Clearance CLR-3291 · AIR706
AIRGAO
Airspace & RegulationClearance sheet
GAO warns of spoofed ATC messages as FAA accepts nine cybersecurity fixes
GAO report GAO-26-108439, published September 21, 2026, flags spoofing risks in ACARS and CPDLC. DOT concurred with all nine recommendations; FAA met only 2 of 8 collaboration practices.
Read-back
- GAO published report GAO-26-108439 on September 21, 2026
- DOT concurred with all nine GAO recommendations, all open at release
- GAO found FAA fully met only 2 of 8 cybersecurity collaboration leading practices
- FAA assessed 8 spectrum-dependent systems with formal risk assessments recommended on 7
- September 21, 2026 New York/Philadelphia ATC outage attributed to circuit failure, not a cyberattack
The US Government Accountability Office on September 21, 2026 published report GAO-26-108439, identifying cybersecurity weaknesses in two pilot-controller data systems and gaps in the Federal Aviation Administration's ability to detect spoofed transmissions. The Department of Transportation, responding on behalf of the FAA, concurred with all nine recommendations, each of which remained open as of release pending confirmation of corrective action.
Which data links are exposed?
The watchdog examined the Aircraft Communications Addressing and Reporting System (ACARS) and Controller-Pilot Data Link Communications (CPDLC), the digital channels airlines use to exchange clearances, weather data and operational messages without voice radio.
GAO concluded both are vulnerable to interception and spoofing because of weak authentication, limited encryption and protocol-design gaps. A malicious actor could inject fraudulent messages — including fake clearance cancellations — with the report warning this could result in "possibly leading to flight delays or safety issues."
GAO called on the FAA to work with federal agencies and industry to harden authentication and data protection, specifically covering spoofing, unauthorized transmissions and message tampering.
How ready is the FAA to spot an attack?
The FAA has identified electromagnetic-spectrum threats such as spoofing and jamming along US and international routes but has not completed the risk assessments, mitigation plans and security documentation needed to address them comprehensively.
GAO reviewed eight spectrum-dependent systems and recommended formal risk assessments on seven. The agency also lacks a defined capability to continuously monitor and detect spectrum-related threats in real time, and generally relies on incidents being reported before investigations can begin.
On cybersecurity collaboration, the FAA fully met only two of eight leading practices and partially addressed the remaining six, with interagency information-sharing procedures not formalized beyond existing groups.
What happened on the day the report dropped?
The report coincided with a controller-link outage that disrupted flights across the New York area and at Philadelphia International Airport (PHL).
FAA Administrator Bryan Bedford attributed the September 21, 2026 disruption to the failure of a primary communications circuit at the Philadelphia Terminal Radar Approach Control facility, compounded by a severed backup fiber-optic connection. The outage was not attributed to a cyberattack.
Is this only an FAA problem?
The risk is not US-specific. The European Union Aviation Safety Agency has separately identified the possibility of fraudulent messages being injected into aircraft communications. In August 2026, researchers from ETH Zurich and armasuisse Science and Technology demonstrated the injection of fake CPDLC instructions in a controlled test using real avionics hardware, presented at USENIX Security 26.
The GAO findings also follow a September 2025 coalition of aviation and maritime industry groups urging the US government to strengthen defenses against GPS jamming and spoofing.
What changes next?
Implementation timelines for the nine recommendations now sit with the DOT and FAA. Until the FAA closes its spectrum-monitoring gap and the data-link authentication weaknesses flagged in GAO-26-108439 are remediated, the regulator will continue to depend on crew reports and post-event analysis rather than real-time detection — leaving the cost of any spoofing incident to fall first on the carriers and controllers operating the affected flights.
via gao.gov (Original)
More from Sophie Lindqvist
Show full bio
Senior reporter covering industry trends and analytics at Flightdeck Report.
329 articles
Same bay
- FDR942NORAD to Enforce Temporary Flight Restrictions Over Multiple US Areas · September 30, 2026
- FDR797Fighter Jets Intercept Airspace Violators During Trump Chicago Visit · September 28, 2026
- FDR961Secret Service Sends Deputies to Marengo Airport After Airspace Violation · September 29, 2026
- FDR462In-Flight Attack on FlyDubai Pilot Renews Security Scrutiny · October 2, 2026
- FDR703Saudi Arabia opens air safety probe into flydubai incident · October 9, 2026