Drooid Logo
Back to story perspectives

Full Breakdown

GAO Report Finds U.S. Air-Traffic Communications Insecure

By Drooid · · How we work

Core Findings of the GAO Report

The Government Accountability Office (GAO) concluded that the technology used by U.S. air-traffic controllers to communicate with commercial aircraft is “incredibly insecure.” The agency said the FAA has not completed required risk assessments, has not updated security documentation for spoofing and jamming threats, and lacks a real-time detection capability for all spectrum-related hazards. Hackers could transmit fraudulent clearance cancellations or other messages, potentially causing flight delays, air-space disruptions, or safety incidents.

Background on Aviation Communication Systems

The two primary systems for sending messages to aircraft were developed before modern cybersecurity safeguards became common and do not employ standard encryption. Similar spoofing and jamming problems have plagued Europe, where Estonia and Finland have blamed Russia for GPS-jamming in regional airspace—a charge Moscow denies. A 2025 incident involving a Spanish military jet carrying the country’s defense minister highlighted the tangible risk of signal interference.

Official Reactions

“This sobering report from GAO reveals that the technology used by air traffic controllers to communicate with aircraft is incredibly insecure, can be intercepted, impersonated, and jammed, and that hackers and foreign governments can exploit these vulnerabilities to disrupt air travel and even put passengers at risk,” — Ron Wyden, senator

The Federal Aviation Administration (FAA) responded by agreeing with all nine GAO recommendations.

Implications for Safety and Security

If malicious actors intercept or impersonate controller messages, the resulting misinformation could disrupt airline schedules, compromise air-space coordination, and endanger passengers.

Data & Statistics

  • GAO: FAA has not completed risk assessments for communication-system vulnerabilities.
  • GAO: FAA has not updated security documentation addressing spoofing and jamming.
  • GAO: FAA lacks a real-time detection capability for all spectrum-related threats.

These gaps underscore the urgency of implementing encryption and detection measures to protect the nation’s air-traffic infrastructure.