US sounds alarm on hacking of passenger jets, air traffic control

Government report says the FAA needs to do more to ensure safety in the skies

Millions of air passengers could be at risk if more isn't done to prevent hackers targeting aircraft and air traffic control systems, the U.S. government said on Tuesday.

The warning was the conclusion of a 56-page report published by the Government Accounting Office (GAO) into how the Federal Aviation Administration (FAA) is addressing cyberthreats as it deals with modernization of the national air traffic control system and increasingly connected aircraft.

While the FAA has taken steps to protect against cyberattacks, the GAO found "significant security-control weaknesses remain that threaten the agency's ability to ensure the safe and uninterrupted operation of the national airspace system."

The FAA has agreed to address the specific weaknesses identified in the report, but the GAO said the air traffic control system remains vulnerable because the FAA hasn't conducted an overall study that would identify potential threats to information systems and bring order to its current cyberthreat management, which is shared between several FAA offices.

"While FAA has taken some steps toward developing such a model, it has no plans to produce one and has not assessed the funding or time that would be needed to do so," the GAO said. "Without such a model, FAA may not be allocating resources properly to guard against the most significant cybersecurity threats."

The GAO, which audits and evaluates government agencies and departments, is clashing with the FAA on the degree to which the agency's office of safety should be involved in overall cyberthreat planning.

One of the jobs of the FAA's safety office is to certify interconnected networks on aircraft, such as the avionics system and in-flight Internet system, to ensure the aircraft isn't vulnerable to hackers. The GAO has recommended the FAA make the safety office a member of its Cyber Security Steering Committee, but the FAA has resisted the call, it said.

"Not including [the office of safety] as a full member could hinder FAA's efforts to develop a coordinated, holistic, agency-wide approach to cybersecurity," the GAO said.

The report comes as the FAA is working on development and deployment of the Next Generation Air Transportation System, a new air traffic control system that is intended to let more planes fly at once while making flying safer and more economical.

One component of the system, called the Surveillance and Broadcast Services Subsystem, is already in use. But the FAA has not adopted a 2013 government standard on security controls, such as intrusion detection improvements.

"Systems with weaknesses that could be exploited by adversaries may be at increased risk if relevant controls are not implemented," the GAO said.

The FAA could not immediately be reached for comment.

Martyn Williams covers mobile telecoms, Silicon Valley and general technology breaking news for The IDG News Service. Follow Martyn on Twitter at @martyn_williams. Martyn's e-mail address is

Join the CSO newsletter!

Error: Please check your email address.

Tags U.S. Government Accountability OfficesecuritytransportationU.S. Federal Aviation Administrationindustry verticals

More about FAAFederal Aviation AdministrationIDGNewsTransportation

Show Comments

Featured Whitepapers

Editor's Recommendations

Solution Centres

Stories by Martyn Williams

Latest Videos

  • 150x50

    CSO Webinar: The Human Factor - Your people are your biggest security weakness

    ​Speakers: David Lacey, Researcher and former CISO Royal Mail David Turner - Global Risk Management Expert Mark Guntrip - Group Manager, Email Protection, Proofpoint

    Play Video

  • 150x50

    CSO Webinar: Current ransomware defences are failing – but machine learning can drive a more proactive solution

    Speakers • Ty Miller, Director, Threat Intelligence • Mark Gregory, Leader, Network Engineering Research Group, RMIT • Jeff Lanza, Retired FBI Agent (USA) • Andy Solterbeck, VP Asia Pacific, Cylance • David Braue, CSO MC/Moderator What to expect: ​Hear from industry experts on the local and global ransomware threat landscape. Explore a new approach to dealing with ransomware using machine-learning techniques and by thinking about the problem in a fundamentally different way. Apply techniques for gathering insight into ransomware behaviour and find out what elements must go into a truly effective ransomware defence. Get a first-hand look at how ransomware actually works in practice, and how machine-learning techniques can pick up on its activities long before your employees do.

    Play Video

  • 150x50

    CSO Webinar: Get real about metadata to avoid a false sense of security

    Speakers: • Anthony Caruana – CSO MC and moderator • Ian Farquhar, Worldwide Virtual Security Team Lead, Gigamon • John Lindsay, Former CTO, iiNet • Skeeve Stevens, Futurist, Future Sumo • David Vaile - Vice chair of APF, Co-Convenor of the Cyberspace Law And Policy Community, UNSW Law Faculty This webinar covers: - A 101 on metadata - what it is and how to use it - Insight into a typical attack, what happens and what we would find when looking into the metadata - How to collect metadata, use this to detect attacks and get greater insight into how you can use this to protect your organisation - Learn how much raw data and metadata to retain and how long for - Get a reality check on how you're using your metadata and if this is enough to secure your organisation

    Play Video

  • 150x50

    CSO Webinar: How banking trojans work and how you can stop them

    CSO Webinar: How banking trojans work and how you can stop them Featuring: • John Baird, Director of Global Technology Production, Deutsche Bank • Samantha Macleod, GM Cyber Security, ME Bank • Sherrod DeGrippo, Director of Emerging Threats, Proofpoint (USA)

    Play Video

  • 150x50

    IDG Live Webinar:The right collaboration strategy will help your business take flight

    Speakers - Mike Harris, Engineering Services Manager, Jetstar - Christopher Johnson, IT Director APAC, 20th Century Fox - Brent Maxwell, Director of Information Systems, THE ICONIC - IDG MC/Moderator Anthony Caruana

    Play Video

More videos

Blog Posts