GAO warns of spoofing risk to aircraft data
A US watchdog warns that cybersecurity flaws in aircraft communications systems could let attackers send fake air traffic control messages, including

The US Government Accountability Office (GAO) warns that malicious actors could send fraudulent air traffic control messages to aircraft. This could include fake clearance cancellations, potentially disrupting flights and creating safety hazards.
In a report published on September 21, 2026, the watchdog identified cybersecurity weaknesses in aircraft communications systems. It also found gaps in the Federal Aviation Administration’s (FAA) ability to detect and respond to threats like spoofing and jamming. The findings concern vulnerabilities that could be exploited, not confirmed instances of fraudulent ATC clearances being transmitted.
Aircraft data links vulnerable to spoofing
The GAO report examined two key communications systems: the Aircraft Communications Addressing and Reporting System (ACARS) and Controller-Pilot Data Link Communications (CPDLC). These digital systems allow crews and ground personnel to exchange operational information, reducing reliance on voice radio.
The watchdog found both systems are vulnerable to interception and spoofing. Weaknesses exist in authentication, encryption, and protocol design. A malicious actor could exploit these flaws to transmit fraudulent messages. The report warned this could lead to flight delays or safety issues.
GAO called on the FAA to work with federal agencies and aviation industry stakeholders. It recommended developing and implementing a plan to strengthen authentication and data protection. The plan should specifically address spoofing, unauthorized transmissions, and message tampering.
FAA lacks comprehensive real-time threat monitoring
The watchdog also identified shortcomings in the FAA’s response to electromagnetic spectrum threats. These include spoofing and jamming along US and international flight routes.
Although the agency has identified these threats, it has not completed necessary risk assessments, mitigation assessments, and security documentation. GAO examined eight spectrum-dependent systems and recommended formal risk assessments for seven of them.
The FAA also lacks a defined capability to continuously monitor and detect all spectrum-related threats in real time. As a result, it generally relies on incidents being reported before investigations can begin.
The findings follow repeated warnings about interference with satellite navigation. In September 2025, a coalition of aviation and maritime industry groups urged the US government to strengthen defenses against GPS jamming and spoofing.
GAO separately examined the FAA’s cybersecurity collaboration. It found the agency fully met only two of eight leading practices, partially addressing the remaining six. While responsibilities have been established within interagency working groups, the FAA has not formalized information-sharing and coordination procedures with partners outside those groups.
FAA accepts recommendations amid outage
GAO issued nine recommendations covering spectrum risk assessments, continuous threat monitoring, interagency collaboration, and aircraft communications security. The US Department of Transportation (DOT), responding on behalf of the FAA, concurred with all nine. Each recommendation remained open when the report was released, pending confirmation of corrective action.
The report's publication coincided with a major ATC communications outage. On September 21, 2026, an outage disrupted flights across the New York area and at Philadelphia International Airport (PHL).
FAA Administrator Bryan Bedford attributed the disruption to the failure of a primary communications circuit at the Philadelphia Terminal Radar Approach Control facility. A severed backup fiber-optic connection compounded the problem. The outage was not attributed to a cyberattack.
The vulnerabilities are not unique to the US. The European Union Aviation Safety Agency (EASA) has also identified the risk of fraudulent messages being injected into aircraft communications. In August 2026, researchers from ETH Zurich and armasuisse Science and Technology demonstrated the injection of fake CPDLC instructions in a controlled test using real avionics hardware.





