Skip to main content

Aviation Cybersecurity: Enhanced Air Safety Requires FAA to Better Mitigate Threats to Aircraft Communications

GAO-26-108439 Published: Sep 21, 2026. Publicly Released: Sep 21, 2026.
Jump To:

Fast Facts

The Federal Aviation Administration provides air traffic services for more than 44,000 flights and 3 million people per day.

FAA's air traffic and data communications systems are vulnerable to cyber threats. These threats are continuously evolving and include spectrum interference, spoofing and jamming, and more.

While FAA has identified spectrum-related threats, it hasn't sufficiently addressed them. For example, there are tools that monitor for such threats in real time, but FAA doesn't currently have them. Consequently, FAA can only investigate incidents after they've been reported.

Our recommendations address this and more.

Air traffic control tower with airplane flying nearby

Air traffic control tower with airplane flying nearby

Skip to Highlights

Highlights

What GAO Found

The Federal Aviation Administration (FAA) has identified electromagnetic spectrum-related threats, including spoofing and jamming, to the National Airspace System (NAS) and international flight routes. However, FAA has not completed risk and mitigation assessments, and updated security documentation needed to address these threats. Additionally, FAA did not have a defined, real-time monitoring and detection capability for all spectrum-related threats. Without comprehensive risk and mitigation assessments, complete security documentation, and real-time monitoring capabilities, FAA may not have sufficient information to identify, prioritize, and respond to evolving spectrum-related threats. As a result, spoofing, jamming, and other attacks could disrupt aviation communications, degrade situational awareness, and increase the risk of operational disruptions.

Potential Cyberattacks Impacting Aircraft Communications

Potential Cyberattacks Impacting Aircraft Communications

FAA participates in multiple collaborative efforts with other federal agencies as well as non-federal aviation industry stakeholders regarding cybersecurity. FAA's collaborative efforts fully addressed two of the eight leading practices and partially addressed six. While FAA has defined roles and responsibilities within interagency groups, it has not established policies or procedures for information sharing, reporting, and coordination with non-federal partners outside those groups. Fully implementing leading collaboration practices could strengthen FAA's ability to effectively coordinate with key partners to mitigate cybersecurity threats affecting the aviation sector and thereby avoid fragmented and inefficient responses to incidents.

The communication applications that FAA, pilots, and aviation stakeholders use to exchange text-based information are vulnerable to cyber threats, including interception and spoofing, due to limitations related to authentication, encryption, and protocol design. For example, a malicious actor could transmit fraudulent clearance cancellations, possibly leading to flight delays or safety issues. Until FAA develops and implements a plan to strengthen authentication and data protection for these applications, malicious actors could exploit weaknesses and increase the risk of disrupted flight operations, aviation accidents, or safety incidents.

Why GAO Did This Study

Commercial flight operations rely on interconnected systems that reside onboard an aircraft and on the ground in the NAS. These systems use radio frequency signals transmitted through the electromagnetic spectrum to communicate. The Servicemember Quality of Life Improvement and National Defense Authorization Act for Fiscal Year 2025 includes a provision for GAO to review the vulnerability of the NAS to spectrum attacks and to assess efforts to prevent and prepare for such attacks.

This report examines, among other objectives, the extent to which FAA has identified and mitigated spectrum-related cybersecurity threats; the extent to which FAA has collaborated with federal partners to defend against cybersecurity threats; and what specific cybersecurity vulnerabilities exist in key communication applications.

To address these objectives, GAO analyzed FAA vulnerability assessments to identify spectrum-related threats to the NAS. GAO selected eight spectrum-dependent systems and assessed them against National Institute of Standards and Technology guidance. GAO also assessed key FAA collaboration mechanisms against leading practices. In addition, GAO reviewed FAA documentation to identify vulnerabilities with communication applications. GAO interviewed FAA officials and federal and non-federal stakeholders.

Recommendations

GAO is making nine recommendations to FAA to strengthen its management of spectrum cybersecurity risks, enhance collaboration, and improve the security of aviation communication applications. The Department of Transportation, responding on behalf of FAA, concurred with the nine recommendations.

Recommendations for Executive Action

Agency Affected Recommendation Status
Federal Aviation Administration The Administrator of FAA should develop a formal risk assessment report that addresses, analyzes, and documents specific risks to the seven of eight identified NAS systems arising from but not limited to threats such as spectrum attacks, spoofing, and jamming. (Recommendation 1)
Open
When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Federal Aviation Administration The Administrator of FAA should conduct a review of system categorization for the one system we reviewed to ensure all system documents are consistent and align with the appropriate system impact level. (Recommendation 2)
Open
When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Federal Aviation Administration The Administrator of FAA should implement capabilities to continuously monitor threats such as interference, spoofing, and jamming to aviation communications links within the National Airspace System. (Recommendation 3)
Open
When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Federal Aviation Administration The Administrator of FAA should, in coordination with partner agencies, develop methods to monitor and assess progress toward short- and long-term outcomes in interagency groups to ensure accountability. (Recommendation 4)
Open
When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Federal Aviation Administration The Administrator of FAA should, in conjunction with partner agencies, develop formal guidance on information sharing outside of interagency groups. (Recommendation 5)
Open
When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Federal Aviation Administration The Administrator of FAA should, in conjunction with interagency partners, describe how leadership roles in interagency groups will be sustained over the long-term, including in the event of resignation, reassignment, or retirement of the individual serving in that leadership role. (Recommendation 6)
Open
When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Federal Aviation Administration The Administrator of FAA should work to clarify the roles and responsibilities for information sharing with non-federal partners outside of interagency groups. (Recommendation 7)
Open
When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Federal Aviation Administration The Administrator of FAA should work with federal and non-federal partners to ensure that all relevant stakeholders are included in FAA's collaborative efforts both within, and outside of, interagency groups. (Recommendation 8)
Open
When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.
Federal Aviation Administration The Administrator of FAA should, in conjunction with federal and non-federal partners, develop and implement a plan to strengthen authentication and data protection for ACARS and CPDLC communications to mitigate risks of spoofing, unauthorized transmissions, and message tampering. (Recommendation 9)
Open
When we confirm what actions the agency has taken in response to this recommendation, we will provide updated information.

Full Report

GAO Contacts

Media Inquiries

Sarah Kaczmarek
Managing Director
Office of Public Affairs

Public Inquiries

Topics

AviationCybersecurityAircraftCommunicationsInformation securityPublic and private partnershipsSpectrum managementBroadcasting standardsGlobal positioning systemInformation sharing