The FAA lacks real-time tools to detect and combat spectrum-based cyberattacks—including spectrum interference, spoofing, and jamming—against aircraft communications in the National Airspace System (NAS), according to a Government Accountability Office report published this week. Without real-time tools, the FAA can investigate attacks only after they are reported, the GAO noted.
Notably, the GAO found vulnerabilities in aircraft communications addressing and reporting system (ACARS) and controller-pilot data link communications (CPDLC) messages, the text-based systems pilots, airlines, and air traffic controllers can use to exchange flight plans, clearances, and other operational information. Because the two systems generally lack encryption and authentication, the GAO said messages can be intercepted, spoofed, or blocked through denial-of-service attacks. “A malicious actor could transmit fraudulent clearance cancellations, possibly leading to flight delays or safety issues,” the report states.
The GAO made nine recommendations to address vulnerabilities, including completing formal risk assessments for seven NAS systems; implementing continuous threat monitoring; and developing a plan to strengthen authentication and data protection of ACARS and CPDLC messages. The DOT concurred with all nine recommendations.
The FAA fully addressed two of eight leading interagency collaboration practices the GAO identified and partially addressed the remaining six; it has not set formal policies for information sharing, reporting, or coordination with non-federal partners outside interagency groups such as the Aviation Cyber Initiative, the GAO found.
After it reviewed eight spectrum-dependent NAS systems, the GAO found that the FAA had not completed separate, detailed risk assessments for seven of them, as required under National Institute of Standards and Technology guidance. The GAO also found that four of the eight systems still referenced an outdated NIST security-control standard that was superseded in 2021.
“Without comprehensive risk and mitigation assessments, complete security documentation, and real-time monitoring capabilities, FAA may not have sufficient information to identify, prioritize, and respond to evolving spectrum-related threats,” the GAO said in the report.
The report was released under a provision of a 2025 law that directed the GAO to review the NAS’ vulnerability to spectrum attacks.