{"id":56449,"date":"2026-09-22T10:36:48","date_gmt":"2026-09-22T14:36:48","guid":{"rendered":"https:\/\/www.kaspersky.com\/blog\/?p=56449"},"modified":"2026-09-22T10:36:48","modified_gmt":"2026-09-22T14:36:48","slug":"hidden-ssid-dangers-wifi-security-explained","status":"publish","type":"post","link":"https:\/\/www.kaspersky.com\/blog\/hidden-ssid-dangers-wifi-security-explained\/56449\/","title":{"rendered":"Fact and fiction about hidden Wi-Fi network names"},"content":{"rendered":"<p>For more than two decades now, setting up a home router has meant going through the same old routine: pick a Wi-Fi band, name your network, choose a security type, and set a password. After you type in your network name, you often see an option next to it to hide the network name \u2014 sometimes labeled <em>hide SSID<\/em>, or simply <em>hidden<\/em> or <em>closed network<\/em>. If you choose this option, the network you create won\u2019t show up automatically in the list of available Wi-Fi networks on any smartphone, computer, or smart-home device \u2014 you need to type in the correct network name by hand. Only then will the device be able to find that network and connect to it. At first glance, hiding your wireless network\u2019s name might seem like a smart precaution: keeping neighbors or passersby from <a href=\"https:\/\/www.kaspersky.com\/resource-center\/preemptive-safety\/12-signs-your-router-has-been-hacked\" target=\"_blank\" rel=\"noopener nofollow\">hacking into your Wi-Fi<\/a> since they simply can\u2019t see it. But in fact things work differently: all your devices will give away the hidden network \u2014 and not just at home either.<\/p>\n<h2>How devices connect to Wi-Fi<\/h2>\n<p>Every Wi-Fi access point broadcasts a short data packet roughly 10 times a second so your smartphone or computer can show you a list of nearby networks\u2019 names, like <em>JohnWiFi<\/em>, <em>TommyNet<\/em>, <em>CafeDeArts_Guest<\/em>, or other, creative variants. This packet contains (i) the network\u2019s name (Service Set Identifier, or SSID), (ii) a unique identifier for the access point (Basic Service Set Identifier, or BSSID), and (iii) details about the radio channel the network uses. This info helps devices (i) pick the best network to connect to, and (ii) automatically join networks they already know; accordingly, none of the data in that packet is encrypted. Hidden networks also broadcast these advertising packets; they just leave the SSID field blank. This method of finding networks is called passive because a Wi-Fi client, like, say, your smartphone, just needs to listen to the airwaves to spot nearby access points.<\/p>\n<p>On top of that, the client can scan for Wi-Fi networks on its own, which is known as active discovery. Your smartphone or computer is constantly broadcasting the names of Wi-Fi networks it knows and would like to connect to. If one of those networks happens to be nearby, the access point answers back, and the connection is made.<\/p>\n<p>Active discovery can sometimes help save your smartphone\u2019s battery, and it\u2019s indispensable when you\u2019re working with hidden networks. Discovering a hidden network and connecting to it <a href=\"https:\/\/arxiv.org\/abs\/2206.03745\" target=\"_blank\" rel=\"noopener nofollow\">becomes a two-step process<\/a>. First, the smartphone \u201chears\u201d that there\u2019s a Wi-Fi access point nearby with a hidden network name. It then tries to reach that network by broadcasting the names (SSIDs) it already knows \u2014 either hidden networks it\u2019s connected to before, or the name the user typed in when first connecting to a hidden network. If the name matches, the router responds, and the connection goes through.<\/p>\n<h2>A hidden network name (SSID) doesn\u2019t actually hide your Wi-Fi network<\/h2>\n<p>The regular list of available Wi-Fi networks on your smartphone or computer won\u2019t show networks that don\u2019t broadcast a public SSID. But any specialized Wi-Fi scanning software can spot them easily \u2014 it just won\u2019t show their names. And hidden networks are still easy to identify and tell apart thanks to each router\u2019s unique BSSID.<\/p>\n<p>So hiding a Wi-Fi network\u2019s name doesn\u2019t make it truly invisible, and it won\u2019t protect you from cybercriminals. It\u2019s worth noting that any large-scale analysis, such as <a href=\"https:\/\/www.kaspersky.com\/blog\/wps-router-geolocation\/51515\/\" target=\"_blank\" rel=\"noopener nofollow\">mapping the geographic locations of Wi-Fi networks<\/a>, relies on BSSIDs, not SSIDs. Besides the huge databases kept by Apple and Google, there are public access-point-mapping projects too, like <a href=\"https:\/\/wigle.net\/\" target=\"_blank\" rel=\"noopener nofollow\">WiGLE<\/a>.<\/p>\n<p>If someone wants to break into a network at a specific location, specialized software lets them find out its SSID just by waiting for one of the legitimate clients to connect and listening in on the active discovery session. From there, they can connect to that Wi-Fi network \u2014 provided it uses a weak enough security protocol.