Quick answer: Public wifi at cafes, airports, and hotels is not encrypted by the network itself, which is what lets attackers on the same network read your traffic or clone the hotspot outright. A VPN wraps your connection in its own encryption before it touches that network, so your bank login and streaming session stay private, and it also gives your bank a stable home-country IP instead of a new one every border crossing. Pair it with HTTPS, MFA, and never using shared computers for banking.
NomadGear may earn a commission when you buy through links on this page, at no extra cost to you.
You check your bank balance from the airport, join a call from a hostel lobby, and stream something from home after a long travel day, all on wifi you don't control. Most of it was never secured properly, and on the road you don't get the option of skipping it. Here's what's actually at risk, and what closes the gap.
What actually happens on public wifi
Three things go wrong on open networks, none requiring a mistake on your part. A man-in-the-middle (MITM) attack puts someone else's device between you and the internet, reading your traffic in plain text if the connection isn't encrypted (us.norton.com). An evil twin is a fake hotspot with a name close to the real one, and it needs zero interaction: your phone auto-connects to whatever signal looks familiar (nordlayer.com). Session hijacking steals an active login session outright, no password needed.
These aren't hypothetical. Researchers monitoring unsecured hotspots in Japan pulled unencrypted photos, documents, and credentials over 150 hours of testing, and one survey found roughly a quarter of cafe wifi users had experienced identity compromise after connecting (nordlayer.com).
How a VPN protects you
A VPN (a service that encrypts your traffic and routes it through a server you choose before it reaches the open internet) closes the specific gap that makes public wifi risky. Connected, everyone else on that network sees only encrypted noise between your device and the VPN server, not your bank login or which sites you're on. That defeats packet sniffing and most MITM setups outright, and makes an evil twin far less useful, since there's nothing readable to capture even if you land on their fake hotspot.
A VPN doesn't make banking on public wifi risk-free on its own; it doesn't stop malware already on your device or protect you if you approve a fake login page yourself. What it removes is the risk entirely outside your control: a stranger on the same network reading your traffic in transit.
Banking abroad without getting locked out
The public-wifi risk is only half the banking problem on the road; the other half is your own bank. Fraud detection flags logins and charges from unfamiliar locations, and Lisbon this week followed by Bangkok next month can look exactly like a stolen account. Many banks say formal travel notices aren't required anymore since fraud monitoring runs automatically, but a new country can still trigger a temporary hold or a declined card.
Two things reduce that friction. Keep your phone number and email current so you can clear a flagged charge fast, that's usually how these get resolved. And a VPN server in your home country gives your bank a consistent IP instead of a new one every border crossing, which helps keep routine logins from tripping fraud rules at all. Never log into banking apps on a hotel business-center computer; save that for your own device, ideally on a VPN.
Streaming your home library while traveling
Streaming catalogs differ by country because of content licensing, not technical limits. Log into Netflix from a new country and it swaps in the local library, even on the same account (streamlocator.com). A VPN server in your home country restores the library you're paying for. That's different from unlocking a country's catalog you were never subscribed to: accessing your own account from a home-country server is standard practice, but platforms' terms of service technically prohibit circumventing regional restrictions, and it's the habit of hopping unrelated catalogs that risks a suspension, not watching your own library while traveling (streamlocator.com).
Beyond the VPN: the non-negotiable basics
A VPN is the biggest fix, but not the whole setup. Layer these in regardless of the network:
- HTTPS everywhere. A site without the padlock sends data in plain text either way.
- MFA on your bank, email, and money accounts, so a leaked password alone doesn't become a takeover.
- Never bank from a shared or public computer, hotel business centers included; a VPN can't protect a session started on someone else's machine.
- Turn off file sharing and auto-connect so devices don't silently rejoin an open network by name.
- Keep your OS and browser patched. Most exploits target known, unpatched holes.
NordVPN or Surfshark for this use case?
For public wifi specifically, both work: either encrypts your traffic the moment it connects. The difference shows up in the details that matter for banking and streaming on the road.
| Factor | NordVPN | Surfshark |
|---|---|---|
| Kill switch | Yes | Yes |
| Extra protection | Threat Protection, Double VPN | CleanWeb, MultiHop |
| Streaming unblocking | Netflix, Disney+, Prime Video, iPlayer | Same catalog, manual switching |
| Simultaneous devices | 10 | Unlimited |
| Starting price (2-yr) | $3.39-3.49/mo | $2.49/mo |
The kill switch matters more than it sounds: it stops your bank login from silently falling back to open wifi if the VPN drops mid-session. A partner or a pile of devices tips it toward Surfshark's unlimited allowance. Full breakdown: NordVPN vs Surfshark, or start with the best VPN for digital nomads basics.
Safe setup checklist
Run through this before connecting to any network you don't control:
- Confirm the exact network name with staff; evil twins rely on you guessing.
- Connect your VPN first, then open banking or work apps.
- Turn on the kill switch so a dropped connection doesn't fall back to open wifi unnoticed.
- Check for HTTPS (the padlock) before entering a password or card number.
- Turn off auto-connect and file sharing.
- Save banking and admin tasks for your own device, never a shared or hotel computer.
- Keep MFA on for your bank, email, and cloud storage, ideally via an authenticator app over SMS.
Who this is for (and who can skip it)
This matters most if you work from cafes, coworking spaces, and hotel wifi on a rotating basis, bank or invoice clients while traveling, or want your streaming library to follow you. It matters less if you work almost exclusively from a paid coworking membership with its own secured network, though a VPN is cheap enough that skipping it saves little. Anyone handling client payments or business banking from public networks should treat it as non-negotiable: a compromised session costs far more than the subscription.
FAQ
Is a VPN enough to bank safely on public wifi?
It's the biggest single fix, encrypting your traffic so nobody else on the network can read it, but pair it with HTTPS, MFA, and your own device rather than a shared computer.
Will my bank block my card if I travel without telling them?
Less often than it used to, since fraud monitoring now runs automatically, but a sudden new country can still trigger a temporary hold; current contact details matter more than a formal travel notice.
Can I watch my home Netflix library abroad?
Not by default. Streaming services detect your location and show the local catalog even on your home account; a VPN server in your home country restores your usual library.
Is it legal to use a VPN for banking and streaming while traveling?
Yes, in most countries including the US, UK, Canada, Australia, and most of Europe. A handful of countries restrict VPN use, so check local rules first.
NordVPN or Surfshark for banking and streaming on the road?
Both encrypt your traffic the same way. NordVPN has the edge in speed and streaming reliability; Surfshark's unlimited device count fits better for covering a partner's gear too.
Bottom line
Public wifi wasn't built to be safe, and your bank's fraud system wasn't built to expect a new country every few weeks. A VPN fixes both at once: it encrypts your traffic so a network sniffer gets nothing usable, and it gives your bank and streaming apps a stable home-country IP instead of a red flag. Add HTTPS, MFA, and a hard rule against banking on shared computers, and the setup is complete. Start with NordVPN for speed and streaming, or weigh it against Surfshark in the full comparison. Browse the Tools & Software directory for the rest of a nomad-ready setup.
Related in the NomadGear directory
- ProtonVPN - privacy-first VPN with a real free tier
- NordVPN - encrypts your connection on airport, cafe and coworking wifi
- ExpressVPN - a second reliable VPN option with fast servers in more countries
- Surfshark VPN - unlimited devices on one VPN subscription
- 1Password - one vault for every login, card and travel document
- LastPass - shared passwords without a shared spreadsheet