• Home
  • Latest
  • Fortune 500
  • Finance
  • Tech
  • Leadership
  • Lifestyle
  • Rankings
  • Multimedia

Trendingnow

1

Jeff Bezos wants the bottom half of earners to pay zero income tax—he says nurses making just $75K should save $12K a year

2

Apple’s Steve Wozniak says he cofounded the tech giant after 5 rejections from HP—not to ‘make money.’ For years, his paycheck was just $50

3

Indeed chief economist says we’re entering an era of ‘great mismatch’ thanks to a generational imbalance of workers

1

Jeff Bezos wants the bottom half of earners to pay zero income tax—he says nurses making just $75K should save $12K a year

2

Apple’s Steve Wozniak says he cofounded the tech giant after 5 rejections from HP—not to ‘make money.’ For years, his paycheck was just $50

3

Indeed chief economist says we’re entering an era of ‘great mismatch’ thanks to a generational imbalance of workers
PoliticsU.S. Politics

Homeland Security Issuing Hacking Alert for Small Planes

By
Tami Abdollah
Tami Abdollah
and
The Associated Press
The Associated Press
Down Arrow Button Icon
By
Tami Abdollah
Tami Abdollah
and
The Associated Press
The Associated Press
Down Arrow Button Icon
July 30, 2019, 9:28 AM ET

The Department of Homeland Security plans to issue a security alert Tuesday for small planes, warning that modern flight systems are vulnerable to hacking if someone manages to gain physical access to the aircraft.

An alert from the DHS critical infrastructure computer emergency response team recommends that plane owners ensure they restrict unauthorized physical access to their aircraft until the industry develops safeguards to address the issue, which was discovered by a Boston-based cybersecurity company and reported to the federal government.

Most airports have security in place to restrict unauthorized access and there is no evidence that anyone has exploited the vulnerability. But a DHS official told The Associated Press that the agency independently confirmed the security flaw with outside partners and a national research laboratory, and decided it was necessary to issue the warning.

The cybersecurity firm, Rapid7, found that an attacker could potentially disrupt electronic messages transmitted across a small plane’s network, for example by attaching a small device to its wiring, that would affect aircraft systems.

Engine readings, compass data, altitude and other readings “could all be manipulated to provide false measurements to the pilot,” according to the DHS alert obtained in advance by AP.

The warning reflects the fact that aircraft systems are increasingly reliant on networked communications systems, much like modern cars. The auto industry has already taken steps to address similar concerns after researchers exposed vulnerabilities.

The Rapid7 report focused only on small aircraft because their systems are easier for researchers to acquire. Large aircraft frequently use more complex systems and must meet additional security requirements. The DHS alert does not apply to older small planes with mechanical control systems.

But Patrick Kiley, Rapid7’s lead researcher on the issue, said an attacker could exploit the vulnerability with access to a plane or by bypassing airport security.

“Someone with five minutes and a set of lock picks can gain access (or) there’s easily access through the engine compartment,” Kiley said.

Jeffrey Troy, president of the Aviation Information Sharing and Analysis Center, an industry organization for cybersecurity information, said there is a need to improve the security in networked operating systems but emphasized that the hack depends on bypassing physical security controls mandated by law.

With access, “you have hundreds of possibilities to disrupt any system or part of an aircraft,” Troy said.

The Federal Aviation Administration said in a statement that a scenario where someone has unrestricted physical access is unlikely, but the report is also “an important reminder to remain vigilant” about physical and cybersecurity aircraft procedures.

Aviation cybersecurity has been an issue of growing concern around the world.

In March, the U.S. Department of Transportation’s inspector general found that the FAA had “not completed a comprehensive, strategy policy framework to identify and mitigate cybersecurity risks.” The FAA agreed and said it would look to have a plan in place by the end of September.

The UN’s body for aviation proposed its first strategy for securing civil aviation from hackers that’s expected to go before the General Assembly in September, said Pete Cooper, an ex-Royal Air Force fast jet pilot and cyber operations officer who advises the aviation industry.