<\/p>\n<h2>Your devices leak hidden Wi-Fi network names and personal data<\/h2>\n<p>The main drawback of a hidden SSID is that smartphones and computers have to broadcast it before they can connect to the wireless network. And they do this everywhere \u2014 not just near the specific access point in question. As soon as any network with a hidden name shows up within signal range, the client attempts to connect, and during that attempt it broadcasts the names of every hidden network it knows. And this broadcast isn\u2019t encrypted, which means anyone nearby can pick up the data being transmitted.<\/p>\n<p>In 2021, researchers at the University of Hamburg ran an <a href=\"https:\/\/arxiv.org\/abs\/2206.03745\" target=\"_blank\" rel=\"noopener nofollow\">experiment<\/a> collecting radio signal data on a busy street. In just three one-hour listening sessions, they gathered 252\u00a0000 Wi-Fi connection requests from passersby\u2019s smartphones. Of those, 23% contained the SSID of a network the smartphone would have preferred to connect to.<\/p>\n<p>And that\u2019s where a factor few people think about comes into play: the network\u2019s name itself. Twelve percent of the SSIDs found were long numeric strings that looked a lot like passwords. So, once someone knows the SSID and BSSID, they can look up the BSSID in a service like WiGLE and find the access point\u2019s real-world address. Once there, an attacker can try to use such a string as both the SSID and the password to connect \u2014 with a good chance of success. The researchers\u2019 sample also included 106 SSIDs containing a first and\/or last name, 92 SSIDs that pointed to a home address, and three that revealed an email address.<\/p>\n<p>Given all this, it\u2019s no surprise that <a href=\"https:\/\/support.apple.com\/en-us\/102766\" target=\"_blank\" rel=\"noopener nofollow\">Apple<\/a> and <a href=\"https:\/\/rog.asus.com\/en\/support\/faq\/1047947\/\" target=\"_blank\" rel=\"noopener nofollow\">Asus<\/a> recommend against using the hidden SSID feature.<\/p>\n<h2>Other drawbacks of hiding your Wi-Fi network<\/h2>\n<p>Beyond the data leak issues, hidden SSID technology \u2014 a holdover from early Wi-Fi versions \u2014 also hurts the performance of modern versions of the radio protocol. In the 6GHz band, searching for a hidden Wi-Fi network across 59 possible channels becomes noisy and power-hungry: the client has to run through every option and send a lot of requests. As a result, performance drops for all nearby Wi-Fi networks in the 6GHz band, and the client itself burns through battery power sending out all those requests.<\/p>\n<p>Asus also <a href=\"https:\/\/rog.asus.com\/en\/support\/faq\/1047947\/\" target=\"_blank\" rel=\"noopener nofollow\">points out<\/a> that Windows devices may tend to connect to visible networks first \u2014 even if a network with a hidden SSID is available and marked as preferred.<\/p>\n<h2>When a hidden SSID actually makes sense<\/h2>\n<p>There aren\u2019t many scenarios where hiding your network name is genuinely useful. For example, if a router is meant for a small group of people but is installed in a very crowded location, a hidden SSID can cut down on the number of connection attempts and ease the load on the router. But keep in mind that this boosts performance, not security \u2014 and only slightly at that.<\/p>\n<p>Another similar case is a technical Wi-Fi network for a limited number of fixed devices \u2014 like a network of security cameras or smart home gadgets. These devices always stay in the same place, so whenever they try to connect to their assigned Wi-Fi, they find it right away, and no data leaks out\u00a0\u2014 unless an attacker is actually listening in on the radio signal near the router. At the same time, outsiders are less likely to try connecting to such a network.<\/p>\n<h2>How to make your Wi-Fi more secure<\/h2>\n<p>To protect your Wi-Fi network from wireless hackers, don\u2019t hide the SSID: instead, use the modern WPA3 security protocol along with a long password. Attackers can intercept data over the air and then try to crack the password with brute force, so a strong Wi-Fi password <a href=\"https:\/\/www.kaspersky.com\/blog\/passwords-hacking-research-2026\/55743\/\" target=\"_blank\" rel=\"noopener nofollow\">should be at least 20 characters long<\/a>. The easiest way to generate and store such long, hard-to-crack passwords is with a <a href=\"https:\/\/www.kaspersky.com\/password-manager?icid=gl_kdailyplacehold_acq_ona_smm__onl_b2c_kasperskydaily_wpplaceholder____kpm___\" target=\"_blank\" rel=\"noopener nofollow\">password manager that syncs across your devices<\/a>; that way they\u2019re always at hand \u2014 no matter which gadget you\u2019re using.<\/p>\n<p>If some of your older devices don\u2019t support WPA3, it\u2019s fine to use WPA2 with protected management frames (PMF) turned on, which guard against many types of attacks on Wi-Fi networks.<\/p>\n<p>You should also make sure Wi-Fi Protected Setup (WPS) is turned off, since it essentially replaces your password with an easy-to-guess PIN code.