started · updated
FAA aircraft communications identified as insecure by GAO report
A report from the Government Accountability Office (GAO) has identified “incredibly insecure” communication channels between U.S. air traffic controllers and commercial aircraft. Senator Ron Wyden noted that the vulnerabilities allow communications to be intercepted, impersonated, or jammed by hackers and foreign governments.
The GAO found that the Federal Aviation Administration (FAA) has failed to complete necessary risk assessments, update security documentation, or implement real-time detection for spectrum-related threats such as spoofing and jamming. Two primary messaging systems used by the FAA were developed before modern cybersecurity standards and lack standard encryption. These flaws could allow unauthorized parties to transmit fraudulent messages, such as clearance cancellations, potentially causing flight delays, airspace disruptions, or safety risks.
The FAA stated it agrees with the nine recommendations provided by the GAO, acknowledging that increasing interconnection in flight operations raises cyber and electromagnetic risks to air traffic control and avionics.
Entities
Federal Aviation Administration · Government Accountability Office · Ron Wyden