The vulnerability disclosure report is the product of nearly two years of work by Rapid7. After their researchers assessed the flaw, the company alerted DHS. Tuesday’s DHS alert recommends manufacturers review how they implement these open electronics systems known as “the CAN bus” to limit a hacker’s ability to perform such an attack.

The CAN bus functions like a small plane’s central nervous system. Targeting it could allow an attacker to stealthily hijack a pilot’s instrument readings or even take control of the plane, according to the Rapid7 report obtained by The AP.

“CAN bus is completely insecure,” said Chris King, a cybersecurity expert who has worked on vulnerability analysis of large-scale systems. “It was never designed to be in an adversarial environment, (so there’s) no validation” that what the system is being told to do is coming from a legitimate source.

Only a few years ago, most auto manufacturers used the open CAN bus system in their cars. But after researchers publicly demonstrated how they could be hacked, auto manufacturers added on layers of security, like putting critical functions on separate networks that are harder to access externally.

The disclosure highlights issues in the automotive and aviation industries about whether a software vulnerability should be treated like a safety defect — with its potential for costly manufacturer recalls and implied liability — and what responsibility manufacturers should have in ensuring their products are hardened against such attacks. The vulnerability also highlights the reality that it’s becoming increasingly difficult to separate cybersecurity from security overall.

“A lot of aviation folks don’t see the overlap between information security, cybersecurity, of an aircraft, and safety,” said Beau Woods, a cyber safety innovation fellow with the Atlantic Council, a Washington think tank. “They see them as distinct things.”

The CAN bus networking scheme was developed in the 1980s and is extremely popular for use in boats, drones, spacecraft, planes and cars — all areas where there’s more noise interference and it’s advantageous to have less wiring. It’s actually increasingly used in airplanes today due to the ease and cost of implementation, Kiley said.

Given that airplanes have a longer manufacturing cycle, “what we’re trying to do is get out ahead of this.”

The report didn’t name the vendors Rapid7 tested, but the company alerted them over a year ago, the report states.

More must-read stories from Fortune:

—The strongest Democratic candidate for 2020 is a woman, poll finds

–Why kids are skipping school to fight climate change

—Thousands of migrant children remain in shelters at the border

—What to expect from the second Democratic debate

—When it comes to politics, Americans are divided. Can data change that?

Get up to speed on your morning commute with Fortune’s CEO Daily newsletter.

About the Authors
By Tami Abdollah
See full bioRight Arrow Button Icon
By The Associated Press
See full bioRight Arrow Button Icon

Latest in Politics

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025

Most Popular

Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Finance
Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam
By Fortune Editors
October 20, 2025
Fortune Secondary Logo
Rankings
  • 100 Best Companies
  • Fortune 500
  • Global 500
  • Fortune 500 Europe
  • Most Powerful Women
  • World's Most Admired Companies
  • See All Rankings
  • Lists Calendar
Sections
  • Finance
  • Fortune Crypto
  • Features
  • Leadership
  • Health
  • Commentary
  • Success
  • Retail
  • Mpw
  • Tech
  • Lifestyle
  • CEO Initiative
  • Asia
  • Politics
  • Conferences
  • Europe
  • Newsletters
  • Personal Finance
  • Environment
  • Magazine
  • Education
Customer Support
  • Frequently Asked Questions
  • Customer Service Portal
  • Privacy Policy
  • Terms Of Use
  • Single Issues For Purchase
  • International Print
Commercial Services
  • Advertising
  • Fortune Brand Studio
  • Fortune Analytics
  • Fortune Conferences
  • Business Development
  • Group Subscriptions
About Us
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • About Us
  • Press Center
  • Work At Fortune
  • Terms And Conditions
  • Site Map
  • Facebook icon
  • Twitter icon
  • LinkedIn icon
  • Instagram icon
  • Pinterest icon

