Autoflight computers can fly an aeroplane when it is just 30 meters off the ground and can hone in on runway radio beacons to land the aircraft automatically. The question has been asked in the aviation sector about whether or not aeroplanes even need pilots, but aside from the separate debate regarding passenger perception of safety with a human at the controls, the spectre of cybercrime is constant, especially now that aircraft are becoming increasingly connected to the internet.
ACCESS WITH AN ANDROID PHONE
In July 2013, Hugo Teso, a security researcher at N.Runs and a commercial airline pilot, demonstrated to the audience at the Hack In The Box security summit in Amsterdam that it was possible to take control of aircraft flight systems and communications using an Android smartphone and some specialised attack code. At a Black Hat hacking conference in Las Vegas in late July 2014, cyber security researcher and a consultant with cyber security firm IOActive, Ruben Santamarta, also claimed to have worked out how to hack the satellite communications equipment on passenger aircraft through WiFi and in-flight entertainment systems. Research by IOActive shows that 100% of the devices in satellite communications used in aerospace could be abused. The vulnerabilities uncovered by the company included multiple backdoors, hardcoded credentials, undocumented and/or insecure protocols or weak encryption algorithms. “These vulnerabilities allow remote, unauthenticated attackers to fully compromise the affected products. In certain cases, no user interaction is required to exploit the vulnerability, just sending a simple SMS or specially crafted message from one ship to another ship can do it,” according to an abstract of Santamarta’s research on IOActive’s website.
Santamarta claimed to have discovered the vulnerabilities by “reverse engineering” – or decoding – highly specialised software known as firmware, used to operate communications equipment made by Cobham, Harris Corp, EchoStar Corp’s Hughes Network Systems, Iridium Communications and Japan Radio. His theory explains that a hacker could use a plane’s onboard WiFi signal or in-flight entertainment system to hack into its avionics equipment, potentially disrupting or modifying satellite communications, which could interfere with the aircraft’s navigation and safety systems. The reverse engineering has only been tested by the researcher in IOActive’s Madrid laboratory. Santamarta agrees that it may be difficult to replicate his results in the real world and while representatives for Cobham, Harris, Hughes and Iridium said they had reviewed Santamarta’s research and confirmed some of his findings, they downplayed the risks saying that a hacker would need physical access to their systems and equipment. Cobham specifically has stated that it has strict
requirements restricting such access to authorised personnel only. Still, risks remain, as IOActive has demonstrated.
On June 13, 2014, the US Federal Aviation Administration (FAA) proposed additional safety requirements for Boeing 737s to protect the airplanes from hackers. In the Federal Register, the FAA noted that newer 737s “may allow increased connectivity to and access from external network sources and operations and maintenance networks to the aircraft control domain and operator information domain… Previously these domains had very limited connectivity with external network sources.”
“A security researcher and commercial airline pilot demonstrated to the audience that it was possible to take control of aircraft flight systems and communications using an Android smartphone”
“The architecture and network configuration may allow the exploitation of network security vulnerabilities resulting in intentional or unintentional destruction, disruption, degradation, or exploitation of data, systems, and networks critical to the safety and maintenance of the airplane,” the FAA added.
CHANGING REGULATIONS
Because existing regulations and guidance don’t anticipate these issues, the FAA proposed that operators need to ensure that the “airplanes’ electronic systems are protected from access by unauthorized sources external to the airplane, including those possibly caused by maintenance activity”. Operators must also ensure that “electronic system security threats are identified and assessed, and that effective electronic system security protection strategies are implemented to protect the airplane from all adverse impacts on safety, functionality, and continued airworthiness”.
In February 2014, Boeing modified its 777-200, -300, and -300ER series aircraft to prevent onboard hacking of critical computer systems, which was confirmed by the FAA in a Federal Register filing.
“These special conditions are issued for the Boeing Model 777-200, -300, and -300ER series airplanes. These airplanes, as modified by the Boeing Company, will have novel or unusual design features associated with the architecture and connectivity of the passenger service computer network systems to the airplane critical systems and data networks. This onboard network system will be composed of a network file server, a network extension device, and additional interfaces configured by customer option. The applicable airworthiness regulations do not contain adequate or appropriate safety standards for this design feature. These special conditions contain the additional safety standards that the Administrator considers necessary to establish a level of safety equivalent to that established by the existing airworthiness standards,” states the report.”

Boeing was prompted to act following concerns over the possibility that the passenger in-flight entertainment system would be connected to critical systems of the aircraft giving an effective open door for hackers. Passenger seatback entertainment systems on modern aircraft have USB ports and are equipped with Ethernet. Before the modifications by Boeing there was no separation between entertainment systems and the overall network of the aircraft. The 777 aircraft on-board computer network system and a network extension device has now been improved to ensure separation between the aircraft’s information services domain and the aircraft control domain.
Air traffic control manufacturer and defence firm Raytheon has been at the forefront of cyber defence for four decades and presented a briefing specifically on the risks associate with the commercial aviation industry at the UK Farnborough Airshow in July 2014.
