United Airlines aircraft below the air traffic control tower at Denver International Airport in 2018.
Bmurphy380 / Wikimedia Commons, CC BY-SA 4.0. Cropped for presentation. Context photograph; it does not depict an attack or a GAO-identified system.

Imagine an aircraft crew receiving a digital cancellation of a clearance that the controller did not send. The crew does what a careful crew should do: questions the inconsistency, switches to voice, and waits for a controller to resolve it. Nothing about that sequence requires an airplane to obey a malicious instruction. It still consumes radio time, attention, and a departure slot. Repeat it across several aircraft and a security problem becomes a capacity problem before it becomes the cinematic disaster that usually dominates aviation cybersecurity discussion.

That example comes from the GAO’s September 21 aviation cybersecurity report. Its value is in the boundaries. The auditors did not report a successful attack on an aircraft. They examined eight spectrum-dependent systems, reviewed incident and outage material, spoke with federal and industry participants, and looked closely at the text applications used among air traffic control, aircraft, and airline operations. Their nine recommendations address a set of weaknesses that interact: seven of the eight examined systems need formal risk assessments addressing spectrum attacks; detection is incomplete; coordination outside established interagency groups lacks formal rules; and ACARS and CPDLC need a plan for stronger authentication and data protection.

A message is an operational input

Aircraft Communications Addressing and Reporting System, or ACARS, carries operational messages among aircraft, airlines, and service partners. Controller–Pilot Data Link Communications, or CPDLC, carries structured messages between controllers and pilots. Depending on the application, those exchanges can involve clearances, requests, acknowledgments, position, estimates, weather, flight plans, and aircraft status. Calling them “texts” can make them sound casual. Their content enters a tightly timed system in which a message can change what a crew expects to do next.

The security question is whether the receiving party can reliably establish who sent the message, whether it was altered, and whether it belongs to the current exchange. A format that looks correct is not proof of origin. A flight number or aircraft identifier used to initiate a session is not, by itself, the same as cryptographic authentication of every subsequent operational instruction. GAO says the applications generally lack encryption and authentication and are vulnerable to interception, spoofing, and flood-based denial of service. It also says the FAA has not fully implemented enhanced cryptographic measures for these applications.

The distinction among these attacks matters. Jamming prevents or degrades reception; it may announce itself as a loss of service without telling an operator who caused it. Spoofing supplies false information that appears to come from a trusted party. Message alteration or replay interferes with the content or timing of an exchange. Flooding can consume limited link capacity. Each has a different signature and response. One monitoring dashboard that notices interference would not automatically authenticate a clearance, and adding encryption to one application would not make the underlying radio spectrum impossible to jam.

GAO’s example of a false cancellation illustrates a relatively contained failure path. A crew sees a contradiction, verbally checks it, and delays action. The report also discusses the more serious conditional case in which a recipient accepts a modified or injected message as legitimate and makes a flight-path decision on false information. The word “conditional” belongs in any honest description. The published audit establishes a vulnerability and plausible consequences; it does not measure the probability that a particular malicious message would defeat pilots, controllers, existing procedures, and equipment defenses in an actual flight.

Why the existing human barrier matters

This is not a story in which digital text instantly and silently controls an airplane. GAO notes that CPDLC requires controller input and flight-crew acceptance before action. The FAA also uses an airline flight-number login process, and crews can resolve conflicting clearances by voice. Those protections reduce the likelihood or consequence of an unauthorized message. They deserve to be described as real controls rather than dismissed because they are not cryptographic.

Their weakness is that a control can work and still impose a cost. If an adversary sends contradictory messages, the safe response is to stop and verify. Radio channels, controller attention, cockpit workload, and departure scheduling are finite resources. A forged instruction need not be followed to be disruptive. Cyberdelia’s mechanism check is therefore a workload question: how many false or inconsistent messages could a sector absorb before the verification process itself delays normal traffic? That number is not in the public report; obtaining it would require operational data, simulation, and cooperation from controllers and operators.

There is also a difference between a discrepancy a human can recognize and one that fits the surrounding context. Pilots and controllers work within procedures and shared situational awareness, but the effectiveness of a manual check depends on timing, workload, the specificity of the message, and whether the expected alternative channel remains available. A real assessment would test those conditions without treating the crew as either an infallible firewall or an easily fooled prop.

