Researcher Shows How To Hack A Plane With An Android Phone

Flaws in airline communication systems could lead to plane hijacks carried out just by software, a researcher has claimed, showing how this could be done using just an Android phone.

Whilst the findings appear initially terrifying, the researcher behind the findings, Hugo Teso, took four years to uncover the flaws in aircraft systems he needed to hijack a virtual plane, not a real one. And his work could and should get software developers to improve aircraft security.

Teso, who works at German IT consultancy N.Runs and used to test systems running critical infrastructure, found a range of different flaws that let him hijack a flight simulator session to send the jet in different directions and adjust its speed.

BA British Airways plane aeroplance © Steve Mann / Shutterstock.comAndroid vs. aircraft

He showed off his work at the Hack In A Box conference in Amsterdam, hijacking two protocols called Automatic Dependent Surveillance-Broadcast (ADS-B) and Aircraft Communications Addressing and Report System (ACARS). The first is a replacement for radar and used to send location and altitude information to the ground, whilst ACARS is used for exchanging a variety of messages in text, via radio or satellite.

His attack also used flaws in flight management software dealing with ACARS interactions run by a number of firms, including French company Thales, which builds plenty of security systems itself, according to Forbes. Thales had not responded to a TechWeek request for comment at the time of publication.

Teso found there was very little security in ADS-B and ACARS, which was exploited to easily spoof messages to affect the behaviour of the plane, as noted in Teso’s presentation slides. However, Teso is understood to be talking with a number of the affected organisations and is not revealing any specifics on the vulnerabilities, due to their sensitive nature.

He built an Android app to easily execute his exploits and ran it on a Samsung Galaxy device, showing how he could set up an ACARS session and just tap on the map within the application to change the direction of the virtual plane. That plane was created using hardware bought from eBay and simulation software he believed contained the same code as found on real planes.

The Federal Aviation Administration and the European Aviation Safety Administration have been contacted about the findings.

Teso, a qualified commercial pilot as well as security researcher, and others have noted pilots should be able to override any dangerous commands manually.

What do you know about Internet security? Find out with our quiz!

Thomas Brewster

Tom Brewster is TechWeek Europe's Security Correspondent. He has also been named BT Information Security Journalist of the Year in 2012 and 2013.

Recent Posts

Virgin Media O2 To Invest £700m To ‘Transform’ 4G, 5G Network

Virgin Media O2 confirms it will invest £2m a day for new mobile masts, small…

13 hours ago

Tesla Cybertruck Deliveries On Hold Due To Faulty Side Trim

Deliveries of Telsa's 'bulletproof' Cybertruck are reportedly on hold, amid user complaints side trims are…

14 hours ago

Apple Plots Live Translation Option For AirPods – Report

New feature reportedly being developed by Apple for iOS 19, that will allow AirPods to…

15 hours ago

Binance Token Rises After Trump Stake Report

Binance BNB token rises after WSJ report the Trump family is in talks to secure…

1 day ago

iRobot Admits ‘Substantial Doubt’ Over Continued Operation

After failed Amazon deal, iRobot warns there is “substantial doubt about the Company's ability to…

1 day ago

Meta’s Community Notes To Use X’s Algorithm

Community Notes testing across Facebook, Instagram and Threads to begin next week in US, using…

2 days ago