“Before the modifications by Boeing there was no separation between entertainment systems and the overall network of the aircraft”
“We have more computing power in the smart phone in our pocket than the computer that sent men to the moon,” said Lynn Dugle, president of Raytheon
Intelligence Information and Services. “The whole mobile device movement is embedded into our lives and by 2020 there will be 50-70 billion devices in circulation with a population of 7.8 billion people. All of that connectivity is there to make our lives easier but they are also vulnerabilities because every time there is a connection there is opportunity for penetration by malcontent actors.”
Raytheon’s research and development encompasses an end-to-end approach to cyberdefence. As a result, the company is conducting research on hacker behavior and human behavior; searching for vulnerabilities in software or devices by launching millions of attacks at it in greater than real-time; and it is working globally to identify threats that are not always on networks. The breach at Target Corp. that exposed credit card and personal data on more than 110 million consumers in February 2014 began with a malware-laced email phishing attack sent to employees at a heating, ventilation, and air conditioning firm that conducted business with the retailer. The attackers broke into the retailer’s network on November 15, 2013 using network credentials stolen from Fazio Mechanical Services, which provides refrigeration and HVAC systems.
GLOBAL INTERCONNECTIVITY
Aircraft are part of that ever-expanding Internet of Things and are becoming more and more connected in the air. Table 1 shows the vulnerabilities present in the systems present on a modern aircraft.
| TABLE 1 AVIATION SYSTEMS Aircraft control Flight and embedded control, Flightsafety related, Navigation systems, Cabin crewpp Airline information services Airline business, Administrative support, Passenger support Passenger information & entertainment services In-seat entertainment, Passenger information, Internet access Passenger-owned devices Smartphones, tablets, laptops, e-readers |
Although all of the aircraft control systems are isolated from the general connection of the plane including the passenger information and entertainment systems, there are still access points for clever hackers. “All planes have WiFi now,” says Steve Hawkins, vice president for International Solutions at Raytheon Intelligence Information and Services.
“Typically planes use WiFi for entertainment and to allow people to work onboard but it is also tied in, with some isolation, with all of the digital control systems of the plane. If you are a hacker there are lots of vulnerabilities, be it the flight controls or the data from airline reservation systems such as credit card information that could also be present in personal devices on board the aircraft. You can’t control that environment once they are on the plane, which makes lots of vulnerabilities. This is why regulators are asking airplane manufacturers to deal with these kinds of issues.”
“Aircraft manufacturers, airlines and aircraft operators need to be aware of the risks present in their aircraft to be able to mitigate them”
Aircraft manufacturers, airlines and aircraft operators need to be aware of the risks present in their aircraft to be able to mitigate them.
The insider threat is a real danger to all companies, including airlines, through error or malicious activity. “Think of the potential danger you have with the number of passengers on a plane, the pilots themselves who are allowed to carry a laptop or tablet onboard, everybody is connected wirelessly on these planes, and you need to look for these types of vulnerabilities,” says Hawkins.

“Anti-tamper software is essential as it stops individuals from accesses systems by setting off alarms, blocking access or disable it completely”
Dugle adds: “We have been concerned with the insider threat for decades but now with Wikileaks and Mr Snowden, we are very sensitive to the fact that some of the most dangerous threats are posed by people that operate within our own networks – be it someone with the intent to steal or defame, or like the majority of us, they make a mistake. The whole idea is to automate systems as far as you can to stop mistakes from happening.”
“Anti-tamper software is essential as it stops individuals from accesses systems by setting off alarms, blocking access or disable it completely to protect the aircraft,” says Hawkins. “Different types of [Advanced Persistent Threat] APT solutions – all devices and computers have some sort of anti-virus software installed but what is starting to happen is new vulnerabilities are appearing – new threats and variants – that they can’t catch. We create non-signature based detection tools to detect these threats on planes.”
All aircraft are becoming e-enabled so airlines need to address the cybersecurity aspect. The Internet of Things connects areas included aircraft, air traffic control systems, airline reservation systems, aircraft maintenance systems – they are all connected and part of the aviation internet of things. Raytheon is working on how to put all of these provisions into its air traffic controls systems, while aircraft manufacturers are constantly working to update their onboard systems to secure any vulnerability that exist today or that may exist in the future. Having that proactive approach will help airlines and aircraft operators to stem the persistent cyberthreat against critical infrastructure such as transportation assets.
| MITIGATING RISKS IN AVIATION Training Personnel who understand how attackers are less likely to become unwitting accomplices Insider-threat tools A safety net for operator error and a watchdog for malicious actions Anti-tamper software Protects baseline configurations from unauthorized changes APT solutions Make it difficult for hackers to rely on ground networks High Assurance Products Barriers to cross-domain exploits Monitoring and traffic analysis To find successful intrusions and attacks in progress Vulnerability and security assessments Discover unaddressed vulnerabilities and threats |
THE THREAT TODAY
According to an article published in The Irish Times on January 3rd, 2025, counterfeit signals sent to planes’ GPS systems ‘present a direct safety threat’ and have increased since Russia invaded Ukraine. Hacking attacks on airlines’ global positioning systems (GPS) increased worldwide by some 400% in the first 10 months of last year , according to research by the aviation advisory body OpsGroup, representing 450 airlines and industry specialists such as Nasa.
