Cyber Security News

British Citizen Jailed for Islamophobic WiFi Hack at UK Train Stations

A British man has been sentenced to 24 months’ imprisonment, suspended for 24 months, after pleading guilty to hijacking WiFi networks at major UK train stations.

Also, users were directed to Islamophobic content that referenced prior terrorist acts, causing significant fear and anguish among travelers. 

Key Takeaways
1. Ex-employee John Wik hijacked UK station WiFi landing pages.
2. Admin access served Islamophobic content, invoking past UK terror attacks.
3. Passengers panicked; British Transport Police launched a rapid inquiry.
4. Court imposed a suspended 24-month sentence, community service, and a fine.

Targeting Station WiFi Systems

John Andreas Wik, 37, of Limes Road in Beckenham, exploited his privileged access as an employee of Global Reach Technology to compromise the WiFi landing pages at Network Rail’s busiest stations on September 25, 2024. 

The attack began around 3pm when passengers attempting to connect to the free WiFi network at twenty major stations across Britain were redirected to a malicious landing page containing Islamophobic messaging.

The compromised network infrastructure affected not only Network Rail-managed stations but also extended to venues elsewhere in the country and abroad, demonstrating the widespread reach of the company’s WiFi management services. 

Wik utilized his company-issued laptop to modify the captive portal pages – the initial web pages users encounter when connecting to public WiFi networks – effectively conducting a man-in-the-middle attack on unsuspecting passengers.

British Transport Police (BTP) launched an immediate investigation after receiving multiple reports from 3pm onwards. 

Initially, Global Reach Technology suspected external hackers had compromised their employee, but digital forensics quickly revealed the internal nature of the breach. 

Network logs showed that Wik had used his legitimate administrative credentials to access the content management system controlling the WiFi landing pages.

A subsequent forensic analysis of Wik’s mobile phone and work laptop uncovered bookmarked pages containing terrorist attack information and Islamophobic content, indicating premeditation. 

The landing page displayed references to significant terrorist incidents, including the 7/7 London bombings and the Manchester Arena bombing, causing some viewers to fear an imminent attack.

Legal Consequences

At Inner London Crown Court on July 9, 2025, Wik received a suspended sentence along with a £150 victim surcharge, 280 hours of unpaid work, and 25 days of rehabilitation activity for publishing material intended to stir up religious hatred. 

The case highlights critical vulnerabilities in public WiFi infrastructure management and the importance of implementing robust access controls and monitoring systems.

DC Adrienne Curzon emphasized the severity of the abuse of privileged access, stating that such “highly planned and disturbing” actions cause genuine fear among passengers. 

The incident highlights the importance of implementing robust security protocols in managing public network infrastructure, particularly with regard to administrative access to captive portal systems and real-time monitoring of content modifications.

Investigate live malware behavior, trace every step of an attack, and make faster, smarter security decisions -> Try ANY.RUN now 

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

3 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

4 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

5 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

5 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

5 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

7 hours ago