TL;DR: Planes Aren’t Hacked Because Isolation Still Works — But the Ground Is Catching Up
Why Planes Don’t Get Hacked: The Real Aviation Cyber Risk
Commercial aircraft remain extraordinarily resistant to hacking because the systems that fly the plane—certified avionics running on deterministic buses like ARINC 429 and AFDX—were never designed to be networked with the outside world, the certification regime (DO-178C, DO-326A) makes code changes glacially slow, and physical access to avionics buses is a prerequisite for nearly every credible attack path. The risk, however, is migrating to everything around the airframe: ADS-B and ACARS datalinks that are unauthenticated by design, SATCOM terminals with their own firmware problems, airline ground IT, maintenance toolchains, and the emerging class of software-defined aircraft, eVTOL platforms, and OTA update pipelines. Defend the ground, treat the datalinks as hostile, and don’t confuse the myth of the “hacked cockpit” with the documented reality of spoofable broadcasts and fragile ground infrastructure.
The Aircraft Attack Surface, Mapped
Before you can reason about aircraft cybersecurity, you need an accurate inventory. The aircraft is not one network—it’s a stack of loosely coupled systems that mostly do not trust each other and, in many cases, cannot physically reach each other.
- Avionics data buses: ARINC 429 is a point-to-point, unidirectional, deterministic bus—each signal source drives one or more receivers with no addressing and no routing. ARINC 664 (AFDX), used on newer airframes like the A380 and B787, adds switched Ethernet with bandwidth partitioning and deterministic behavior—more connected, but still not a general-purpose network.
- Integrated Modular Avionics (IMA): Multiple functions share compute platforms under strict partitioning, enforced in hardware and certified at DAL-A (Design Assurance Level A, meaning catastrophic failure conditions must be “extremely improbable”).
- Passenger Wi-Fi and In-Flight Entertainment (IFE): The most exposed part of the aircraft—consumer-grade networking, media content loading, thousands of untrusted client devices.
- Datalinks: ACARS over VHF and SATCOM, CPDLC, ADS-B out/in. These are the pipes between the aircraft and the ground.
- Maintenance interfaces: Laptops plugged into avionics during line maintenance, software data loaders, and the toolchains that push loadable software parts onto the airframe.
The critical architectural question—the one every credible analysis comes back to—is whether these domains are properly segmented. On a correctly maintained, certified airframe, the answer is yes, mostly by physics and partitioning rather than by firewalls.
Why Legacy Avionics Are Hard to Hack
Traditional penetration testing assumes general-purpose operating systems, shared networks, and fast patch cycles. Flight-critical avionics violate all three assumptions:
- Deterministic buses with no routing intelligence. ARINC 429 has no concept of an address, a session, or a route. There is no way to “send a packet” to the flight control computer from a bus segment you’re not physically on.
- No general-purpose OS in the critical path. Flight control software runs on bare-metal or RTOS platforms with no shell, no dynamic loading of arbitrary code, and no interpreters. There’s no injection point for memory-corruption exploits in the way a web application exposes one.
- Certification freezes change. DO-178C-compliant software changes require re-verification across the entire qualification chain. An airline can’t patch an FMC on a Tuesday because a CVE dropped—the change control regime is the security control, even if nobody intended it that way.
- Physical access requirements. Most credible avionics attack paths documented in research require access to equipment bays, maintenance panels, or avionics buses—meaning the attacker is already on the aircraft with tools and time.
This is the core insight that the sensational headlines miss: aircraft cybersecurity is not a software patching problem, because the attack surface was never exposed in the first place.
Myth vs. Reality: The “Hacker Took Down a Plane” Claims
Separate the documented research from the verified incidents, because the gap is enormous.
In 2015, security researcher Chris Roberts claimed—via tweets en route to Syracuse—that he could access engine controls through the in-flight entertainment system on a United Airlines aircraft. The FBI detained and interviewed him; his equipment was seized. What was not produced was any verified evidence that he reached flight controls. The FAA and United never confirmed a compromise, and subsequent technical analysis strongly suggested the IFE-to-avionics path was neither claimed accurately nor plausible as described.
