
Washington, United States: The US Government Accountability Office (GAO) has identified cybersecurity weaknesses across Federal Aviation Administration (FAA) systems supporting aircraft communications, air traffic control and navigation, warning that gaps in risk assessments, security documentation and real-time monitoring could leave the National Airspace System exposed to spoofing, jamming and other spectrum-related threats.
The 58-page report, titled “Aviation Cybersecurity: Enhanced Air Safety Requires FAA to Better Mitigate Threats to Aircraft Communications,” was published and publicly released on 21 September 2026. GAO said the FAA has identified the threats but has not fully implemented measures needed to assess, detect and respond to them.
The FAA provides air traffic services for more than 44,000 flights and 3 million airline passengers each day across more than 29 million square miles of National Airspace System airspace. GAO found that spectrum interference, spoofing and jamming can disrupt, degrade or manipulate radio-frequency signals used for aviation communications, navigation and surveillance.
The agency cited previous incidents, including GPS interference around a Dallas-area airport in 2022 that affected arriving aircraft and resulted in more than 230 departure delays, and a 2022 incident near Denver International Airport involving an unauthorized transmitter that disrupted GPS-dependent systems. GAO also identified increasing GPS/GNSS interference along international routes, particularly around the Middle East, Eastern Europe, Southeast Asia and the Baltic region.
GAO’s review of eight spectrum-dependent NAS systems found several weaknesses in FAA’s security documentation and controls. Four systems still referenced NIST Special Publication 800-53 Revision 4, despite that standard being superseded in 2021, while five did not include all required baseline controls for high-impact systems. One system had conflicting security classifications across its documentation, and another had not completed its required annual security assessment since 2023. FAA completed some corrective actions after GAO’s review, but GAO said deficiencies remained. “Until the FAA fully aligns system documentation, security controls, system categorizations, and assessment activities with current federal requirements,” the agency may lack complete information for risk-based cybersecurity decisions, GAO said.
A major concern was the FAA’s ability to detect spectrum-related attacks as they happen. While the FAA’s cyber operations teams have tools to monitor network traffic, GAO found that the agency’s Spectrum Engineering office has limited ability to continuously monitor interference, spoofing and jamming.
FAA officials told GAO that the agency does not have continuous 24/7 monitoring for these threats and generally relies on incidents being reported before investigating them. GAO noted that technologies capable of continuously monitoring spectrum activity and generating alerts already exist, but the FAA does not currently have comparable capabilities. FAA officials also cited funding constraints as a factor limiting deployment of monitoring tools.
The report also examined FAA’s cooperation with federal and industry partners. GAO assessed FAA against eight leading practices for interagency collaboration and found that two were fully addressed and six were partially addressed. FAA participates in the Aviation Cyber Initiative, the Purposeful Interference Response Team/CRUCIBLE and the Interdepartmental Radio Advisory Committee, among other coordination mechanisms.
GAO found that the FAA has established common objectives and uses a range of technical and analytical resources, but identified weaknesses in accountability, leadership continuity, role definition, stakeholder participation and formal information-sharing arrangements.
GAO found that the FAA has no formal information-sharing agreements with the Department of Defense or Federal Communications Commission outside relevant interagency frameworks. Aviation stakeholders also reported limited information sharing, inconsistent communication over issue resolution and uncertainty about which FAA offices should handle spectrum-related concerns. GAO said the absence of clearly documented arrangements could weaken coordination during emerging cybersecurity incidents.
The report separately identified vulnerabilities in the Aircraft Communications Addressing and Reporting System (ACARS) and Controller Pilot Data Link Communications (CPDLC), two text-based communications applications used by aircraft, airlines and air traffic controllers. GAO said the systems were developed before modern cybersecurity safeguards became common and generally lack encryption and authentication.
As a result, messages can be vulnerable to interception, spoofing, flood-based denial-of-service attacks, jamming and other interference.
GAO described potential scenarios in which a malicious actor could transmit fraudulent CPDLC route modifications, altitude changes or clearances that appear to originate from ATC. Affected pilots would have to verify conflicting instructions through voice communications, potentially increasing workload and causing delays. In a more serious scenario, GAO said an attacker could modify, replay or inject ACARS or CPDLC messages that appear legitimate, potentially causing a pilot to act on false information. The report said such exploitation could increase operational disruption and flight-safety risks.
The report also noted that FAA and operators already use procedural safeguards. ACARS messages can be checked against flight identification, aircraft tail numbers and message sequence numbers, while pilots and dispatchers can cross-check unusual messages with flight plans and other communications.
CPDLC includes message acknowledgement, standardized formats, logon requirements and voice communications as a backup. GAO, however, said these measures do not provide the same protection as modern cryptographic authentication and message-integrity controls and can still depend on human verification.
The FAA told GAO that newer communications standards based on the Internet Protocol Suite (IPS) are being developed to improve aircraft data-communication security and eventually replace older technologies. FAA said IPS implementation is being tested at selected locations, but GAO said the agency has not provided documented deployment timelines. Wider implementation will depend partly on airlines equipping aircraft and obtaining approvals from manufacturers and operators. FAA officials also cited the limited availability of compatible avionics and ground infrastructure, as well as the cost and complexity of coordinating the transition.
GAO also found that the FAA does have cybersecurity requirements for new aircraft technologies. Through certification and operational approval processes, manufacturers must identify potential safety and security threats and propose mitigations. FAA evaluates whether systems can remain safe during conditions including signal loss, degradation, delay, misleading data and electromagnetic interference. Where existing regulations are insufficient, the FAA can impose aircraft-specific special conditions and require additional protections, monitoring, testing or architectural safeguards.
However, GAO noted that the FAA does not apply one standardised cybersecurity package to every new aviation technology. Requirements vary according to system architecture, connectivity and identified risks. FAA may also require Aircraft Network Security Programs to maintain cybersecurity protections throughout an aircraft’s operational life.
GAO ultimately issued nine recommendations to the FAA. They call for formal risk assessments covering seven of the eight reviewed NAS systems, a review of one system’s security categorisation, continuous monitoring for interference, spoofing and jamming, stronger accountability within interagency groups, formal information-sharing guidance, clearer leadership-continuity arrangements, clearer responsibilities for non-federal information sharing, broader stakeholder participation and stronger authentication and data protection for ACARS and CPDLC.
The Department of Transportation, responding on behalf of the FAA, concurred with all nine recommendations. DOT said it is strengthening its risk-assessment process to reflect the current threat environment and relevant guidance. It also said the Aviation Cyber Initiative will enhance outreach across the aviation ecosystem and that the FAA will continue working with government and industry to identify and mitigate emerging risks to the NAS. All nine recommendations were listed as open when the report was released.
GAO also made clear that its findings concern vulnerabilities and potential attack scenarios rather than a confirmed successful cyberattack on an aircraft that caused a safety impact. “Although the FAA has not experienced a successful cyberattack resulting in safety impacts,” GAO said, the evolving threat environment makes protection of aviation communications increasingly important.
The report was based on an audit conducted from April 2025 to September 2026 and included reviews of FAA records, cybersecurity controls, incident reports and academic research, along with interviews with federal agencies and aviation stakeholders. GAO said the evidence provided a reasonable basis for its findings and conclusions under generally accepted government auditing standards.




















