ELINT · Electronic Intelligence

The FAA cannot see a spectrum attack in real time, and its datalinks cannot authenticate a message

A US oversight report published on 21 September found that the FAA investigates jamming and spoofing only after someone reports it, and that the two text datalinks carrying controller instructions have no workable authentication. Nine recommendations were accepted. None are closed.

The finding

The US Government Accountability Office published Aviation Cybersecurity: Enhanced Air Safety Requires FAA to Better Mitigate Threats to Aircraft Communications on 21 September 2026, as report GAO-26-108439 [1]. The congressionally mandated review examined three things: whether the FAA has identified and mitigated spectrum-related threats to the National Airspace System, how it collaborates with federal partners, and the security of specific communication applications [1][2].

The answer to the first is that the FAA has identified the threats and not addressed them. GAO records that the agency has named electromagnetic spectrum threats including spoofing and jamming, but "has not completed risk and mitigation assessments, and updated security documentation" for them [1][2]. AVweb, reading the full report, puts the shortfall at seven of eight spectrum-dependent systems reviewed [3].

The operative sentence is narrower and more useful. The FAA lacks "a defined, real-time monitoring and detection capability for all spectrum-related threats" [2]. It waits for an incident report and then investigates [3]. GAO notes the technology to monitor in real time exists [3].

The datalink finding is the more serious one

GAO also examined the text-based applications that carry controller instructions and operational data between aircraft and the ground. It found ACARS and CPDLC "vulnerable to cyber threats, including interception and spoofing, due to limitations related to authentication, encryption, and protocol design" [1][2]. The scenario GAO puts in the highlights is specific: a malicious actor could transmit fraudulent clearance cancellations, "possibly leading to flight delays or safety issues" [2][4].

None of this is a new technical discovery. Strohmeier, Martinovic and Lenders documented that ACARS generally offers no authentication or confidentiality, that the ARINC 823 security standard written to address it has seen no adoption in practice, and that CPDLC offers neither [7]. What changed on 21 September is that a national oversight body wrote the gap into a formal recommendation and the regulator accepted it.

The research position has also moved. At USENIX Security 2026 in August, Ziazi, Aleem, Sathaye and Strohmeier presented practical message attacks on CPDLC, demonstrating hijack of the controller-pilot link with a rogue ground station and a denial of service capable of disabling CPDLC service for every aircraft in transmission range [6]. The work used real, certifiable avionics hardware in a test environment built with air navigation service providers and manufacturers, which removes the usual objection that laboratory results do not transfer [6]. Their assessment is that the protocol does not implement encryption and relies primarily on complexity and obscurity as a barrier to misuse, and that datalink security standardisation needs urgent attention [6].

Scale makes that matter. European airspace mandates CPDLC above FL285 under Regulation 2023/1770, and it carries level assignments, vectors, speed control, direct routing and SSR code changes [8].

Nine recommendations, all accepted, none closed

GAO made nine recommendations [1][2]. They cluster into three groups:

  • Risk management: complete a formal risk assessment for the systems that lack one, review system categorisation for consistent impact levels, and implement continuous monitoring of interference, spoofing and jamming [1].
  • Collaboration: define how progress in interagency groups is tracked, formalise information sharing outside those groups, clarify long-term leadership, and define roles for non-federal partners [1]. GAO assessed the FAA's collaborative work as fully addressing two of eight leading practices and partially addressing six [1][2].
  • Communications: develop and implement an authentication and data protection plan for ACARS and CPDLC [1].

The Department of Transportation, responding for the FAA, concurred with all nine [1][2]. All nine are recorded as open pending confirmation of corrective action [1][4]. Senator Ron Wyden, who had pressed the issue, described aircraft communications with the FAA as "incredibly insecure, can be intercepted, impersonated, and jammed" [5]. The agency's own response acknowledged that as aircraft and flight operations become more interconnected, cyber and electromagnetic vulnerabilities pose increasing risks to critical systems [5].

What a reporting-driven picture cannot show

One recent case illustrates the monitoring gap without proving anything about cause, and the distinction has to be kept. On 14 May 2026 a Beech C90 air ambulance struck terrain near Lincoln, New Mexico, killing four. The NTSB preliminary report records that military jamming was active during the flight, that three other aircraft reported losing GPS in the area, that controllers asked the military to stop the operation, and that the crew reported losing GPS capability and requested vectors [12]. The NTSB subsequently issued a public statement refuting a viral claim that blamed the military, stressing that no probable cause or contributing factors have been established [13].

That is not evidence that jamming caused an accident. It is evidence that a jamming condition affecting multiple aircraft was characterised only afterwards, from crew reports and a controller's call. That is the missing capability, described from the outside.

Where somebody is looking, the data exists. The FAA's own GNSS Interference Resource Guide, version 1.1 of 12 March 2026, carries IATA's figure that the rate of loss of GNSS per 1,000 flights rose 65% in the first half of the year against 2023, and identifies Nicosia as the most-affected flight information region with 5,655 spoofing incidents [9]. Lo and colleagues at Stanford detected spoofing worldwide using crowdsourced ADS-B data, ground receivers and multilateration, including events over Myanmar from August 2024 and near the India-Pakistan border, with pattern geometry small enough to indicate drones rather than airliners as the intended targets [10]. Their conclusion is that aviation can no longer ignore GNSS spoofing [10]. Both datasets were built from receivers and reports that already exist.

