FAA Left Air Traffic Systems ‘Vulnerable to Cyberattacks’

The federal agency responsible for keeping American skies safe has failed to properly secure critical air traffic control systems, even as it considers handing a massive modernization contract to foreign companies with deep ties to Communist China.

Aviation experts are sounding the alarm over the Federal Aviation Administration’s shortlist for its new Common Automation Platform, a sweeping overhaul of how controllers track flights and move aircraft between facilities. Two of the four companies under consideration, Spain’s Indra and France’s Thales, have been “deeply entrenched” with China’s aerospace industry for decades.

The timing couldn’t be worse. A Department of Transportation Inspector General report from April found the FAA had left many of its systems “vulnerable to cyberattacks that could cause severe or catastrophic effects” on the National Airspace System. Between 2020 and 2025, nearly 2,300 cybersecurity incidents in the aviation sector were reported to the Cybersecurity and Infrastructure Security Agency.

CISA itself flagged the “threat posed by malicious cyber actors” working on China’s behalf in its 2024 threat priorities report.

Transportation Secretary Sean Duffy announced the push for a “single, state-of-the-art platform” last November as part of his plan to build a brand-new air traffic control system. The FAA’s shortlist also includes U.S.-based Leidos and RTX, according to Air Current, which reported in April that all four companies were asked to present their CAP proposals at the agency’s Washington headquarters.

The contrast with how Europe protects its airspace is striking. In 2024, the European Union put regulations in place barring non-EU companies from providing air traffic control services in any member states. America, meanwhile, appears ready to welcome contractors whose business relationships with Beijing raise obvious counterintelligence concerns.

A July 2026 Government Accountability Office report titled “FAA and TSA Are Collaborating on Cybersecurity but Need to Address Key Shortfalls” urged the FAA to update its Zero Trust Architecture implementation plan. The framework operates on the principle of “never trust, always verify,” treating every user, device, and application as untrusted by default.

Without adopting such measures, the GAO warned, the FAA “cannot ensure that it is effectively managing cybersecurity risks, including during NAS modernization.”

The stakes extend far beyond bureaucratic procedure. America’s air traffic control infrastructure represents a crown jewel of critical national systems. A successful cyberattack could ground commercial aviation, disrupt military operations, and endanger countless lives.

MORE STORIES