A new U.S. Government Accountability Office (GAO) report found that communications between air traffic controllers and commercial aircraft remain vulnerable to cyber and electromagnetic threats, including interception, spoofing and jamming.
GAO also found that text-based aircraft communication systems have vulnerabilities related to authentication, encryption and protocol design. The agency found that while the FAA has identified spectrum-related threats, it lacks tools to continuously monitor for them in real time and can generally investigate incidents only after they are reported.
The Department of Transportation, responding on behalf of the FAA, agreed with all nine of GAO’s recommendations. The report was released the same day as a telecommunications failure involving a severed backup fiber line that caused the FAA to halt incoming flights at several major Northeast airports, contributing to roughly 7,000 delayed or canceled flights nationwide. The disruption was not attributed to a cyberattack.
Damon Small, Board of Directors, Xcape Inc.:
“Unencrypted and unauthenticated aviation data links expose national airspace operations to severe financial disruptions, safety risks, and systemic operational failures. A recent Government Accountability Office (GAO) report reveals that legacy text-based communications lack cryptographic authentication and protocol integrity, leaving air traffic control (ATC) systems vulnerable to active spoofing, jamming, and interception.
“The nine recommendations from the GAO are valid, but they also show how far behind the Federal Aviation Administration (FAA) is in protecting and maintaining its aging infrastructure, a frightening prospect given that millions of passengers and crew depend on it every day. Furthermore, a single fiber cut led to the disruption of ATC in the northeastern United States, demonstrating a severe lack of redundancy in these safety-critical systems. Aviation executives and government leaders must prioritize implementing cryptographic payload signing across aircraft messaging systems, deploying continuous automated spectrum monitoring tools, and engineering true physical resiliency into ground network backbones.
“Critical Takeaways:
- Valid GAO recommendations highlight how far behind the FAA remains in securing legacy aviation infrastructure against radio frequency spoofing and jamming.
- A single severed fiber line disrupting northeastern air traffic control exposes a critical lack of redundancy in safety-critical ground networks.
- Aviation leaders must enforce cryptographic authentication on text communications and deploy real-time spectrum monitoring equipment.
“Relying on post-incident investigations for radio frequency jamming in aviation is like buying a smoke detector after the house burns down.”
John Strand, Owner, Black Hills Information Security:
“The biggest concern with this report isn’t necessarily the findings. It’s how difficult the recommended fixes may be to implement.
“With a lot of standard technology, you patch it, update it, and move on. But when you’re dealing with the FAA and critical infrastructure, these are real-time systems where the tolerance for downtime or errors is basically zero.
“Even changes that look simple on paper can become incredibly complicated and expensive because of the systems involved and the requirement to keep them running. I applaud the report. It looks like they found some very real issues. The problem is that fixing them could be extremely expensive and take a significant amount of time.
“And time is the part that worries me. We’re already seeing attackers targeting critical infrastructure. We don’t have the luxury of assuming they’ll wait for us to finish fixing it.”
Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs:
“As a pilot, I cannot treat a clearance like an email that can wait for a second look. Under Instrument Flight Rules (IFR), crews may be flying by instruments with limited outside visual reference while responding quickly to a tower or controller. If the channel becomes suspect, every clearance becomes a verification problem as well as an instruction.
“The Government Accountability Office (GAO) findings show the trust problem inside the communications system. FAA lacks continuous, real-time detection for all spectrum-related threats. Aircraft Communications Addressing and Reporting System (ACARS) and Controller Pilot Data Link Communications (CPDLC) still depend on procedural checks because they lack cryptographic authentication and message integrity. Voice confirmation adds workload without proving message origin or integrity.
“Monday’s fiber outage showed the visible failure mode. A broken link produces silence. Spoofing creates a harder failure mode because the link can stay open while the message is false. I would treat live monitoring and authentication as urgent fixes.
“The FAA needs to distinguish an unavailable link from jamming or spoofing during operations. Until then, pilots and controllers remain the last security control in the loop, manually compensating for a network that cannot authenticate its messages.”
I have to ask if this is being truly taken care of at in order to make this go away. That’s the real question and I hope that someone has an answer.
