Anonymous case study

When a weak wireless password opened the internal network.

An authorised assessment demonstrated why staff wireless should be treated as an external security boundary, not simply an internal convenience.

The challenge

A UK organisation asked Vortigen Cyber to assess its staff wireless network and the internal systems reachable from it. The work was controlled and time-boxed, with the aim of establishing whether separate weaknesses could be combined into a realistic route to compromise.

What we found

The wireless network used WPA2 with AES encryption. The technology itself was appropriate, but the shared password was predictable enough to be recovered offline from a captured wireless handshake.

This meant that an attacker within wireless range could join the staff network without entering the premises or connecting to a physical network port.

Once connected, the assessment demonstrated a clear sequence: internal authentication material was captured, a valid password was recovered, internal systems were accessed and administrative file access was confirmed.

Why it mattered

The wireless password had become the practical boundary protecting the organisation's internal network.

Because wireless users could reach internal systems and management services, weaknesses that might otherwise have required an existing internal foothold became accessible to anyone within radio range. Strong encryption did not compensate for a weak shared credential or insufficient network separation.

The recommendations

  • Use a long, random and unique password where shared access remains.
  • Prefer WPA2/WPA3 Enterprise with per-user or per-device authentication.
  • Restrict wireless access to required services and isolate management systems.
  • Harden legacy internal authentication paths and reduce unnecessary administrative access.

The lesson

Wireless should be treated as an external security boundary.

A secure wireless design must consider who can obtain access, what they can reach afterwards and whether a single shared password can expose the wider organisation.

Attack path showing wireless range, handshake capture, password recovery, internal access and administrative file access

Assess your wireless boundary

Find out what access really leads to.

A wireless assessment should test both the access control and the internal reachability that follows.

Discuss an assessment