Key facts
- The FAA has not completed risk assessments and updated security documentation for aircraft communication threats like spoofing and jamming.
- The FAA lacks real-time detection capabilities for all spectrum-related threats.
- Hackers could transmit fraudulent clearance cancellations, potentially causing flight delays or safety issues.
- A July 2026 GAO report identified weaknesses in the FAA's cybersecurity planning, budget reporting, and Zero Trust implementation.
- Vulnerabilities exploited across aviation systems include poor software patch management and outdated operating systems.
A government watchdog has urged the U.S. Federal Aviation Administration (FAA) to enhance its efforts in addressing threats to aircraft communication systems, including spoofing and jamming. The Government Accountability Office (GAO) reported on Monday that the FAA has failed to complete necessary risk assessments and update security documentation to counter these threats. Furthermore, the agency lacks a real-time detection capability for all spectrum-related risks.
The GAO's findings suggest that malicious actors could potentially transmit fraudulent clearance cancellations, which could lead to flight delays or compromise aviation safety. A separate GAO report from July 2026 highlighted significant shortcomings in the FAA's aviation cybersecurity program, pointing to issues in planning, budget reporting, and the implementation of Zero Trust architecture.
While the FAA and the Transportation Security Administration (TSA) have improved their collaboration through the Aviation Cybersecurity Initiative, the GAO noted that critical gaps persist in the FAA's cybersecurity governance and the TSA's strategic planning. The reports also identified recurring vulnerabilities across aviation systems, such as inadequate software patch management, the use of outdated operating systems, and insecure supply chains. These weaknesses could leave critical aviation systems vulnerable to cyberattacks from state-sponsored actors, financially motivated cybercriminals, and hacktivist groups.
