The US Government Accountability Office (GAO) has warned that malicious actors could send fraudulent air traffic control messages to aircraft, including fake clearance cancellations, potentially disrupting flights and creating safety hazards.
In a report published on September 21, 2026, the watchdog identified cybersecurity weaknesses in aircraft communications systems and gaps in the Federal Aviation Administration’s (FAA) ability to detect and respond to threats such as spoofing and jamming.
The findings concern vulnerabilities that could be exploited, not confirmed instances of fraudulent ATC clearances being transmitted.
Aircraft data links vulnerable to spoofing
The report examined two communications systems used by pilots, airlines and air traffic controllers: the Aircraft Communications Addressing and Reporting System (ACARS) and Controller-Pilot Data Link Communications (CPDLC).
These systems allow crews and ground personnel to exchange operational information digitally, reducing reliance on voice radio for certain communications.
GAO found that both are vulnerable to interception and spoofing because of weaknesses in authentication, encryption, and protocol design.
A malicious actor could exploit these vulnerabilities to transmit fraudulent messages, including fake clearance cancellations, “possibly leading to flight delays or safety issues,” the report warned.
GAO called on the FAA to work with federal agencies and aviation industry stakeholders to develop and implement a plan to strengthen authentication and data protection, specifically addressing spoofing, unauthorized transmissions and message tampering.
FAA lacks comprehensive real-time threat monitoring
The watchdog also identified shortcomings in the FAA’s response to threats affecting the electromagnetic spectrum, including spoofing and jamming along US and international flight routes.
Although the agency has identified these threats, it has not completed the risk assessments, mitigation assessments, and security documentation needed to address them comprehensively.
GAO examined eight spectrum-dependent systems and recommended formal risk assessments covering seven of them.
The FAA also lacks a defined capability to continuously monitor and detect all spectrum-related threats in real time. As a result, it generally relies on incidents being reported before investigations can begin.
The findings follow repeated warnings about interference with satellite navigation. In September 2025, a coalition of aviation and maritime industry groups urged the US government to strengthen defenses against GPS jamming and spoofing.
GAO separately examined the FAA’s cybersecurity collaboration with government agencies and industry stakeholders. It found that the agency fully met only two of eight leading practices, partially addressing the remaining six.
While responsibilities have been established within interagency working groups, the FAA has not formalized information-sharing and coordination procedures with partners outside those groups.
FAA accepts nine recommendations as report coincides with major outage
GAO issued nine recommendations covering spectrum risk assessments, continuous threat monitoring, interagency collaboration and aircraft communications security.
The US Department of Transportation (DOT), responding on behalf of the FAA, concurred with all nine. Each recommendation remained open when the report was released, pending confirmation of corrective action.
The report was published on the same day that an ATC communications outage disrupted flights across the New York area and at Philadelphia International Airport (PHL).
FAA Administrator Bryan Bedford attributed the September 21, 2026, disruption to the failure of a primary communications circuit at the Philadelphia Terminal Radar Approach Control facility, compounded by a severed backup fiber-optic connection. The outage was not attributed to a cyberattack.
The vulnerabilities are not unique to the US. The European Union Aviation Safety Agency (EASA) has also identified the risk of fraudulent messages being injected into aircraft communications. In August 2026, researchers from ETH Zurich, armasuisse Science and Technology, demonstrated the injection of fake CPDLC instructions in a controlled test using real avionics hardware.