In 2013, Hugo Teso’s “PlaneSploit” presentation at Hack In The Board demonstrated attack techniques against ACARS and simulator-based FMS platforms. Technically interesting, widely sensationalized, and—critically—demonstrated against simulation, not live aircraft. The ACARS attack paths he explored were real protocol weaknesses, but the “remote code execution on a flying airliner” framing was media invention.
Meanwhile, documented, confirmed incidents cluster elsewhere: ADS-B spoofing exercises, GPS jamming and spoofing in conflict zones (documented extensively by OPS Group and Eurocontrol), and a long list of ground-side IT outages. No regulator—the FAA, EASA, or ICAO—has ever confirmed a successful in-flight compromise of flight-critical systems by an external attacker. That’s not complacency; that’s the actual threat model.
ADS-B: Unauthenticated by Design
Automatic Dependent Surveillance–Broadcast is the transponder technology that replaced radar as the primary surveillance mechanism. Each aircraft broadcasts its position, velocity, and identity continuously on 1090 MHz—and it does so with no encryption and no authentication.
Why? ADS-B was standardized in the late 1990s and early 2000s (ICAO Annex 10, RTCA DO-260/DO-260B) as a broadcast protocol optimized for low latency, universal interoperability, and cheap avionics. Adding cryptographic signing would have required a key management infrastructure across every airframe, every ground station, and every receiver on the planet—a nonstarter then, and a hard retrofit now. Everyone on the same channel must be able to hear everyone else; confidentiality and authenticity were traded away by design.
The consequences are well-demonstrated: ghost aircraft can be injected onto displays (researchers including Andrei Costin and Brad Haines demonstrated this publicly around 2012–2013), tracks can be spoofed or replayed, and receiver aggregation networks—ADS-B Exchange, FlightAware, the OpenSky Network—turn a $30 RTL-SDR dongle into a legitimate surveillance research platform. The practical mitigations in real ATC environments are multi-sensor fusion, plausibility checks against radar and flight plans, and passive multilateration—not cryptography on the message itself.
Crucially: ADS-B is a spoofing and tracking risk. It is not a flight-control risk. Nobody’s autopilot executes commands parsed from a 1090 MHz frame.
SATCOM and ACARS: The Datalink Problem
ACARS (Aircraft Communications Addressing and Reporting System) is the workhorse datalink of commercial aviation: weather requests, gate assignments, engine reports, OTA-style messages between ops and the cockpit. Classic ACARS over VHF is cleartext. Anyone with acarsdec and a cheap receiver can read it. There is no application-layer authentication, no signing, and no encryption in the legacy protocol—the “trust” model is essentially “we share this frequency, so the messages are probably real.”
Honeywell’s own research team disclosed in 2019–2020 several vulnerabilities in SATCOM units (including issues in their MCS-7820 terminal family), demonstrating that the radio hardware itself—long treated as a certified black box—runs firmware with real software weaknesses. CISA published advisories on these findings. The takeaway: the datalink chain from the radio to the avionics interface is software too, and it ages like any other firmware.
The modernization path is the Aeronautical Telecommunication Network (ATN) with CPDLC, which introduces proper message authentication and addressing—but adoption is uneven, and legacy ACARS will remain in the wild for years. Until then, treat every ACARS message as attacker-controllable input to any downstream system: this is where the aviation domain meets a lesson OWASP has been teaching web engineers for two decades—never trust input from a channel you don’t control.
Ground Infrastructure: Where the Real Risk Lives
Here is the uncomfortable asymmetry: the airframe is certified, isolated, and slow-changing; the ground is enterprise IT with aviation-specific software bolted on.