Detecting the problem before a crew reports it

The FAA has identified spoofing, jamming, and other spectrum threats. GAO’s criticism is that identifying a category is not the same as documenting the risk and continuously observing it. The agency found no defined real-time monitoring and detection capability for all spectrum-related threats. According to the auditors, the FAA may therefore investigate some events only after someone reports them. It has collaborative mechanisms and some classified and unclassified tools for GPS interference, but the report does not describe comprehensive coverage of aviation communications links.

The difference between monitoring a link and monitoring an incident is consequential. A crew’s report can establish that something went wrong. Independent radio-frequency and message telemetry can show where, when, and how it went wrong, whether adjacent aircraft received similar signals, and whether an equipment fault resembles deliberate interference. That evidence matters to attribution and to immediate mitigation. If the first signal is an inconsistent clearance heard by a pilot, the system has already passed the point at which infrastructure detected the anomaly on its own.

Seven of the eight selected systems lacked the formal risk assessment GAO recommended for spectrum threats; the eighth drew a separate recommendation about consistent system categorization. A useful risk assessment would name assets and dependencies, threat paths, likelihood assumptions, consequences, existing defenses, and residual risk. That does not mean GAO has shown those systems are uniformly defenseless. It means the documentation needed to prioritize defenses is not complete enough by the auditors’ standard. A reader should not confuse an audit of risk-management practice with a penetration test proving the exploitability of every component.

The response chain also crosses organizational borders. Air traffic control, aircraft operators, manufacturers, communications service providers, regulators, and security agencies hold different pieces of the evidence. GAO found the FAA fully addressed two of eight leading practices for collaboration and partially addressed six. Outside formal interagency groups, some partners did not know which FAA office should receive a spectrum concern or how it would be resolved. In an incident, unclear routing burns the same scarce minutes as unclear technical telemetry.

Why “just encrypt it” takes years

There are standards for stronger aviation data communication. GAO says the FAA is testing an Internet Protocol Suite approach at select locations, but has not documented an implementation timeline. Deployment depends on compatible aircraft avionics, ground infrastructure, manufacturers, operators, approvals, and the economic life of existing fleets. Replacing a protocol is therefore a coordinated infrastructure migration. The newest aircraft cannot make the whole airspace secure if they must still interoperate with older equipment and a mixed ground network.

Authentication and message integrity are the immediate questions in the forged-clearance scenario. Encryption adds confidentiality, but secrecy alone does not show whether an instruction came from the controller. A robust design also has to cope with lost connectivity, key and certificate management, clock errors, emergency procedures, and the failure of a service provider. A security upgrade that introduces a new single point of failure could exchange one problem for another. That is an engineering constraint, not an excuse to leave weak messages indefinitely in service.

GAO’s ninth recommendation asks the FAA, working with federal and non-federal partners, to develop and implement a plan for stronger authentication and data protection for ACARS and CPDLC. The Department of Transportation concurred with all nine recommendations. Concurrence is a commitment to respond to an audit, not evidence that the controls are now deployed. The GAO recommendation tracker listed them as open at publication. A follow-up story can measure documented milestones: which application was upgraded, how many aircraft and ground sites can use it, whether the old path remains available, and whether crews have been trained for conflicting authenticated and unauthenticated messages.

What would change this assessment

Public evidence of a successful safety-impacting intrusion would sharply raise the urgency and change the article’s description of observed harm. Conversely, a published rollout plan with independent tests of message authentication, coverage, and failure behavior would narrow the gap described by GAO. Neither is established by the September report. The present claim is more precise: critical communications use text applications with known security limitations; procedures can catch suspicious messages; comprehensive monitoring and modernization are incomplete.

The honest story is also a useful one. Aviation has spent decades building checks around unreliable channels and human fallibility. The next task is to make the sender of a digital instruction verifiable without losing the resilient practices that already prevent a confusing message from becoming an unsafe maneuver. If the crew must ask “did you really send that?” the answer should be available from both a human controller and the system that carried the message.

CYBERDELIA ASSESSMENT

The immediate failure mode is untrusted operational information imposing verification work on a capacity-constrained system. The safety case for stronger authentication rests on reducing that ambiguity while preserving independent crew and controller checks.

News DeskAndre SuttonMore Features