OpsGroup – made up of about 8,000 professionals at what it calls “the pointy end of the industry” – reports “a troubling spike” in the attacks, up from an average of 200 daily in the first quarter from January to March, to around 900 daily for the second quarter of the year. Some days, it says, as many as 1,350 flights have been hacked. As a result, an international working group has been set up to collate data and talk to airline flight crew to try to get a more detailed picture of the extent and geographical locations of the problem – and who may be behind it.
“Hacking attacks on airlines’ global positioning systems (GPS) increased worldwide by some 400 per cent in the first 10 months of last year”
OpsGroup’s findings are strikingly supported by recent statistics from the Netherlands Aviation Incident Analysis Bureau, which show that Dutch pilots were targeted 983 times in the first 10 months of 2024 by unidentified hackers sending counterfeit GPS locations to their aircraft. “Reports started increasing noticeably after Russia invaded Ukraine in February 2022,” says Coen George, vice-president of the Dutch airline pilots’ association. “Now, less than three years on, it’s so bad it’s a daily problem for pilots. It can lead to false warnings or – equally dangerous – to the absence of warnings. In many ways the real risk is that if pilots get used to discounting fake warnings, they may misinterpret or dismiss a real one. It’s like sailing in the fog: you can no longer fully trust your on-board systems.”
According to C4ADS, a non-profit organisation in Washington DC specialising in data analysis from conflict flashpoints, GPS hacking equipment that might previously have cost tens of thousands of dollars now costs around $350. It’s portable and the software code is open source. Initially the problems posed by GPS hacks were primarily navigational, says OpsGroup. But because as the GPS technology evolves it is becoming “interwoven” with the aircraft’s other online systems, the problems hacking causes are becoming more difficult to trace and tackle. Examples of the navigational impact of a hack might be that the plane could begin turning unexpectedly or that the inertial reference system (IRS), which calculates position, acceleration, vertical speed, ground speed and true and magnetic heading, could became unreliable.
In terms of interacting on-board systems, an example is an increase in the cases of aircraft clocks being affected. Seeing them “running backwards” is often one of the first warning signs of an encounter with a hacker. “Eurocontrol – the EU’s air navigation safety agency – now report seeing this on a daily basis,” says OpsGroup. While the clock may sometimes be a pilot’s early warning, other false alerts can happen hours after a hack, emerging apparently out of nowhere as the fake data works its way through the system. British cybersecurity expert Ken Munro recently described to an industry conference one incident in which clocks on a plane owned by “a major Western airline” suddenly went forward “by years” – causing the jet to lose access to its digitally encrypted communications systems. The plane landed safely but was grounded for weeks while engineers manually reset its on-board systems, Munro told Reuters.
“Early in 2024, Finnair temporarily paused flights to the eastern Estonian city of Tartu as a result of GPS attacks which Tallinn blamed on neighbouring Russia”

Early in 2024, Finnair temporarily paused flights to the eastern Estonian city of Tartu as a result of GPS attacks which Tallinn blamed on neighbouring Russia. It said it planned to take the issue up with the EU and Nato on the grounds that it could be in violation of the UN’s International Telecommunications Union regulations – which forbid harmful radio frequency interference. At around the same time, Germany also claimed Russia was “very likely to have been behind” a series of “disturbances” affecting GPS navigation in the Baltic region. Berlin said it believed the Russian enclave of Kaliningrad – on the Baltic Sea coast – was the source of the interference. However, it refused to say how it knew this, citing “military security”. Russia did not comment in either case.
In an industry where safety plays such an all-consuming role, a bleak warning comes from OpsGroup, whose members know the industry inside out at every level – and are not given to alarmism. “The trouble is that shifts in safety risk are happening without much attention to them,” they warn. “These are largely unaddressed latent pitfalls that will become painfully clear when the first accident attributable to spoofing occurs.”
About RiskBusiness Newletter
The RiskBusiness Newsletter provides in-depth analysis, reviews and research on areas of interest within the broader governance, risk, audit and compliance landscape, designed to provide proactive, 360° intelligence for informed decision making across the enterprise.
About RiskBusiness
RiskBusiness is an international governance, risk, audit and compliance (GRAC) solution provider, delivering risk content, risk intelligence, risk tools and risk advisory services to its clients. It is an association of like minded industry professionals, who have the aim of furthering the risk management discipline to enable better risk-reward decision making. Risk management is an evolving discipline, which has developed in close partnership with the industry. RiskBusiness has, both as individuals and collectively, a depth of established relationships with leading players and regulators in the operational risk field. We are also active participants in industry working groups and contribute thought leadership through publications and education. RiskBusiness was founded in 2003 and today has principal locations in Birmingham, London, Buenos Aries, Amsterdam, Hong Kong, New York, Singapore, Toronto, and Zurich.
Download a PDF version of this report here.





