been sentenced to prison after he was caught launching Wi-Fi attacks at airports and on flights, the Australian Federal Police (AFP) announced. 

The police’s press release does not name the hacker, but he has been identified by Australian media as Michael Clapsis.

Clapsis, 44, pleaded guilty and has been sentenced to seven years and four months in prison. He will be eligible for parole after five years.

The AFP announced charges against Clapsis in June 2024. The man was caught launching evil twin attacks against individuals who wanted to connect to Wi-Fi networks at airports in Perth, Melbourne and Adelaide, as well as on some domestic flights.

Specifically, according to the AFP, the man used a Wi-Fi Pineapple, a device designed for conducting wireless network pentesting. 

The hacking device passively monitored for requests initiated by users looking for free Wi-Fi networks. When such a request was detected, the device created a rogue access point with the name of the targeted network, which resulted in the victim connecting to the attacker’s network.

Advertisement. Scroll to continue reading.

The victim was then presented with a fake login page asking them to enter their email or social media credentials. 

An investigation was launched after an airline employee discovered a suspicious Wi-Fi network during a flight. 

Later that month, police searched Clapsis’s hand luggage when he landed in Perth, seizing the wireless hacking device, a laptop, and a mobile phone. The man’s home was also searched by investigators. 

“Forensic analysis of data and the seized devices identified thousands of intimate images and videos, personal credentials belonging to other people, and records of fraudulent WiFi pages,” the AFP said. 

Authorities also noted that, the day after the search warrant was executed, the suspect deleted files from an online storage account and unsuccessfully attempted to remotely wipe his mobile phone. 

Days later, Clapsis accessed his employer’s laptop, attempting to access confidential meetings between the company and the AFP regarding the investigation.

Related: Developer Who Hacked Former Employer’s Systems Sentenced to Prison

Related: Scattered Spider Hacker Sentenced to Prison

Related: Hacktivist Sentenced to 20 Months of Prison in UK

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Today’s attackers are no longer breaking in — they’re logging in. Join this live webinar as we break down the modern identity attack chain and examine how recent breaches exploited weaknesses in authentication, identity verification, and access management processes.

Register

AI has accelerated both sides of the fight. Adversaries are weaponizing vulnerabilities faster, while defenders are racing to ship detections and configurations. Join this live webinar as we explore how to prove your controls actually hold against new threats, map your security maturity, and unite breach simulation with automated pentesting into a single, coordinated program.

Register

People on the Move

Jonathan Trull has joined Oracle as Global Head of Cyber Defense.

Plaid has appointed Sean Cassidy as Chief Information Security Officer.

Ann Barron-DiCamillo has been named Executive Vice President and Global Chief Information Security Officer at U.S. Bank.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.