A federal watchdog says the Federal Aviation Administration still has critical work to do to protect aircraft communications from spoofing and jamming, including completing risk assessments and establishing broader real-time detection. The warning, disclosed Monday in a new government report described by Reuters, puts a concrete operational gap at the center of a long-running aviation cybersecurity debate: federal agencies recognize that manipulated radio and navigation signals can disrupt flights, but parts of the national system still lack the monitoring and documentation needed to identify every threat quickly.

The report says attackers could transmit fraudulent cancellations of air-traffic clearances, potentially producing delays or safety hazards. It also says the FAA has not completed the risk reviews and security documents needed to address spoofing and jamming, and lacks real-time detection for all spectrum-related threats. Those findings do not establish that a successful attack has caused an aviation accident. They do show that the agency responsible for the world’s most heavily used airspace remains unable to observe and assess every relevant signal threat as it develops.

A new warning follows unfinished cyber work

Monday’s findings are consistent with a broader GAO review released in July. That audit found that the FAA had fully implemented only three of seven objectives supporting its goal of protecting networks and systems. Four objectives — including better cyber monitoring, detection and response, tighter privileged-user controls, alignment with federal security standards and development of zero-trust architecture — were only partly implemented as of February.

The July audit identified the same class of operational consequences now highlighted in the spectrum report. It said exploited weaknesses could cause loss of flight data, disrupt communications with air-traffic control, alter information used by cockpit systems, jam radio-frequency signals, spoof aircraft location data or impersonate ground stations. The Department of Transportation agreed with the audit’s four recommendations for the FAA, which included stronger implementation monitoring, more complete cyber-budget reporting and a fuller zero-trust plan.

The gap is detection, not just prevention

Modern aviation security depends on knowing when trusted data have been denied or falsified. Jamming overwhelms a legitimate signal, while spoofing supplies a convincing false one. Both can interfere with positioning, navigation, timing or communications, but spoofing can be harder to recognize because a system may continue displaying plausible information.

The federal record shows why real-time coverage matters. The July GAO audit cited a Transportation Department inspector general finding that the FAA was not performing near-real-time monitoring on 62 of 85 critical airspace cyber-management systems. By June, the agency said it had added monitoring to 20 of those systems, decommissioned one and judged six unsuitable for onboarding because of technical limits or planned retirement. Work remained on 35 systems. That issue concerns cyber monitoring rather than every radio-spectrum threat, but it points to the same policy problem: a warning that arrives after an operational disruption is less useful than one that can trigger an immediate response.

The exposure has been documented for years

GAO has repeatedly warned that increased connectivity expands aviation’s attack surface. A 2020 audit said the FAA had not fully implemented several elements of risk-based avionics oversight, including an overall risk assessment, independent-testing guidance and a mechanism for tracking cybersecurity issues to resolution. At the time, auditors said they had found no reported successful cyberattack on an airplane’s avionics systems, an important limit that separates documented vulnerabilities from proven compromise.

A separate 2018 review examined Automatic Dependent Surveillance-Broadcast, the technology through which aircraft transmit precise location and other flight information. Auditors found that ADS-B could be exposed to cyberattack and electronic warfare, while also creating security risks through public tracking of military aircraft. The government later implemented accommodations for certain Defense Department flights, showing that identified signal risks can be reduced when agencies approve specific operational mitigations.

A system with little room for blind spots

The FAA’s scale magnifies even narrow weaknesses. Its Air Traffic Organization handles more than 44,000 flights and more than 3 million passengers on a typical day across 29 million square miles of airspace. Communications and navigation services must remain available across that system while agencies modernize aging equipment and connect more digital components.

Responsibility is also divided. The Transportation Department’s research and technology office coordinates federal positioning, navigation and timing policy and is charged with protecting those systems from harmful radio-frequency interference and operational degradation, according to its stated responsibilities. The FAA operates and regulates aviation systems, while other federal entities oversee spectrum, cybersecurity and national-security concerns. That structure makes current risk documentation and clear escalation procedures as important as any individual sensor.

What Congress and the FAA now face

The immediate policy question is not whether every conceivable transmission can be prevented. It is whether the FAA can identify priority threats, detect harmful interference quickly, distinguish malicious activity from equipment failure and give controllers and flight crews reliable fallback procedures. Monday’s report indicates that the agency has not yet completed that foundation for the full range of spectrum risks.

Congress can press for measurable deadlines: when the missing risk assessments will be finished, which systems will gain real-time detection, what coverage will remain unavailable and how the FAA will test its response without jeopardizing live operations. The agency also needs to explain how spectrum monitoring fits with the cybersecurity improvements already underway. The distinction matters because radio interference, compromised networks and falsified navigation data may require different technical defenses, even when they produce similar operational symptoms.

The evidence does not support claims that U.S. air travel is broadly unsafe or that hackers have taken control of passenger aircraft. It supports a narrower but consequential conclusion: watchdogs have again identified incomplete safeguards in systems on which safe flight depends. Closing those gaps before a serious incident is the purpose of risk-based regulation — and the standard by which the FAA’s response should now be judged.