GAO warns fake ATC messages could disrupt flights
A US government watchdog has flagged cybersecurity weaknesses in the data links used by pilots and controllers, warning that forged messages could reach aircraft. The FAA is urged to strengthen authentication and threat monitoring.

The US Government Accountability Office has found security gaps in the digital systems pilots, airlines and air traffic controllers use to exchange operational information, according to a report released on September 21, 2026.
The watchdog looked at two data links: the Aircraft Communications Addressing and Reporting System and Controller-Pilot Data Link Communications. Both carry routine operational messages digitally, cutting the need for voice radio in some situations. Each lacks adequate authentication, encryption and protocol safeguards, the report found, leaving them open to interception and to messages sent by someone impersonating a legitimate sender.
An attacker who exploited those weaknesses could push out forged transmissions, including cancellations of clearances already issued, according to the report. That could cause delays or create safety problems, the watchdog warned. The findings describe vulnerabilities that might be used, not confirmed cases of fake clearances reaching aircraft.
The GAO also pointed to limits in how the Federal Aviation Administration watches for and reacts to threats against the electromagnetic spectrum, naming spoofing and jamming on routes both inside the United States and internationally. It recommended the agency join with other federal bodies and industry parties to draw up and carry out a plan that improves authentication and data protection, with specific measures against spoofing, unauthorised transmissions and tampering with messages.
Sources
- aerotime.aeroFake ATC messages could put flights at risk, US watchdog warns