Related
This entry was posted on September 22, 2026 at 4:43 pm and is filed under Commentary with tags GAO. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
GAO finds FAA aircraft communications vulnerable to hacking and jamming
A new U.S. Government Accountability Office (GAO) report found that communications between air traffic controllers and commercial aircraft remain vulnerable to cyber and electromagnetic threats, including interception, spoofing and jamming.
GAO also found that text-based aircraft communication systems have vulnerabilities related to authentication, encryption and protocol design. The agency found that while the FAA has identified spectrum-related threats, it lacks tools to continuously monitor for them in real time and can generally investigate incidents only after they are reported.
The Department of Transportation, responding on behalf of the FAA, agreed with all nine of GAO’s recommendations. The report was released the same day as a telecommunications failure involving a severed backup fiber line that caused the FAA to halt incoming flights at several major Northeast airports, contributing to roughly 7,000 delayed or canceled flights nationwide. The disruption was not attributed to a cyberattack.
Damon Small, Board of Directors, Xcape Inc.:
“Unencrypted and unauthenticated aviation data links expose national airspace operations to severe financial disruptions, safety risks, and systemic operational failures. A recent Government Accountability Office (GAO) report reveals that legacy text-based communications lack cryptographic authentication and protocol integrity, leaving air traffic control (ATC) systems vulnerable to active spoofing, jamming, and interception.
“The nine recommendations from the GAO are valid, but they also show how far behind the Federal Aviation Administration (FAA) is in protecting and maintaining its aging infrastructure, a frightening prospect given that millions of passengers and crew depend on it every day. Furthermore, a single fiber cut led to the disruption of ATC in the northeastern United States, demonstrating a severe lack of redundancy in these safety-critical systems. Aviation executives and government leaders must prioritize implementing cryptographic payload signing across aircraft messaging systems, deploying continuous automated spectrum monitoring tools, and engineering true physical resiliency into ground network backbones.
“Critical Takeaways:
“Relying on post-incident investigations for radio frequency jamming in aviation is like buying a smoke detector after the house burns down.”
John Strand, Owner, Black Hills Information Security:
“The biggest concern with this report isn’t necessarily the findings. It’s how difficult the recommended fixes may be to implement.
“With a lot of standard technology, you patch it, update it, and move on. But when you’re dealing with the FAA and critical infrastructure, these are real-time systems where the tolerance for downtime or errors is basically zero.
“Even changes that look simple on paper can become incredibly complicated and expensive because of the systems involved and the requirement to keep them running. I applaud the report. It looks like they found some very real issues. The problem is that fixing them could be extremely expensive and take a significant amount of time.
“And time is the part that worries me. We’re already seeing attackers targeting critical infrastructure. We don’t have the luxury of assuming they’ll wait for us to finish fixing it.”
Jacob Krell, Senior Director: Secure AI Solutions & Cybersecurity, Suzu Labs:
“As a pilot, I cannot treat a clearance like an email that can wait for a second look. Under Instrument Flight Rules (IFR), crews may be flying by instruments with limited outside visual reference while responding quickly to a tower or controller. If the channel becomes suspect, every clearance becomes a verification problem as well as an instruction.
“The Government Accountability Office (GAO) findings show the trust problem inside the communications system. FAA lacks continuous, real-time detection for all spectrum-related threats. Aircraft Communications Addressing and Reporting System (ACARS) and Controller Pilot Data Link Communications (CPDLC) still depend on procedural checks because they lack cryptographic authentication and message integrity. Voice confirmation adds workload without proving message origin or integrity.
“Monday’s fiber outage showed the visible failure mode. A broken link produces silence. Spoofing creates a harder failure mode because the link can stay open while the message is false. I would treat live monitoring and authentication as urgent fixes.
“The FAA needs to distinguish an unavailable link from jamming or spoofing during operations. Until then, pilots and controllers remain the last security control in the loop, manually compensating for a network that cannot authenticate its messages.”
I have to ask if this is being truly taken care of at in order to make this go away. That’s the real question and I hope that someone has an answer.
Share this:
Like this:
Related
This entry was posted on September 22, 2026 at 4:43 pm and is filed under Commentary with tags GAO. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.