Aviation cyber attacks cost organisations $1.4m as operational risks grow

A new survey reveals the rising cost of cyberattacks in aviation, alongside mounting concerns over threats to airport infrastructure and operational technology.

A cybersecurity analyst wearing a
Photo: Airbus

Aviation organisations have lost an average of $1.4 million to cybersecurity breaches over the past year, as connected airport and airline systems expand the potential consequences of an attack, according to new research from cybersecurity company Bridewell.

The firm found phishing was by far the most widespread threat. Nine in ten of the US aviation cybersecurity professionals surveyed said their organisation had experienced phishing during the previous 12 months.

Malware, credential theft and distributed denial-of-service (DDoS) attacks were also widespread, with 88% reporting at least one such incident.

However, the findings suggest the industry’s biggest concern is not simply losing data or money. It is the possibility that attackers could reach the operational technology and interconnected infrastructure that keeps airports and aviation businesses running.

Cyber attacks are already costing aviation millions

Bridewell commissioned Censuswide to survey 250 cybersecurity professionals working in the US aviation industry. The research covered cyber threats, financial losses, operational risks, spending, skills and regulation.

More than 41% of respondents said cyberattacks had cost their organisations between $500,000 and $999,999 during the previous 12 months. Another 30.8% put their losses between $1 million and $4.9 million. Bridewell calculated an average loss of $1.4 million.

Airbus Cybersecurity ops
Photo: Airbus

The figures are self-reported survey findings, not an industry-wide calculation of aviation cyber losses. Nevertheless, they hint at the scale of financial exposure security professionals in the sector have reported.

Phishing remains the most commonly reported attack, affecting 90% of organisations represented in the survey. Stealing or compromising credentials can give attackers a route into systems without having to defeat their technical security directly.

Separate analysis of the Bridewell findings says compromised credentials were the most common entry point for organisations’ most significant attacks, cited by 30% of respondents. Third-party and supply-chain access accounted for 13.2%.

Why airport operational systems are the bigger concern

The potential consequences become more serious when cyber risk moves from conventional information technology into operational technology, or OT.

Operational technology controls or monitors physical equipment and processes. In an airport environment, this can include access-control systems, surveillance, telecommunications, operations centres and industrial control systems that support utilities and other infrastructure.

TSA Touchless ID
Photo: TSA

The US Transportation Security Administration identifies information and operational technology as critical to safe, secure and efficient aviation operations. Its aviation security strategy also covers systems used for electricity, fuel delivery, climate control and other airport infrastructure.

The US Government Accountability Office’s July 2026 review of FAA and TSA cybersecurity efforts found that aviation’s interconnected systems face vulnerabilities including insecure operational technology, poor separation of IT and OT networks and insecure supply chains.

Bridewell found that 60% of respondents said they were extremely concerned about cyber threats to airport operational infrastructure and supply-chain partners.

The aviation ecosystem makes isolation difficult. Airlines connect with airports, ground handlers, manufacturers, maintenance providers, technology companies and numerous other suppliers.

Bridewell warns that a compromised system can potentially spread disruption through this connected network, affecting airports, airlines and handlers.

“Airlines, airports, manufacturers, and suppliers now all operate on interconnected technologies, so cyber resilience cannot be achieved by individual organisations working in isolation,” Kelechi Onyedebelu, Director Security Solutions Presales at Bridewell US, said in the company’s announcement of the report. 

US regulators are already treating OT as an aviation security issue

The TSA has introduced cybersecurity requirements for certain airport and aircraft operators. The FAA says those measures include separating IT and operational technology networks so one can continue operating safely if the other is compromised.

The requirements also cover access controls, continuous monitoring and detection, and timely security patching.

American Airlines A319
Photo: Nate Hovee / stock.adobe.com

The TSA’s cybersecurity terminology defines a reportable incident as including unauthorised access to IT or OT systems, malware affecting their availability and denial-of-service attacks, as well as incidents capable of causing operational disruption.

Cyber resilience is also becoming part of the wider modernisation of US aviation infrastructure. 

FAA Administrator Bryan Bedford told Congress this month that the planned FAA Enterprise Network Services network would provide stronger cybersecurity and resilience while replacing ageing telecommunications infrastructure connecting airports, weather systems, radar, voice communications and aircraft.

Aviation companies are spending more – but skills are scarce

More than three-quarters of Bridewell respondents said their cybersecurity budgets had increased during the current fiscal year. Some 44.8% reported increases of between 1% and 10%.

Finding people with the necessary expertise remains difficult.

Some 40% identified recruiting specialists in AI and machine-learning security as their biggest skills challenge. Almost the same proportion, 39.6%, reported difficulty finding cybersecurity professionals with aviation-specific regulatory expertise.

“What we’re seeing is that the aviation industry is under sustained pressure and experiencing significant financial losses as a result,” Onyedebelu said. “At the same time, organisations are also having to balance immediate threats with longer-term concerns around skills shortages, changing regulations, and emerging technologies.”

The Bridewell research points to a cybersecurity problem that extends beyond protecting passenger information or corporate computer networks.

As aviation becomes more digitally connected, protecting the systems that move passengers, aircraft, baggage, and information through airports is critical to protecting airline operations.

Sign up for our newsletter and get our latest content in your inbox.

More from