- Airline ops networks run dispatch, crew scheduling, flight planning, and weight-and-balance systems—the same class of enterprise attack surface as any other large company, with regulatory consequences per hour of downtime. The 2017 British Airways IT failure (a power/data-center fault, not an attack) showed what a single ground-system failure does to a global network. The 2022-2023 FAA NOTAM system outage—which grounded all U.S. departures for the first time since 9/11—was traced to a damaged database file and a contractor error: a contractor deleting files while overlapping directories, per the FAA’s own post-incident statement. Not an attack—but a vivid demonstration of single-point fragility.
- Electronic Flight Bags (EFBs) are iPads and enterprise mobility platforms, full stop. They touch performance calculations, charts, and company datalink messaging. Mobile device management is the security boundary now.
- Maintenance software and the software loading chain are the pipeline through which loadable software parts reach the airframe. Compromise here means compromise of what gets certified onto the aircraft—a supply-chain problem that CISA has repeatedly flagged across critical infrastructure.
An attacker who wants to affect aviation operations doesn’t need to touch a flight control computer. Disrupting dispatch, NOTAMs, or the data pipeline to the aircraft achieves operational impact at a fraction of the technical difficulty.
Passenger Wi-Fi and IFE: Can You Reach the Cockpit?
The claim that gets every headline. The engineering reality: on certified modern aircraft, the cabin domain (Wi-Fi, IFE) connects to avionics—when it connects at all—through tightly controlled interfaces designed to pass specific data (weather, position for moving maps) in one direction or through protocol-restricted gateways. ARINC 429’s unidirectional, point-to-point wiring makes lateral movement physically meaningless on legacy airframes. On AFDX aircraft, partitioning and certified data load configuration constrain what the cabin network can address.
What should a blue-teamer verify if you’re assessing or auditing these systems? Ask for the data load configuration of the cabin-avionics gateway. Ask which ARINC words cross the boundary. Ask whether the IFE head-end runs a supported OS and how content updates reach it. The lateral-movement claims remain contested precisely because nobody has demonstrated them on a certified configuration—but “contested” is not “impossible,” and the interface design documents are where the answer lives, not in a tweet.
Regulation and Standards: DO-326A, ED-202A, and Airworthiness Security
Aviation security stopped being informal with the publication of RTCA DO-326A (and its European counterpart EUROCAE ED-202A), “Airworthiness Security Process Specification,” followed by DO-355/ED-204A for continued airworthiness and DO-356/ED-203A for security methodologies. These standards require applicants to perform security risk assessment across the entire aircraft lifecycle—design, production, operation, and maintenance—identifying security threats, assessing attack surfaces, and demonstrating that security objectives are met with the same rigor applied to safety objectives under 14 CFR / EASA CS-25.
Practically, this means new type certificates can no longer treat cybersecurity as a bolt-on. The security perimeter, the data flows between aircraft domains, and the handling of maintenance access must be documented and assessed. The FAA’s 2023 advisory circular on airworthiness security and EASA’s ongoing work on cybersecurity in type certification formalize this. The standards are the reason the isolation model is being preserved deliberately—not inherited accidentally—as aircraft get more connected.
Where the Next Risk Is: Autonomy, eVTOL, and Connected Software Updates
The legacy airframe’s immunity is an artifact of its architecture. Newer platforms are dismantling that architecture on purpose:
- Software-defined aircraft and OTA updates. Over-the-air software delivery for aircraft functions collapses the “physical access required” assumption that made avionics attack-resistant. Update-chain integrity, signing, rollback protection, and the loading toolchain become the crown jewels.
- eVTOL and urban air mobility. Startups moving at startup speed, heavy reliance on consumer-derived compute, autonomy stacks processing sensor data with real control authority—these invert the legacy assumption that safety-critical code paths are frozen and simple.
- UTM and drone traffic management. Uncrewed traffic management depends on network identity, remote ID broadcasts (unauthenticated, like ADS-B), and command-and-control datalinks. The ground infrastructure is the aircraft in this model.
Bigger models of connectivity, more software in the loop, more update channels, more third-party data services, more autonomy—each one erodes the physical separation that made the old answer simple.
