FAA can't detect spectrum attacks on aircraft comms in real time, GAO finds
The agency identified spoofing and jamming threats to the National Airspace System internally but hasn't completed risk assessments, updated security documentation, or deployed real-time monitoring.
TL;DR
A GAO report released September 21 finds FAA has not completed risk and mitigation assessments or deployed real-time monitoring for spectrum threats (spoofing, jamming, and interference) to the National Airspace System, despite having internally identified those threats. Two major pilot-controller text communications networks, CPDLC and ACARS, lack authentication and encryption, leaving them vulnerable to interception and spoofing. FAA acknowledged the risks but cannot currently detect spectrum attacks as they occur, forcing it to investigate only after incidents are reported.

The GAO reviewed FAA's cybersecurity practices from April 2025 through September 2026, directed by the fiscal 2025 National Defense Authorization Act to assess "the vulnerability of the National Airspace System to spectrum attacks." What it found: an agency that can name the threats but can't see them when they arrive.
FAA has internally identified spectrum-related threats including spoofing and jamming to the NAS and international flight routes. But according to the GAO, it has "not completed risk and mitigation assessments, and updated security documentation needed to address these threats." And while tools exist to monitor for spectrum threats in real time, "FAA doesn't currently have them." The agency can only investigate after someone reports an incident. That's the operational reality, not a theoretical gap, but a blind spot at a critical-infrastructure agency where the threat surface is the airspace itself.
Two communication applications carry the vulnerability directly. The Controller-Pilot Data Link Communications system and the Aircraft Communications Addressing and Reporting System "were not initially designed with strong cryptographic protections." Communications are generally unencrypted and lack authentication, meaning messages can be intercepted by anyone with the right equipment. The GAO report notes that a malicious actor could transmit fraudulent clearance cancellations. The downstream risks range from flight delays to safety incidents.
Not absent, just unfinished
FAA hasn't been idle. It participates in multiple interagency cybersecurity efforts and has a 2025 notice of proposed rulemaking to impose design standards addressing cybersecurity threats for transport category airplanes, engines, and propellers. The GAO found the interagency work partially addresses six of eight leading collaboration practices, roles and responsibilities are defined within groups, but policies for information sharing and coordination with non-federal partners aren't established outside those groups.
The report's recommendations include developing a formal risk assessment covering seven of eight identified NAS systems, implementing continuous real-time monitoring for interference and spoofing, and creating a plan to strengthen authentication and data protection for CPDLC and ACARS. GAO also calls for better information-sharing procedures with non-federal partners and methods to track progress in interagency groups.
In response, DOT deputy assistant secretary for administration Keith Washington said FAA is "strengthening its risk assessment process to ensure it reflects the current threat landscape and leverages recent guidance" and will continue collaborating with industry and government partners.
This isn't the first time GAO has flagged aviation cybersecurity weaknesses. A 2015 report found significant security control weaknesses in air traffic control systems, and a 2020 report noted FAA hadn't fully implemented key practices for risk-based cybersecurity oversight of avionics. The throughline is consistent: the threats evolve faster than the agency's capacity to operationalize defenses. Real-time spectrum monitoring, as the GAO points out, isn't a novel concept, it's off-the-shelf capability FAA still hasn't deployed.
Published ·Deep Fathom