Latest in Politics

Secret Service shoot and kill suspect who fired at White House checkpoint; bystander was also struck but Trump was not affected
Europegun violence
Secret Service shoot and kill suspect who fired at White House checkpoint; bystander was also struck but Trump was not affected
By Darlene Superville, Alanna Durkin Richer and The Associated PressMay 23, 2026
6 hours ago
Ukrainian drone attack causes fire at Russian oil terminal used for exports as Kyiv expands long-range strike capabilities
PoliticsRussia
Ukrainian drone attack causes fire at Russian oil terminal used for exports as Kyiv expands long-range strike capabilities
By The Associated PressMay 23, 2026
8 hours ago
U.S. reaches limit of sanctions power in targeting Iran’s economy
PoliticsIran
U.S. reaches limit of sanctions power in targeting Iran’s economy
By Magdalena Del Valle and BloombergMay 23, 2026
8 hours ago
Trump’s 3,711 trades point to multiple stock-market strategies
InvestingDonald Trump
Trump’s 3,711 trades point to multiple stock-market strategies
By Justina Lee, Vivien Ngo, Elena Popina, Matthew Griffin and BloombergMay 23, 2026
9 hours ago
As U.S.-Iran deal nears, Trump ally warns against creating perception Tehran controls Hormuz — ‘it makes one wonder why the war started to begin with’
PoliticsIran
As U.S.-Iran deal nears, Trump ally warns against creating perception Tehran controls Hormuz — ‘it makes one wonder why the war started to begin with’
By Jason MaMay 23, 2026
9 hours ago
Trump says a deal with Iran that would reopen the Strait of Hormuz has been ‘largely negotiated’
PoliticsIran
Trump says a deal with Iran that would reopen the Strait of Hormuz has been ‘largely negotiated’
By Munir Ahmed, Samy Magdy, Matthew Lee and The Associated PressMay 23, 2026
10 hours ago

Most Popular

Jeff Bezos wants the bottom half of earners to pay zero income tax—he says nurses making just $75K should save $12K a year
Success
Jeff Bezos wants the bottom half of earners to pay zero income tax—he says nurses making just $75K should save $12K a year
By Preston ForeMay 21, 2026
3 days ago
Apple’s Steve Wozniak says he cofounded the tech giant after 5 rejections from HP—not to ‘make money.’ For years, his paycheck was just $50
Success
Apple’s Steve Wozniak says he cofounded the tech giant after 5 rejections from HP—not to ‘make money.’ For years, his paycheck was just $50
By Preston ForeMay 22, 2026
2 days ago
Indeed chief economist says we’re entering an era of ‘great mismatch’ thanks to a generational imbalance of workers
Success
Indeed chief economist says we’re entering an era of ‘great mismatch’ thanks to a generational imbalance of workers
By Emma BurleighMay 22, 2026
2 days ago
Microsoft reports are exposing AI's real cost problem: Using the tech is more expensive than paying human employees
AI
Microsoft reports are exposing AI's real cost problem: Using the tech is more expensive than paying human employees
By Jake AngeloMay 22, 2026
2 days ago
Elon Musk's SpaceX IPO filing just told us what business he's betting on for the future—and it's not rockets
Investing
Elon Musk's SpaceX IPO filing just told us what business he's betting on for the future—and it's not rockets
By Shawn TullyMay 23, 2026
23 hours ago
Meet a 21-year-old community college student who's going to China as the first American woman welder in the trades Olympics
Future of Work
Meet a 21-year-old community college student who's going to China as the first American woman welder in the trades Olympics
By Mike Householder and The Associated PressMay 17, 2026
7 days ago

© 2026 Fortune Media IP Limited. All Rights Reserved. Use of this site constitutes acceptance of our Terms of Use and Privacy Policy | CA Notice at Collection and Privacy Notice | Do Not Sell/Share My Personal Information
FORTUNE is a trademark of Fortune Media IP Limited, registered in the U.S. and other countries. FORTUNE may receive compensation for some links to products and services on this website. Offers may be subject to change without notice.