<\/p>\n<p>To quickly spot unknown devices connected to your Wi-Fi network, use <a href=\"https:\/\/support.kaspersky.com\/kaspersky-for-windows\/21.26\/138202\" target=\"_blank\" rel=\"noopener\">Smart Home Monitor<\/a> in <a href=\"https:\/\/www.kaspersky.com\/premium?icid=gl_bb2023-kdplacehd_acq_ona_smm__onl_b2c_kdaily_lnk_sm-team___kprem___\" target=\"_blank\" rel=\"noopener nofollow\">Kaspersky Premium<\/a>.<\/p>\n<p>As for the network name, instead of hiding it, pick one that doesn\u2019t reveal your name, address, or any other personal details. It\u2019s also worth avoiding default network names like <em>ISPName-XXXX<\/em> or <em>dlink<\/em>, but for a different reason: generic names like these can confuse you and your guests alike. If you don\u2019t want your access point to show up on Wi-Fi geolocation maps from Apple, Google, and other providers, you can <a href=\"https:\/\/www.kaspersky.com\/blog\/wps-router-geolocation\/51515\/\" target=\"_blank\" rel=\"noopener nofollow\">add the suffix <em>_nomap<\/em><\/a> to the end of your network name, but there\u2019s no guarantee it will actually work.<\/p>\n<p>Apart from protecting your Wi-Fi, make sure your router is <a href=\"https:\/\/www.kaspersky.com\/blog\/save-your-home-router-from-apt-residential-proxy\/53840\/\" target=\"_blank\" rel=\"noopener nofollow\">configured securely overall<\/a>. First and foremost, that means giving it a long, unique admin password, and keeping it updated with the manufacturer\u2019s latest firmware. And if you have a bit more time, you could even <a href=\"https:\/\/www.kaspersky.com\/blog\/make-home-wifi-great-again\/35043\/\" target=\"_blank\" rel=\"noopener nofollow\">boost your Wi-Fi performance<\/a>.<\/p>\n<blockquote><p>How Wi-Fi networks get hacked, and how to protect them:<\/p>\n<ul>\n<li><a href=\"https:\/\/www.kaspersky.com\/blog\/dense-pose-recognition-from-wi-fi-signal\/51216\/\" target=\"_blank\" rel=\"noopener nofollow\"><strong>How to find a person and recognize their pose using Wi-Fi<\/strong><\/a><\/li>\n<li><a href=\"https:\/\/www.kaspersky.com\/blog\/wifi-sensing-motion-detection-howto\/53851\/\" target=\"_blank\" rel=\"noopener nofollow\"><strong>Is your printer informing on you to the police?<\/strong><\/a><\/li>\n<li><a href=\"https:\/\/www.kaspersky.com\/blog\/wi-fi-pmkid-attack\/50790\/\" target=\"_blank\" rel=\"noopener nofollow\"><strong>Wi-Fi hacking using PMKID interception<\/strong><\/a><\/li>\n<li><a href=\"https:\/\/www.kaspersky.com\/blog\/how-to-secure-smart-home\/47472\/\" target=\"_blank\" rel=\"noopener nofollow\"><strong>How to secure your smart home<\/strong><\/a><\/li>\n<li><a href=\"https:\/\/www.kaspersky.com\/blog\/protecting-from-wifi-camera-jamming-and-other-burglar-tricks\/50739\/\" target=\"_blank\" rel=\"noopener nofollow\"><strong>Securing home security<\/strong><\/a><\/li>\n<\/ul>\n<\/blockquote>\n<input type=\"hidden\" class=\"category_for_banner\" value=\"premium-geek\">\n","protected":false},"excerpt":{"rendered":"<p>Hiding your Wi-Fi network name might seem like a smart security move, but in practice it does more harm than good. Let&#8217;s take a look at how it works, what side effects it can have, and how to properly secure your home Wi-Fi.<\/p>\n","protected":false},"author":2722,"featured_media":56450,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[9],"tags":[794,187,473,97,660,321,131,174],"class_list":["post-56449","post","type-post","status-publish","format-standard","has-post-thumbnail","category-tips","tag-iot","tag-passwords","tag-routers","tag-security-2","tag-smart-home","tag-technology","tag-tips","tag-wi-fi"],"hreflang":[{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/hidden-ssid-dangers-wifi-security-explained\/56449\/"},{"hreflang":"en-in","url":"https:\/\/www.kaspersky.co.in\/blog\/hidden-ssid-dangers-wifi-security-explained\/31075\/"},{"hreflang":"en-ae","url":"https:\/\/me-en.kaspersky.com\/blog\/hidden-ssid-dangers-wifi-security-explained\/26106\/"},{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/hidden-ssid-dangers-wifi-security-explained\/30908\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/hidden-ssid-dangers-wifi-security-explained\/42723\/"},{"hreflang":"ru-kz","url":"https:\/\/blog.kaspersky.kz\/hidden-ssid-dangers-wifi-security-explained\/31076\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/hidden-ssid-dangers-wifi-security-explained\/36816\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/hidden-ssid-dangers-wifi-security-explained\/36485\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.com\/blog\/tag\/wi-fi\/","name":"wi-fi"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/56449","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/users\/2722"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/comments?post=56449"}],"version-history":[{"count":3,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/56449\/revisions"}],"predecessor-version":[{"id":56452,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/56449\/revisions\/56452"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/media\/56450"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/media?parent=56449"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/categories?post=56449"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/tags?post=56449"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}