Coin-sized device exposes new cybersecurity threat for Boeing 737 systems
Fifteen seconds. No special tools. And a piece of electronics barely bigger than a coin.
That was enough for security researchers to reach a maintenance connection on a Boeing 737 and show how a tiny device planted there could interfere with communications between important aircraft computers – potentially changing a flight plan or feeding misleading information to the cockpit.
The discovery sounds like the plot of an aviation thriller. But the research is real.
A team from the University of California San Diego and Oberlin College demonstrated the technique using genuine Boeing 737 avionics, raising an unusual question about what an attacker with brief physical access to an aircraft might be able to do.
There is an important qualification. Nobody hacked a passenger aircraft in flight. The work was conducted under controlled research conditions in a laboratory environment. Turning it into a real-world attack would require physical access to the aircraft, specialist knowledge, advance preparation and the ability to install hardware without being detected.
What makes the experiment remarkable is the simplicity of the opening.

“You can get to it with no special tools in about 15 seconds,” UC San Diego computer science professor Stefan Savage told WIRED. The complete installation of the experimental device was designed to take less than a minute.
Once there, however, the device could insert itself into communications between aircraft systems. And that is where an unusual laboratory experiment becomes a much bigger aviation-security story.
How researchers used a coin-sized device to target Boeing 737 avionics
The researchers focused on a maintenance connection accessible through the aircraft’s Electronics and Equipment bay beneath the cockpit.
It provided a route to communications involving the Flight Management Computer, or FMC, and cockpit flight-management equipment used by pilots.
The team developed a small electronic implant that could be attached to the connection. The device was roughly coin-sized and cost less than $100 to build, according to the researchers.
The vulnerability centres on ARINC 429, a communications standard widely used to move information between avionics systems.
Rather than breaking into the aircraft in the conventional sense of hacking a computer network, the researchers found they could inject electrical signals onto the avionics data bus. Their technique could overpower legitimate signals and substitute manipulated information.
In laboratory demonstrations, the researchers were able to interfere with the aircraft’s flight-management information, including altering a flight plan and manipulating data used in calculations such as aircraft weight and other parameters important to flight operations. They also explored how changes could be concealed from what the pilot sees.
That distinction is important.
The researchers were not demonstrating that somebody sitting at home with a laptop could suddenly seize control of a Boeing 737 crossing the Atlantic. The scenario begins with somebody gaining access to the aircraft while it is on the ground and physically installing a prepared device.
How the Boeing 737 cybersecurity research was developed
Perhaps the most unusual part of the research is where the idea came from.
The team looked at the tiny skimming devices criminals have used on payment equipment to steal card information and wondered whether a similar principle could be applied to an aircraft.
Instead of stealing information from a payment terminal, could a small device inserted into an aircraft communications system quietly manipulate the information passing through it?
Answering that question required considerably more work than the eventual 15-second access time suggests.
Researchers spent years studying Boeing wiring diagrams and obtaining genuine commercial-aircraft electronics from the second-hand market.
They eventually assembled an avionics test environment using real Boeing 737 components. The laboratory set-up allowed them to investigate how the systems communicated without experimenting on an operational passenger aircraft.
The result was an unusual cybersecurity laboratory: effectively the electronic nervous system of parts of a 737, but without the wings, fuselage or passengers.
What Boeing says about the 737 avionics security findings
The findings were not sprung on Boeing after publication.
The researchers first disclosed the vulnerability to the manufacturer in 2020 and subsequently worked with Boeing, including demonstrating the technique in a company test environment.
Boeing has stressed that the research does not translate easily into a practical attack against an operational aircraft.

After reviewing the relevant aircraft designs, installations and interfaces, the company said existing protections in the aircraft and its operating environment significantly restrict the feasibility and risk of real-world exploitation.
That is a crucial part of the story.
A would-be attacker would need to know which aircraft to target, gain legitimate or unauthorised access to it on the ground, reach the appropriate area, install a specially prepared device and do all of this without attracting attention.
Nor did the experiment establish that pilots would be helpless if manipulated information appeared in the cockpit. Flight crews have procedures and other sources of information available to identify abnormalities and retain the ability to intervene.
There is also no evidence that this technique has been used against an operational passenger aircraft.
Does the research apply to other Boeing 737 models?
There is another distinction worth making.
The research concerned a Boeing 737 Next Generation avionics configuration. The 737 NG family covers the -600, -700, -800 and -900 series.

The findings should therefore not simply be applied to every aircraft carrying the 737 name. They do not establish that the older 737 Classic or newer 737 MAX families have identical installations or the same vulnerability.
That matters because the 737 has been produced across several generations over more than half a century, with major changes to its avionics along the way.
The research nevertheless has implications beyond one aircraft model because ARINC 429 and similar legacy architectures are widely used across commercial aviation.
What the Boeing 737 findings mean for aviation cybersecurity
Much of the public discussion about aircraft hacking has concentrated on remote threats.
Could somebody attack an airliner through Wi-Fi? Could satellite communications be compromised? Could navigation signals be spoofed? Could somebody sitting thousands of miles away somehow reach flight-critical systems?
This research approached the problem from the opposite direction.
What if the attacker is already standing beside the aeroplane?
Commercial aircraft spend hours on the ground surrounded by people who have legitimate reasons to approach them. Engineers inspect them. Mechanics open panels. Ground crews service them. Aircraft routinely pass through maintenance facilities in different countries during operational lives measured in decades.
Maintenance connections exist because those aircraft need to be serviced.
The researchers’ work suggests that such physical access points increasingly need to be considered part of aviation cybersecurity as well as conventional airport security.
It is also why the 15-second figure is both striking and potentially misleading. Fifteen seconds may be enough to reach the relevant connection. Creating the device, understanding the aircraft, gaining access and carrying out an actual attack would be another matter entirely.
The researchers themselves have tried to keep the findings in perspective. They continue to fly on Boeing 737s and have not presented their work as evidence that passengers should avoid the aircraft.
The point of finding a vulnerability in a laboratory is to deal with it before somebody attempts to exploit it elsewhere.
After years spent collecting discarded avionics, deciphering wiring diagrams and building their own 737 testbed, the researchers have demonstrated something rather simpler than the idea of hackers remotely taking over an airliner.
An aircraft does not need to be connected to the internet for cybersecurity to matter. Sometimes the way into a computer begins with someone standing underneath the aeroplane.











