Could hackers disrupt commercial flights? New report warns of aviation cyber risks

A new US Government report warns that weaknesses in aviation communications could leave flight operations vulnerable to spoofing, jamming and other forms of interference.

Tower air traffic controllers ATC by NATS
Photo: NATS

Modern aviation depends on an intricate web of communications systems linking aircraft, pilots, airlines and air traffic controllers. These systems allow flight crews to receive instructions, exchange operational information, and coordinate route changes and clearances.

But a new US Government Accountability Office (GAO) report has highlighted vulnerabilities in some of these communications, raising concerns that malicious actors could interfere with messages or signals used in everyday flight operations.

US Goverment report highlights aviation safety issues

The report, published on 21 September, examined cybersecurity risks affecting the US National Airspace System. It found that some aircraft communication applications have weaknesses involving authentication, encryption and protocol design.

In particular, the GAO identified risks affecting systems including the Aircraft Communications Addressing and Reporting System (ACARS) and Controller Pilot Data Link Communications (CPDLC).

Air traffic control
Photo: 5 Grace Media / Stock.adobe.com

One scenario described by the report is particularly striking: a malicious actor could potentially transmit fraudulent messages that appear to come from air traffic control or another legitimate source.

A false clearance cancellation, for example, could cause a flight to stop or change its planned operation, resulting in delays and increased workload for pilots and controllers. In more serious circumstances, manipulated information could contribute to an unsafe situation.

Importantly, the GAO did not report that such an attack has caused a commercial aviation accident. Rather, it identified vulnerabilities and potential attack scenarios that aviation authorities need to address.

What is hacking?

In aviation, hacking broadly refers to the unauthorised exploitation or manipulation of computer systems, networks or digital communications. Aircraft do not operate as isolated computers.

They exchange information with airline operations centres, air traffic control facilities and other systems on the ground, with some communications transmitted through radio-frequency data links.

The GAO found that certain aviation communications can be vulnerable to interception and spoofing because of limitations involving authentication and encryption. ACARS and CPDLC, for example, can transmit operational and text-based messages between aircraft and ground systems.

The potential danger is not necessarily that someone could simply “take control” of an aircraft. A more immediate concern is information integrity: whether pilots and controllers can be certain that a message really came from the person or system it claims to have come from.

A fraudulent message could create confusion even if detected quickly. Pilots might have to contact controllers by voice to establish which instruction is genuine, while controllers could have to resolve conflicting information. That additional workload could contribute to delays and increase pressure on busy operations.

What is jamming?

Jamming is different from hacking. Rather than creating a false message, a jammer deliberately interferes with legitimate radio signals.

The GAO defines jamming in the context of GPS/GNSS as interference that prevents receivers from acquiring or maintaining satellite signals. The consequences can include loss or degradation of navigation, positioning and timing information.

Jamming can also affect communications. If legitimate radio-frequency transmissions are overwhelmed or disrupted, an aircraft may have difficulty communicating with ground systems.

Heathrow control tower
Photo: Pete Wilson

The problem is not theoretical. Aviation authorities have reported increasing GNSS interference in several parts of the world, particularly around conflict zones.

The European Union Aviation Safety Agency (EASA) says jamming and spoofing have increased notably since 2022 in regions including the Baltic, Black Sea, Middle East and Mediterranean.

Jamming does not necessarily mean an aircraft immediately becomes unsafe. Commercial aviation has alternative procedures and systems available to pilots, and crews are trained to deal with the loss of particular navigation or communications capabilities. Nevertheless, widespread interference can increase workload and complicate flight operations.

What is spoofing?

Spoofing involves producing false signals or information designed to appear legitimate. In satellite navigation, spoofing can cause an aircraft’s navigation receiver to calculate an incorrect position, time, or other information.

EASA describes spoofing as the transmission of counterfeit satellite signals that can deceive receivers into generating incorrect navigation information.

Spoofing can also apply to communications. Instead of simply blocking an authentic message, an attacker may attempt to introduce a fraudulent one that appears to originate from a trusted source. According to the GAO, ACARS and CPDLC can be susceptible to spoofing because of limitations in authentication and message protection.

The distinction is important: jamming attacks availability, while spoofing attacks trust and integrity. A jammed system may simply stop working. A spoofed system can continue working while providing false information.

How could these threats affect aviation?

The potential effects range from delays to serious operational disruption. If communications become unreliable, pilots and controllers may need to switch to alternative procedures, verify instructions verbally or wait for systems to recover.

A spoofed message could have a similar effect. The GAO describes scenarios in which fraudulent CPDLC messages could appear to modify a route, altitude or other clearance. If a pilot received conflicting instructions, the discrepancy would need to be resolved before the aircraft could safely continue.

At scale, multiple aircraft experiencing communication problems could increase air-traffic-controller workload, disrupt departure schedules and create congestion.

FAA Air Traffic Controllers
Photo: NATS

Navigation spoofing introduces another risk. False positioning information can give pilots or ground systems an inaccurate picture of an aircraft’s location.

The GAO cites a 2022 incident around a Dallas-area airport in which GNSS interference affected arriving aircraft and contributed to more than 230 departure delays.

The aviation industry is designed with such failures in mind. Pilots can use alternative navigation techniques and communications methods, while controllers have procedures for dealing with lost or unreliable communications. These safeguards mean that the presence of a vulnerability does not automatically translate into an accident.

Why are these vulnerabilities difficult to eliminate?

One challenge is aviation’s reliance on legacy technology. Many communication systems were developed before today’s cybersecurity threats became a major consideration.

The GAO found that ACARS and CPDLC generally lack some modern protections, including robust authentication and encryption. Because these systems also depend on radio-frequency links, they can face both conventional cyber threats and spectrum-based attacks such as jamming.

DCA Control Tower & Terminal C
Photo: Mario Roberto Duran Ortiz | Wikimedia Commons

Modernising aviation is also unusually complicated. Aircraft and air-traffic systems have long certification cycles, and changes must be tested extensively because failures can have serious consequences.

The GAO recommended nine actions for the FAA, including improvements to risk assessment, monitoring, coordination and the protection of aviation communications. The FAA agreed with the recommendations.

Building a more resilient aviation system

The findings highlight an important principle of aviation cybersecurity: security is not simply about preventing somebody from breaking into a computer. It is also about ensuring that pilots and controllers can trust the information they receive.

That means improving authentication so systems can verify who sent a message, protecting communications from manipulation and improving monitoring so unusual activity can be detected quickly.

The GAO also found that the FAA lacked a defined real-time capability covering all spectrum-related threats. Without effective monitoring, some interference may only become apparent after pilots, controllers or other users report it.

Hacking, jamming and spoofing represent different problems, but they can ultimately produce a similar result: reducing the reliability of the information on which aviation depends. Strengthening these systems, while maintaining the rigorous testing and safety standards required for aviation, will therefore be increasingly important to keeping modern air travel resilient.

Sign up for our newsletter and get our latest content in your inbox.

More from