GAO: FAA Lacks Real-Time Detection for Spoofing, Jamming Threats to Aircraft Communications

Potential cyberattacks can impact aircraft communications.

By: Dawn Zoldi

A new watchdog report finds the Federal Aviation Administration has not finished the risk assessments or built the real-time monitoring tools needed to defend the national airspace system against electromagnetic spectrum attacks, including GPS spoofing and jamming.

The Government Accountability Office’s report, “Aviation Cybersecurity: Enhanced Air Safety Requires FAA to Better Mitigate Threats to Aircraft Communications” (GAO-26-108439), released September 21, examined eight spectrum-dependent systems the FAA relies on to guide and communicate with aircraft across domestic and international routes. GAO found the agency has identified the threats — spectrum interference, spoofing, and jamming among them — but has completed formal risk and mitigation assessments for only one of the eight systems reviewed.

The report also found the FAA lacks a defined, real-time capability to detect all spectrum-related threats. Detection tools exist, but coverage is incomplete, meaning many incidents can only be investigated after they are reported rather than caught as they happen. GAO warned that without comprehensive risk assessments, updated security documentation, and continuous monitoring, the FAA “may not have sufficient information to identify, prioritize, and respond to evolving spectrum-related threats,” raising the risk that spoofing or jamming could disrupt communications, degrade situational awareness, and cause operational disruptions across the airspace system.

Nine Recommendations, Full Agreement

GAO issued nine recommendations to the FAA. They call for the agency to complete formal risk and mitigation assessments for the remaining spectrum-dependent systems, develop a defined capability for continuous, real-time monitoring of interference, spoofing, and jamming, and strengthen authentication and data protection for key communication channels — specifically the Aircraft Communications Addressing and Reporting System (ACARS) and Controller-Pilot Data Link Communications (CPDLC), both used to relay instructions and operational data between controllers and cockpits.

The report separately assessed how well the FAA collaborates with other federal agencies and industry stakeholders on cybersecurity. GAO found the agency fully met only two of eight recognized leading practices for interagency coordination, partially meeting the other six. While the FAA has established roles within existing interagency working groups, GAO said it has not formalized information-sharing procedures with partners outside those groups — a gap the recommendations also target.

The Department of Transportation, responding on behalf of the FAA, concurred with all nine recommendations. As of the report’s release, each recommendation remained open pending confirmation of corrective action, and GAO did not specify a timeline for implementation.

Why It Matters for Autonomy and Airspace Security

For the counter-UAS and airspace-security community, the report reinforces a theme that has been building for years: spectrum-dependent navigation and communication links across the National Airspace System remain exposed to the same spoofing and jamming techniques that have plagued GPS-reliant drone and manned-aviation operations. GAO’s finding that the FAA relies largely on after-the-fact incident reports, rather than continuous detection, underscores a broader gap in real-time spectrum-awareness infrastructure — the same capability gap that counter-drone sensor networks and RF-monitoring systems are increasingly being built to close.

As the FAA works through GAO’s nine recommendations, expect renewed attention on authentication upgrades for ACARS and CPDLC, and on whether commercial detection technologies already used in counter-UAS deployments could be adapted to give air traffic systems the continuous spectrum monitoring GAO says is currently missing.

Report https://www.gao.gov/assets/gao-26-108439.pdf; Highlights https://www.gao.gov/assets/gao-26-108439-highlights.pdf.