Somewhere within range of a major airport, a person with a software-defined radio that costs less than a nice dinner could transmit a message that looks, to a pilot’s instruments, exactly like a legitimate clearance from air traffic control. There is currently no reliable way for that pilot to know the difference. This is not the premise of a thriller; it is the finding of a Government Accountability Office report released September 21, 2026, on the cybersecurity of the systems that keep more than 44,000 daily flights and 3 million passengers from colliding. The FAA has known about this class of problem for years. It has, by GAO’s account, mostly gotten around to writing memos about it.
The ghosts in the frequency
The National Airspace System runs on radio frequency signals, the same physical medium used for GPS, radar, and every other invisible thread holding modern aviation together. GAO catalogs three ways to attack it (interference, spoofing, and jamming), each capable of degrading, faking, or simply killing the signals aircraft and controllers depend on. None of this is theoretical. In 2012, an individual jamming GPS transmissions near Newark Airport degraded a landing-approach system during pre-deployment testing. In 2022, GPS interference with signs of spoofing near a Dallas airport caused controller confusion and more than 230 departure delays; the same year, an unauthorized transmitter near Denver International disrupted navigation accuracy for civil flights. GAO also notes, in the driest possible register, that a December 2024 Azerbaijan Airlines flight was shot down amid GPS disruptions linked to the Russia-Ukraine conflict, an approach GAO describes as having “become more complex than usual” due to pilot and controller miscommunications. International GNSS interference is now concentrated enough to have hotspots, mapped in the report like weather systems, radiating out of the Middle East, Eastern Europe, Southeast Asia, and the Baltic region.
FAA is well aware of all this. Awareness, GAO’s report makes clear, is where the agency’s competence currently ends. This is also the third GAO aviation cybersecurity report in as many years; a September 2024 report found 51 of FAA’s 138 air traffic control systems outright unsustainable, and a July 2026 report found FAA had fully implemented only two of its own seven cybersecurity strategy goals.
Assessed, in a general sort of way
Federal information security law requires agencies to run risk assessments for individual systems, evaluating specific threats, vulnerabilities, and likely impact under NIST Special Publication 800-53 Rev. 5, and FAA’s own internal order requires the same. For seven of the eight spectrum-dependent NAS systems GAO reviewed, FAA had not done this. Instead it points to one general spectrum risk assessment covering everything at once, which GAO politely observes “does not satisfy the NIST recommendation” because it treats every system’s exposure as roughly identical rather than evaluating each one’s actual architecture and controls.
The paperwork underneath these systems is not in better shape. Four of the eight still cite a NIST standard that was superseded in 2021. Five are missing required security controls for high-impact systems, including contingency planning and denial-of-service protection. One system’s documents cannot agree with each other on whether the system is high impact or merely moderate. One had not had its required annual security assessment done since 2023. A separate DOT Inspector General audit, cited in the report, found the same pattern of stale NIST standards and missing controls across FAA’s high-impact systems.
Real-time monitoring, the thing that would actually let FAA notice an attack while it is happening rather than reconstructing it afterward, does not fully exist. FAA’s Spectrum Engineering office told GAO it has no 24/7 monitoring capability and lacks the specialized tools to detect interference or spoofing as it occurs; instead it investigates after someone reports a problem. The agency’s own Wide Area Augmentation System can flag degraded GPS performance but cannot detect spoofing or identify where it came from. FAA officials cited funding constraints as the reason certain monitoring tools have not been deployed to high-risk sites. It is worth sitting with that sentence; the nation’s air traffic infrastructure lacks live detection for signal spoofing because of a budget line item.
A coalition of the partially willing
FAA does talk to other agencies about all this, and GAO gives it credit for two of the eight leading interagency collaboration practices it measured against, defining common outcomes and leveraging shared resources, chiefly through the Aviation Cyber Initiative, the Purposeful Interference Response Team, and the Interdepartmental Radio Advisory Committee. The other six practices were only partially met, and the gap has a consistent shape. Inside the formal interagency groups, FAA has charters, bylaws, and defined roles. Outside them, it has almost nothing. FCC and DOD officials told GAO they routinely share information with FAA through informal channels with no documented policy governing how or when. Some aviation industry stakeholders told GAO they were unsure which FAA office to even contact about a spectrum issue, and some reported wanting more access to the incident coordination calls that already exist. FCC itself was apparently dropped from continued participation in the Aviation Cyber Initiative after an earlier interagency taskforce wound down in 2021, and nobody seems to have noticed enough to fix it.
Clearance to land, or so says somebody
The most concrete vulnerability in the report involves two applications that pilots and controllers actually use every day, ACARS, which handles operational messaging between aircraft and airlines, and CPDLC, which lets controllers send digital text clearances as an alternative to voice. Both predate modern cryptography as a design assumption. Neither is encrypted. Neither authenticates the sender. GAO walks through, with illustrated step-by-step diagrams, how a malicious actor could pull public flight-tracking data, transmit a spoofed clearance cancellation over VHF using nothing more exotic than a software-defined radio, and force a pilot into a verbal shouting match with real air traffic control to sort out which instruction is genuine. Do that to several aircraft at once and you have delayed departures, an overloaded controller workload, and, in a worse version of the same scenario, a pilot who follows a fabricated altitude or route change believing it came from ATC.
FAA’s defense against all this is essentially procedural rather than technical: message-format standardization, mandatory acknowledgments, and the expectation that a suspicious pilot will simply pick up a voice radio and ask. These are reasonable stopgaps. They are also, as GAO notes, “not designed to provide the same level of protection as modern cryptographic controls,” which is a generous way of saying the agency is trusting human vigilance to compensate for a protocol built before anyone thought to secure it. A next-generation replacement, built on standard internet protocols, is in testing at select locations. FAA has not given GAO a timeline for when, or whether, it will actually replace the systems currently in use.
GAO issued nine recommendations, covering system-specific risk assessments, consistent categorization, real-time monitoring, interagency accountability, sustained leadership, formal information-sharing agreements outside the existing clubs, broader stakeholder inclusion, and a plan to actually authenticate ACARS and CPDLC traffic. The Department of Transportation, replying on FAA’s behalf, concurred with all nine and promised a detailed response within 180 days, the standard federal-agency interval for “we will get back to you, eventually, with something.” Bureaucracy Times will be checking the calendar.