The regional reading

Asia-Pacific operators already carry the reporting half of this. Singapore's CAAS Safety Information Bulletin 2022-01 R3 requires AOC holders to report loss of system function from GNSS interference, confirmed spoofing, interference in unexpected locations, false triggering of GPWS and TCAS, and deviations from ATC clearance, and instructs crews to report anomalous GNSS performance to ATC regardless of location [11]. Its list of affected areas names Yangon alongside the Black Sea, Baltic and eastern Mediterranean [11].

That is a duty on operators to describe what they experienced. It is not a monitoring capability at the service provider, and the two are not substitutes. An obligation to report produces narratives with inconsistent timing and no RF measurement. A monitoring capability produces a time series correlatable across aircraft, which is the only way to separate a local receiver fault from a regional emission.

What to do

  • Treat interference as a telemetry problem. Instrument the receivers and surveillance feeds already in service – integrity flags, ADS-B position and velocity consistency, approach abandonment rates by procedure – and retain the series.
  • Assume datalink messages are unauthenticated, because they are [6][7]. Where an instruction has operational consequence and arrives by CPDLC or ACARS, the control is procedural confirmation on a second channel, not trust in the link.
  • Record declared jamming windows as configuration, not as notices. A NOTAM warning that GNSS, WAAS, GBAS and ADS-B may be unavailable is a predicted degradation of specific procedures at specific times [12], and should drive dispatch and approach planning automatically rather than being read once at briefing.
  • Report anomalies even when the flight was uneventful. The regional datasets that exist are built from voluntary reports and crowdsourced receivers [9][10][11].
  • For operators into US airspace, track the recommendations rather than the headline. The ACARS and CPDLC authentication plan is the one that will eventually change avionics and procedures [1].

Domain close

The electromagnetic spectrum is not a background condition in aviation. It is the transport layer for navigation, surveillance and, increasingly, instruction. GAO's report says the agency responsible for the busiest airspace in the world can identify threats to that layer but cannot watch it, and that the messages crossing it cannot prove who sent them. Both findings were accepted without argument. Neither is fixed. For anyone running a fielded receiver or datalink estate, the sequencing is the transferable lesson: monitoring has to be built during the quiet period, because after the incident all that can be collected is testimony.

Sources

Every R3KONX article cites its primary material. 13 sources, in order of first citation. Links open the original publication.

  1. Aviation Cybersecurity: Enhanced Air Safety Requires FAA to Better Mitigate Threats to Aircraft Communications (GAO-26-108439) US Government Accountability Office · 2026-09-21
  2. GAO-26-108439 Highlights US Government Accountability Office · 2026-09-21
  3. GAO Flags FAA Jamming, Spoofing Gaps AVweb · 2026-09-22
  4. Fake ATC messages could disrupt US flights, GAO warns AeroTime · 2026-09-22
  5. US Aircraft Communications With FAA 'Incredibly Insecure,' Senator Says Claims Journal (Reuters) · 2026-09-21
  6. Sliding into the Flight Deck's DMs: Practical Message Attacks on CPDLC USENIX Security Symposium 2026 (Ziazi, Aleem, Sathaye, Strohmeier) · 2026-08-01
  7. Securing the Air-Ground Link in Aviation University of Oxford (Strohmeier, Martinovic, Lenders) · 2019-01-01
  8. Controller Pilot Data Link Communications (CPDLC) SKYbrary Aviation Safety · 2026-01-01
  9. GPS/GNSS Interference Resource Guide, version 1.1 US Federal Aviation Administration (AFS-400) · 2026-03-12
  10. Global Incidents of Aviation Spoofing in 2024-2025 Detected with Automatic Dependent Surveillance Broadcast Stanford University GPS Laboratory / ION International Technical Meeting (Lo, Liu, Ibrahim, Chen, Akos, Walter) · 2026-01-01
  11. Safety Information Bulletin 2022-01 R3: GNSS Outage and Alterations Leading to Navigation/Surveillance Degradation Civil Aviation Authority of Singapore · 2024-01-11
  12. NTSB: GPS Jamming Active Before C90 Accident AVweb · 2026-06-19
  13. NTSB Clarifies No Cause Determined in New Mexico Medevac Crash AviatorDB · 2026-08-07

Researched and written by the R3KONX analysis desk from the cited primary material. Methodological caveat: the GAO report's own quantitative tables could not be read from the published product page or the highlights document, so the count of systems with incomplete risk assessments is carried from AVweb's reading of the full report and attributed to that publisher. The May 2026 accident is described strictly as circumstances recorded in a preliminary report; the NTSB has determined no probable cause. Corrections to event@r3konx.asia.

R3KONX 2027

Work in this domain? So does the programme

4–6 May 2027, World Trade Centre Kuala Lumpur. Curated talks, hands-on training and The BattleGrid.