Citation spine

Evidence

Every operative claim used on this site, with attribution. Prefer this page or the PDFs over secondary paraphrase.

Last updated July 30, 2026 · Changelog · How to cite · Corrections · What we do not claim · Evidence dossier (PDF) ↗

Read this first

We do not claim this attack has been carried out. We do not claim any specific airport is vulnerable. We do not claim to know what capabilities the FAA may have deployed and not disclosed. We do not claim the novel’s scenario is a forecast.

We claim that this layer is unauthenticated, that it has been publicly demonstrated, and that the current modernization program does not appear to address it.

How to cite this

Smith, Sunny Paul, with Ernie Ortiz (2026). “Evidence.” HAIJACKED, https://haijacked.com/evidence. Accessed [date].

Smith, Sunny Paul, with Ernie Ortiz (2026). “Policy Brief: Unauthenticated Aviation VHF Voice Communication.” HAIJACKED, https://haijacked.com/brief.pdf. Accessed [date].

Changelog

  • 2026-07-30 Site published. Citation spine, policy brief, and evidence dossier posted.
  • 2026-07-30 Corrected Vu & Wei section references; separated reconciliation bill (H.R.1) from the 2024 FAA Reauthorization Act; narrowed Doc 4444 citations; revised historical-incident sourcing.

The Vulnerability

Aviation VHF voice communication operates on unencrypted analog channels, 118.0–136.975 MHz.

Aviation VHF band allocation (118.0–136.975 MHz)

There is no cryptographic authentication, no digital signature, and no challenge-response mechanism on these channels.

Source: Vu & Wei (2026), § III — threat model: “exploiting the absence of cryptographic authentication and encryption in legacy VHF voice communication architectures.”

Pilots comply based on four cues: the voice sounds like the controller, it arrives on the expected frequency, it uses correct phraseology, and it is contextually plausible.

Operational practice; phraseology governed by ICAO Doc 4444, Procedures for Air Navigation Services — Air Traffic Management

The openness is deliberate and operationally valuable — pilots need to hear other traffic. This is why encryption has consistently been rejected.

Operational design of open VHF party-line voice; encryption would break shared situational awareness


The 2025 Demonstration

On Sunday, August 10, 2025, Andrew "Helicopters of DC" Logan — audio engineer and aviation-transparency researcher — presented "Voice Cloning Air Traffic Control: Vulnerabilities at Runway Crossings" on the main DEF CON 33 speaker track.

Source: DEF CON 33 official schedule, Main Track, August 10, 2025.

The presentation was delivered on the main DEF CON speaker track — not the Aerospace Village.

Source: DEF CON 33 official program; Aviation International News, August 22, 2025 ↗

The talk was covered by Aviation International News on August 22, 2025, under the headline "DEF CON Talk Warns of ATC Voice Cloning 'Nightmare.'"

Source: Aviation International News ↗

The full talk recording is available online.

Source: YouTube — DEF CON 33 recording ↗


The 2026 Research

Dao Vu and Peng Wei of George Washington University published "Generating Realistic Air Traffic Control Voice Communication using AI-based Text-to-Speech Models" — a peer-reviewed conference paper presented at IEEE ICNS 2026, the 26th Integrated Communications, Navigation and Surveillance Conference, Herndon, Virginia, April 14–16, 2026.

Source: Vu & Wei, IEEE ICNS 2026 proceedings ↗

The model was evaluated against 1,000 authentic controller utterances from the ATCOSIM corpus — a standard benchmark dataset of real ATC voice recordings.

Source: Vu & Wei (2026), § V-A, ATCOSIM corpus evaluation methodology.

Results: Word Error Rate 3.9% (median 0%); critical-token F1 = 0.958; speaker-embedding cosine similarity 0.726. The paper notes that same-speaker verification typically reaches ≥0.8 for the same utterance — so 0.726 across different utterances is the striking figure, not a weak one.

Source: Vu & Wei (2026), § V-B, Table I — evaluation metrics.

The authors' threat model: "an adversary capable of generating synthetic ATC-style audio conditioned on publicly available recordings of controller speech… exploiting the absence of cryptographic authentication and encryption in legacy VHF voice communication architectures."

Source: Vu & Wei (2026), § III — threat model definition (direct quotation).

Prosody and cadence were the weakest-reproduced dimensions. The authors listed as a limitation that evaluation was conducted "without explicit VHF channel modeling, radio compression artifacts, or environmental noise injection."

Source: Vu & Wei (2026), § VI — limitations and future work (direct quotation).

The detail worth pausing on

Prosody and cadence were the weakest-reproduced dimension — the detection cue. The researchers then listed as a limitation that their evaluation was conducted “without explicit VHF channel modeling, radio compression artifacts, or environmental noise injection.”

