Yes — for most US households, using the bank’s official app or an https website on café or airport Wi-Fi is usually fine, because modern sites and apps encrypt traffic. The FTC’s public Wi-Fi article (updated for today’s encryption reality) says connecting through a public hotspot is usually safe when you see the lock / https, and that most mobile apps also encrypt. The bigger risks are fake “Free Wi-Fi” networks, phishing pages that look like your bank, and outdated devices — not the mere fact that the network is public.

What the FTC actually says about public Wi-Fi

Public hotspots in coffee shops, malls, airports, and hotels used to be riskier when few sites encrypted data. Today most websites do encrypt, so the FTC concludes public Wi-Fi is usually safe. Confirm encryption in a browser with the lock icon or https in the address bar (same check on mobile browsers). Apps are harder to inspect visually, but the FTC notes the majority encrypt. Still follow the FTC’s always-on basics: strong unique passwords, two-factor authentication when available, and keep the phone/OS/browser and security software updated (automatic updates on).

Banking on public Wi-Fi: do this, skip that

  1. Prefer the bank’s official app from the App Store / Google Play you already installed at home — not an APK from a search ad.
  2. Confirm the network name with staff. Avoid twin SSIDs like “Airport_Free_WiFi_1” that nobody posted.
  3. Use cellular data for a one-time large transfer if you feel unsure; public Wi-Fi is convenience, not a requirement.
  4. Turn on the bank’s MFA / 2FA. CISA’s Turn On MFA guidance: a stolen password alone should not open the account.
  5. Never type a password into a browser page that arrived from a text or email link while on public Wi-Fi — open the app or type the bank URL yourself. Pair with how to spot a phishing email.
  6. Log out when finished; do not leave the bank session open on a shared tablet.
  7. Skip “Wi-Fi login” pages that ask for your bank password. Captive portals should not need banking credentials.
  8. Keep the phone updated. FTC groups OS updates with account hygiene for a reason.

Home Wi-Fi hardening is a separate job — use how to check if your home Wi-Fi is safe and the FTC home Wi-Fi guide when you are back at the house.

Public Wi-Fi myths vs FTC reality

Encryption protects the path. It does not prove the page is your bank.

ClaimBetter reading
“Never bank on public Wi-Fi”FTC: usually safe when the site/app encrypts; look for https / lock
“https means the site is honest”FTC warns scammers also encrypt fake sites — encryption protects the path, not the destination
“You must buy a VPN or new antivirus first”Optional extra. FTC’s baseline is passwords, 2FA, and updates. Buy-nothing is valid
“The café Wi-Fi password proves it is safe”A shared password is not the same as end-to-end https to your bank

FAQ

Is it safe to use banking apps on public Wi-Fi?

Usually yes if you use the official app or an https bank site, MFA is on, and you did not follow a phishing link. That matches the FTC’s current public Wi-Fi guidance.

Do I need a VPN to check my balance at the airport?

Not required by the FTC article. A VPN can add privacy from the local network, but it does not stop phishing. Skip upsells that claim you will be hacked without one.

What if a pop-up says my bank session is unsafe on this Wi-Fi?

Treat unexpected scare pages like other fake warnings. Close them and open the bank app yourself.

Is home Wi-Fi automatically safer?

Only if you secured the router. Misconfigured home networks are covered in our home Wi-Fi checklist.

You do not need to buy software to bank safely on modern encrypted apps. If you later want a suite that bundles VPN or identity tools, compare on-site paid pages only: TotalAV, Norton, Bitdefender, McAfee, Avast, and the extras explainer at 5 antivirus extras worth paying for.