Aviation Cyber Risk: Ground-Based Losses Outweigh In-Air Threats, Expert Warns
Aviation cybersecurity expert Eliran Almong highlights that significant financial losses in the airline industry stem from ground-based operations, not in-flight hacking, urging a shift in security focus.
Eliran Almong, CEO of Cyviation, is sounding an alarm that the aviation industry's cybersecurity focus is misplaced, often fixated on the dramatic, yet unlikely, scenario of an aircraft being hacked mid-flight. Instead, Almong argues in a recent interview that the vast majority of realized cyber losses for airlines occur on the ground, impacting critical operations such as reservations, ground handling, maintenance IT, crew scheduling, and airport management. This ground-based infrastructure is frequently the target of ransomware and other cyberattacks, leading to substantial financial damage, while the aircraft itself remains largely untouched in terms of direct cyber-induced financial loss.
While acknowledging that the "hacking a plane" narrative is largely overhyped in its cinematic portrayal, Almong does not dismiss the aircraft's vulnerability entirely. He points out that aircraft are constantly ingesting data from the ground, including navigation databases, performance data, Electronic Flight Bag (EFB) content, and loadable software. This constant data flow makes the aircraft an endpoint in a complex supply chain that is often unmonitored. Therefore, Almong frames the cybersecurity challenge for airline boards as a dual problem: the ground is where financial losses are incurred and should be funded accordingly, while the aircraft represents a blind spot that requires separate attention.
Almong highlights two specific areas that challenge the typical enterprise Security Operations Center (SOC) analyst's understanding. The first is GNSS interference, such as jamming and spoofing, which has become routine in regions like the Eastern Mediterranean, Black Sea, and Persian Gulf. This interference degrades inertial navigation systems and provides false position fixes, but crucially, it leaves no trace in traditional IT security logs or SIEM systems. Detection often relies on pilot reports after landing, presenting a significant telemetry gap for security teams accustomed to detailed log analysis.
The second area of surprise is the prevalence of vulnerabilities stemming from a lack of authentication in critical systems. Almong cites his team's disclosure of CVE-2026-1579 in PX4 Autopilot, a widely used flight control software. This flaw allowed unsigned drone command messages to be accepted, effectively enabling an attacker on the network to fly the aircraft without any complex exploit. This contrasts with typical IT security where the focus is on bypassing existing security measures; in aviation, the issue is often the absence of authentication in safety-critical communication channels from the outset.
Regarding the Electronic Flight Bag (EFB), Almong views it as an underrated entry point but primarily as a symptom of a larger issue. While EFBs are commodity tablets, often used for personal purposes and holding sensitive flight data, their true vulnerability lies in the data loading chain that supports them and delivers other critical software updates. The core problem, according to Almong, is the inability of most operators to verify the integrity and provenance of data as it loads onto the aircraft, and to reconstruct what was loaded afterward.
To address these blind spots, Almong advocates for the use of "digital twins" – virtual models of aircraft subsystems and communication paths. These twins allow for security testing and analysis that cannot be performed on the actual airframe without risking its airworthiness. By simulating data loading processes and replaying events on the digital twin, airlines can identify potential cyber threats and faults before they impact the fleet, moving beyond mere documentation to active, testable security assurance.
Almong also touches upon the delicate balance of handling sensitive operational data. Airlines guard this data, which includes utilization, maintenance practices, and route economics, from manufacturers and lessors for commercial reasons. Cyviation operates on a model where per-customer infrastructure is isolated, ensuring that one airline's fleet data does not mix with another's. Analysis is conducted under the airline's control, and only data they choose to release leaves their environment, maintaining trust and preventing the company from becoming a mere data pipeline for OEMs.
Ultimately, Almong's message is a call for a strategic realignment of cybersecurity investments and efforts within the aviation sector. By shifting focus from the sensationalized threat of in-flight hacking to the tangible risks posed by ground-based operations and the unmonitored data supply chain to aircraft, airlines can build more robust and effective defenses against the cyber threats that truly threaten their financial stability and operational integrity.