Security issues when attending public events

Practical tips for concerts, conferences, and stadiums: fake ticket sites, phishing, public Wi-Fi, rogue hotspots, and sketchy ATMs.

Topics Hardening & checklists

Lars Koudal

Updated Published

Crowds, excitement, and free Wi-Fi are a gift to scammers. People hurry to buy tickets, join “official” networks, and check email between sets. That is when phishing, fake shops, and snooping networks work best.

These habits help whether you are at a conference, match, or festival. They also protect the WordPress sites and inboxes you manage when you travel for work.

Fake event sites and phishing

Before a big show, lookalike domains and “last tickets” emails show up everywhere. They harvest logins and card details, then disappear.

  • Buy only from URLs you confirm via the organizer’s official site or verified social accounts
  • Do not trust a link in an unsolicited SMS or email, even if the branding looks right
  • Hover or long-press links; misspellings and odd TLDs are common tells
  • If you manage a brand, warn your audience about known fakes; attackers love event season

Same pattern hits WordPress admins on the road: fake “your site is down” messages. Treat unexpected login or payment links as hostile until proven otherwise. More: guide to phishing.

Fake ticketing

Criminals build checkout pages that feel real enough. You pay, get a useless QR code, and they keep the card data.

  • Prefer the venue or promoter’s own checkout, or a well-known reseller you already trust
  • Be suspicious when a “simple ticket” form demands odd personal data or rush wire transfers
  • Use virtual card numbers or a card with tight alerts when buying from a new seller
  • Screenshot confirmations and keep order emails; you may need them at the door

Public Wi-Fi and rogue hotspots

Event Wi-Fi is convenient and often lightly controlled. Other attendees (or someone nearby) can run a hotspot named almost like the official SSID.

  • Prefer mobile data for banking, password managers, and wp-admin
  • If you must use venue Wi-Fi, use a reputable VPN so traffic is encrypted to a trusted endpoint
  • Turn Wi-Fi and Bluetooth off when you are not using them
  • Forget the network after the event so your phone does not auto-join later
  • Avoid password changes and admin work on open networks without a VPN

Public Wi-Fi is also a bad place to reuse passwords. Credential stuffing loves leaked event-account combos that match your email elsewhere.

ATMs and physical skimmers

Stadium and venue ATMs see heavy traffic and less scrutiny during peaks. Skimmers and cameras still show up.

  • Use bank ATMs you know, or withdraw before you arrive
  • Cover the keypad; check for loose card slots or odd overlays
  • Prefer tap-to-pay or a card with strong fraud monitoring for on-site purchases

Short event checklist

  • Tickets only from verified sellers
  • No surprise login/payment links from “the organizer”
  • VPN or mobile data for sensitive work
  • Wi-Fi off when idle; forget event networks afterward
  • Skip sketchy venue ATMs when you can

Stay curious, not paranoid. Verify the ticket source, treat free networks as hostile, and keep admin habits the same on the road as at your desk. If your business runs WordPress, keep the baseline strong before you travel: WordPress security checklist.

Found this useful? Share it.