Flights Halted at US Airports Due to Cybersecurity Threat
· deals
Flights Halted at US Airports as Watchdog Warns Over Hacking Threat
The recent disruption to flights at three major US airports may have been caused by an Amtrak construction crew’s unfortunate mishap, but it’s a symptom of a more insidious problem. A new report from the Government Accountability Office (GAO) has exposed the Federal Aviation Administration’s (FAA) woefully inadequate approach to cybersecurity threats in air traffic control systems.
The FAA’s failure to update security documentation and complete risk assessments on spoofing, jamming, and other attacks on radio frequencies is a ticking time bomb. The GAO report highlights the vulnerability of these systems to interference and deception, which could be exploited by hackers or foreign governments to disrupt air travel and even put passengers at risk.
Two critical systems used to send text messages to aircraft predate modern cybersecurity standards and lack basic protections like encryption. This is not just a matter of updating software or hardware; it’s about acknowledging the very real threat posed by cyber attacks on our nation’s air traffic control infrastructure.
Senator Ron Wyden has been a vocal advocate for improved aviation security, stating, “The FAA’s failure to require secure communications is a major threat to US national security, to our economy, and the safety of the flying public.” The stark reality is that the FAA’s inertia on this issue could have devastating consequences.
Recent incidents worldwide have shown the vulnerability of air traffic control systems. Estonia and Finland have accused Russia of interfering with satellite navigation in their airspace, and there have been numerous other incidents where air traffic control systems have been compromised. The recent outage at Newark airport, which blanked controllers’ screens for 60-90 seconds, is just one example.
The FAA’s handling of these issues has been slow and ineffectual. In April 2025, a similar problem caused departures to be halted, prompting the FAA to move the Philadelphia Tracon to a new fiber-optic link with New York. This kind of patchwork solution is not a substitute for comprehensive cybersecurity measures.
The GAO’s report makes nine recommendations, which the Department of Transportation has agreed to implement. However, this is not enough. The FAA needs to take bold action, issuing new standards and protocols that prioritize security above all else. Anything less would be a dereliction of duty.
As we continue to rely on air travel to move people and goods across the country, it’s imperative that our infrastructure is protected from cyber threats. With millions of passengers relying on safe air travel every day, we can’t afford to wait any longer for the FAA to get its priorities straight.
Reader Views
- TCThe Cart Desk · editorial
The FAA's sluggish response to cybersecurity threats is nothing new, but the recent GAO report highlights just how dire the situation has become. What's particularly alarming is the agency's lack of urgency in updating its security documentation, despite multiple high-profile incidents worldwide where air traffic control systems have been compromised. The real concern isn't just hacking, but also the possibility of spoofing or jamming radio frequencies, which could be used to intentionally manipulate flight trajectories. The FAA needs to accelerate its efforts and implement more robust cybersecurity measures before it's too late.
- SBSam B. · deal hunter
"We're staring down a very real threat here, folks. Cyber attacks on air traffic control systems aren't just hypotheticals - they've happened before and will happen again if we don't get serious about upgrading our infrastructure. What's disturbing is that the FAA's solution seems to be more of the same old patchwork fixes rather than a comprehensive overhaul. We need transparency about what's being done to secure these systems, and we need it now."
- PRPat R. · frugal living writer
The FAA's cybersecurity shortcomings are a perfect example of bureaucratic inertia. What's often overlooked is that updating air traffic control systems isn't just about throwing money at the problem – it's also about tackling systemic issues like out-of-date software and hardware. Airlines and aviation companies must share some of the blame, too, for not pushing harder for more robust security measures when investing in these systems. This is a ticking time bomb that won't explode with a single catastrophic event; it'll be a series of smaller incidents that ultimately erode public trust.