The antagonist of this novel spends months of the story solving precisely that problem. The researchers named the gap as future work. The novel had already walked through it.


Historical Precedent

Date Incident
Apr 1999 USAir flight diverted on approach to Reagan National Airport by unknown voice on frequency
Dec 1999 Transmitter stolen from Edinburgh Airport; false commands issued to aircraft
1999 Ham radio operator issued false instructions to aircraft at Manchester
Jul 2000 Controller at East Midlands Airport transmitted "Respond to my voice only" after impostors detected on frequency

All four incidents are drawn from a single contemporaneous wire story (ABC News, August 29, 2000), which itself cites the Sunday Times for the East Midlands case. SKYbrary summarizes the same attack class.

Sources: ABC News, "Hackers Attack Air Traffic Control," August 29, 2000 ↗; SKYbrary, "Unauthorised Use of ATC Frequency" ↗

Important context

These incidents are twenty-six years old and three of the four are British. They establish that the attack class is old. They establish nothing about the present.

Regulators assessed these incidents as low-severity because pilots read back instructions — and impostors betray themselves with incorrect phraseology or inability to sustain a plausible dialogue.

Source: SKYbrary, "Unauthorised Use of ATC Frequency" — controller and pilot readback as defensive layers.

That is exactly the defense that has stopped working. A model trained on thousands of hours of archived controller audio does not get the phraseology wrong. It produces correct phraseology, in the identity of the specific controller who worked that position, and it can answer a read-back.

As far back as 2000, the FAA acknowledged that unauthorized people periodically use controller frequencies to issue false instructions, including "ghost transmissions" at JFK. Reporting at the time indicated that no capability existed to block or filter such broadcasts. We are not aware of any deployed since.

Source: ABC News, August 29, 2000 ↗


Modernization Funding

$12.5B
Appropriated Jul 4, 2025
~$20B
Additional requested
>$32B
Total commitment

$12.5 billion was appropriated for FAA modernization in the reconciliation bill signed July 4, 2025, with approximately $20 billion additional requested — more than $32 billion in total.

Source: Reconciliation bill text, July 2025; FAA FY2026 budget justification.

Target completion: end of 2028. 612 legacy radar systems to be replaced by June 2028.

Source: FAA National Airspace System modernization timeline, 2025.

Infrastructure migration from copper to fiber, satellite, and wireless links — approximately 40% complete as of program updates.

Source: FAA telecommunications infrastructure program status briefings.

The gap

None of it authenticates the voice on the frequency.


Staffing

The FAA entered 2026 approximately 3,544 certified controllers below its own staffing target.

Source: FAA Controller Workforce Plan, FY2025–2034; NATCA congressional testimony.

More than 41% of certified controllers work 10-hour days, six days per week.

Source: NATCA (National Air Traffic Controllers Association) workforce briefings, 2025–2026.

On May 15, 2026, the FAA revised its staffing target downward from 14,633 to 12,563.

Source: FAA revised CPC staffing standards, published May 15, 2026.


Aviation-Interference Statutes

  • 49 U.S.C. § 46308 — Interference with air navigation; up to 5 years
  • 18 U.S.C. § 32, including § 32(a)(8) — Destruction of aircraft or aircraft facilities; up to 20 years
  • 47 U.S.C. § 333 — Willful or malicious interference with radio communications

Synthetic-Media Legislation

  • TAKE IT DOWN Act (S.146) — Signed May 19, 2025
  • AI Fraud Accountability Act of 2026 (S.3982) — Introduced March 4, 2026
  • NO FAKES Act of 2026 (S.4591) — Reported June 18, 2026

The gap

No federal synthetic-media statute reaches impersonation of a safety-critical operator, and the general aviation-interference statutes predate synthetic voice — they punish the act afterward while requiring no capability to detect or prevent it.


What We Do Not Claim

Scope of Claims

We do not claim this attack has been carried out. We do not claim any specific airport is vulnerable. We do not claim to know what capabilities the FAA may have deployed and not disclosed. We do not claim the novel's scenario is a forecast.

We claim that this layer is unauthenticated, that it has been publicly demonstrated, and that the current modernization program does not appear to address it.


What Remains Unverified

DOT OIG finding (reported April 2026) that the FAA lacks baseline security controls on approximately 10% of "high-impact" ATC systems. Verify

Source: Reported in trade press, April 2026. Primary DOT OIG report not yet independently reviewed.

Reported January 2021 arrest in Berlin for repeated ATC impersonation via unauthorized radio transmission. Verify

Source: German media reports, January 2021. Court records not yet located.


Corrections

Factual corrections are welcome and will be noted in the changelog. Include the page or PDF URL, the claim, the proposed correction, and a source.