What Blue-Teamers and CTF Players Can Practice
Aviation is one of the few domains where you can legally practice against the real protocols from your desk:
- ADS-B decoding: dump1090 or readsb with an RTL-SDR dongle (~$30) gives you live aircraft telemetry. ADS-B Exchange and the OpenSky Network offer datasets for offline analysis.
- ACARS decoding: acarsdec or vdlm2dec against VHF frequencies; ACARS messages are unencrypted broadcasts.
- Flight-data analysis: ADS-B Exchange historical data and OpenSky’s research datasets support anomaly-detection exercises—spoofing detection, track-plausibility modeling.
- Simulators: X-Plane and flight sim FMS platforms let you reason about nav-data and FMS input handling without touching real avionics.
Know the legal boundaries: receiving these unencrypted public broadcasts is legal in most jurisdictions, but transmitting on aviation frequencies is not, and jamming or spoofing ADS-B/GPS is a serious offense in the U.S. and EU. Passive listening and analysis—yes. Injection—absolutely not, outside licensed research environments.
Key Takeaways for Security Engineers
- Defend the ground. Airline IT, maintenance chains, EFBs, and NOTAM/dispatch systems are where verified failures and realistic attack paths live.
- Treat datalinks as untrusted. ADS-B and ACARS have no cryptographic guarantees; any system consuming them must validate plausibility, never authenticity-by-protocol.
- Respect the certified isolation model. Don’t retrofit web-security assumptions onto deterministic avionics—but don’t let the cabin-avionics boundary erode unnoticed either.
- Watch the OTA update pipeline. Software-defined aircraft move the perimeter from the equipment bay to the delivery chain.
- Separate claims from confirmed incidents. No regulator has verified an in-flight flight-control compromise; hype analysis damages the discipline.
Frequently Asked Questions
Can a plane’s flight controls be hacked remotely?
There is no verified public case of it happening. The architecture makes it extremely hard: flight controls run on deterministic, partitioned avionics (ARINC 429/AFDX) with no general-purpose operating system, no routable path from the cabin or external datalinks, and software changes locked behind DO-178C certification. Credible attack paths documented in research require physical access to avionics buses or maintenance equipment—not remote access through Wi-Fi.
Is ADS-B a security risk?
It’s a spoofing and tracking risk, not a flight-control risk. ADS-B broadcasts position and identity with no encryption or authentication by design—standardized in an era that prioritized interoperability and low-cost avionics. Ghost aircraft injection and track spoofing are demonstrated, but ADS-B data feeds surveillance displays, not autopilots. Real-world mitigation relies on multi-sensor fusion and plausibility checks.
Was the 2015 “hacked a plane through IFE” claim proven?
No. Chris Roberts claimed on Twitter that he could access engine controls via the IFE system; the FBI investigated and seized his equipment, but no verified evidence of a compromise was produced, and the FAA and United Airlines never confirmed the claim. It remains the most cited anecdote in aviation cybersecurity—and the clearest example of a claim outrunning the evidence.
Can I legally decode ADS-B and ACARS signals myself?
Yes. Both are unencrypted public broadcasts. An RTL-SDR dongle with dump1090 (ADS-B on 1090 MHz) or acarsdec (ACARS on VHF) is a common and legal hobbyist setup in most jurisdictions. The line is transmission: injecting spoofed signals or jamming aviation frequencies is illegal in the U.S. and EU, with serious penalties.
What’s the biggest aviation cybersecurity threat today?
Ground-side systems, not the airframe. The FAA NOTAM outage of January 2023, airline IT outages, fragile maintenance software, and the supply chain feeding loadable software parts to aircraft all represent confirmed or realistic failure modes. The airframe’s certified isolation holds; the enterprise IT and data pipelines around it are where attackers will find their returns.
Related reading
- What Is Prompt Injection and How to Prevent It: A Complete Exam Prep Guide
- Pyramid of Pain to Production: How Detection Engineers Prioritize What to Hunt
