Washington, D.C./ Transportation & Infrastructure

Federal Watchdog Warns FAA Aircraft Communications Remain Open to Hacking, Jamming

AI Assisted Icon
Published on September 21, 2026
Federal Watchdog Warns FAA Aircraft Communications Remain Open to Hacking, JammingSource: Tech. Sgt. Peter R. Miller / U.S. Air Force / Wikimedia Commons

The technology that air traffic controllers use to talk to commercial airplanes across the United States is riddled with security gaps that could let hackers intercept, impersonate, or jam those communications, according to a new report from the Government Accountability Office. The watchdog agency found the Federal Aviation Administration has not finished the risk assessments and updated security documentation needed to address spoofing and jamming threats, raising fresh questions about how well the nation's air traffic system is protected from bad actors.

The report, detailed by Reuters, found that the FAA also lacks real-time detection capability for all spectrum-related threats, meaning the agency may not know in the moment when something is interfering with signals used to guide planes. As Journal Record reporter David Shepardson wrote for The Journal Record, the vulnerabilities extend to how the FAA oversees the systems tasked with keeping pilots and controllers connected.

According to the GAO findings reported by Reuters, hackers could transmit fraudulent clearance cancellations or other bogus messages directly to airplanes, a scenario that could trigger flight delays, airspace disruptions, or outright safety issues. The report also singled out two aircraft messaging systems that were built before modern cybersecurity safeguards became standard practice and still lack common encryption protections, according to the same Reuters account.

Senator Says Insecure Links Threaten National Security

Senator Ron Wyden said communications between U.S. air traffic controllers and commercial airplanes are insecure and argued the FAA must address the threats, framing the agency's failure to require secure communications across the aviation industry as a risk to national security, the economy, and the safety of the flying public. The FAA did not immediately comment on the report, per the Reuters account, and a separate report from kansas.com likewise noted the agency offered no immediate response.

For its part, the FAA acknowledged in the report that cyber and electromagnetic vulnerabilities pose increasing risks to critical systems, including air traffic control, data communications, and avionics. The agency agreed with all nine of the GAO's recommendations, though the specifics of how and when those fixes will be implemented were not detailed in the findings.

Europe Offers a Preview of the Risks

The GAO report arrives as spoofing and jamming have already become a major headache for critical satellite navigation systems in Europe. Estonia and Finland have both blamed Russia for jamming GPS navigation devices in the region's airspace, an accusation Moscow has denied, illustrating how attribution for these incidents can remain contested even when the disruption itself is well documented.

Sweden recorded 733 GPS-jamming incidents over the Baltic Sea in 2025 alone, a sharp jump from just 55 incidents across all of 2023, according to the BBC. GPS interference in the region has increased since 2022, with disturbances concentrated near Kaliningrad and Finland's eastern border with Russia, per Reuters' earlier reporting on Estonia's complaints. In one especially stark example from that reporting, Finnair temporarily suspended flights to Tartu after GPS disturbances prevented two aircraft from landing.

A separate analysis from Spire Global detected 84 hours of GNSS interference over a six-month stretch in 2024, with 29 of those hours concentrated in October alone. During that October period, disruptions lasted up to seven hours at a time and produced position errors exceeding 30 meters — enough, Spire's researchers found, to compromise safe routing for both ships and aircraft. The interference near the Baltic Sea affected civil aviation, NATO surveillance missions, and commercial maritime traffic alike, the firm reported.

Even High-Profile Flights Have Been Caught Up

The stakes of these vulnerabilities are not purely theoretical. One 2025 jamming incident, according to the GAO findings cited by Reuters, involved a Spanish military jet carrying Spain's defense minister onboard — a reminder that interference has already reached flights carrying senior officials, not just routine commercial traffic. Spire's analysis of more than 300 aircraft on October 14, 2024, found that the bottom five percent experienced a total collapse in the metrics used to measure GNSS positional accuracy and integrity.

Notably, the current findings do not claim that any hacker has actually succeeded in compromising or transmitting a fraudulent message through an FAA aircraft communication system — the report flags the vulnerability, not a confirmed breach. This is not the first time GAO has flagged weaknesses in the FAA's cyber defenses. The watchdog previously reported, per a 2015 GAO review, that the FAA had taken steps to protect its air traffic control systems from cyber-based threats but that significant security-control weaknesses remained even then — suggesting the gaps identified this week are part of a much longer pattern the agency has struggled to fully close.