← Back to Home
August 12, 2026

Boeing 737s Can Be Hacked in Under 60 Seconds

Coin-Sized Device Can Hack a Boeing 737 in Under 60 Seconds
SECURITY

Coin-Sized Device Can Hack a Boeing 737 in Under 60 Seconds

Here is the detail that should make every frequent flyer put down their in-flight pretzels: a device slightly larger than a quarter, built for under $100, can be plugged into an externally accessible port on a Boeing 737 in about 15 seconds — no special tools required — and from there, it can tell the autopilot where to fly while feeding the pilot completely fabricated data.

Researchers from UC San Diego and Oberlin College are presenting this finding at the Usenix Cybersecurity Conference, and the implications are genuinely unsettling. The Wi-Fi-enabled implant connects to one of the 737's internal networks and can manipulate the systems that control autopilot navigation while simultaneously spoofing the readings a pilot relies on for takeoff calculations — things like aircraft weight and outside air temperature. Get those numbers wrong, even slightly, and a runway overrun becomes a real possibility. Get them very wrong, and the consequences get much worse.

What makes this threat different from the traditional nightmare scenario of a bomb on a plane is exactly what makes it harder to defend against. An attacker using this method gets stealth, deniability, and control. The plane does not explode on the ground. It takes off, appears normal, and the manipulation happens quietly at altitude. By the time something seems wrong, the window to correct it may already be closing.

The research team spent over a decade on this project and dropped tens of thousands of dollars on salvaged aircraft components to test their approach in realistic conditions. The port they exploited sits behind an exterior hatch that maintenance workers, ground crew, and various airport staff routinely access between flights. That is not a hypothetical attack surface — it is a real one, with real people moving around it every day at airports around the world.

The researchers are intentionally withholding which specific port they used, a responsible disclosure move that gives Boeing and aviation regulators time to respond before that detail becomes public knowledge. Boeing has acknowledged the research. The FAA has not yet commented publicly.

The broader point the researchers are making is about a category of attack the aviation industry has largely not had to think about. Aircraft computer systems have historically been considered secure partly because they are air-gapped — disconnected from the internet and therefore hard to reach remotely. But air-gapped does not mean physically inaccessible, and the history of intelligence operations is full of examples where physical access to an isolated system was enough to compromise it entirely.

Aviation security has long focused on what passengers bring onto planes. This research asks an uncomfortable question about what might already be on the outside of the aircraft before anyone boards. The answer, it turns out, could fit in your jacket pocket.
Source: WIRED
DEF CON Hackers Suspected of Fake Hotspot Attack on Delta Flight
SECURITY

DEF CON Hackers Suspected of Fake Hotspot Attack on Delta Flight

The timing here is almost too perfect to be coincidental. One day after the DEF CON security conference wrapped up in Las Vegas, passengers on Delta Flight 591 from Las Vegas to Atlanta allegedly found themselves sitting next to someone who had decided the flight home was a good time to run a hacking demonstration — on their fellow passengers.

According to a pilot message transmitted over publicly tracked air-to-ground communications, a group of passengers who had attended a cyber conference in Las Vegas managed to jam the plane's onboard Wi-Fi and replace it with their own signal. A Reddit post describing the incident added the detail that the fake network was named something reassuringly mundane — "Delta WiFi Fast" — and that anyone who connected was greeted with a phishing page designed to steal their login credentials.

This is what security professionals call an evil twin attack, and it is about as old as Wi-Fi itself. You spin up a hotspot with a convincing name, wait for people to connect automatically or out of habit, and harvest whatever they type into the fake login page. It requires minimal technical sophistication, which is precisely why it remains a staple of beginner-level security demonstrations at conferences like DEF CON.

Delta confirmed the broad strokes to Ars Technica, acknowledging that an unauthorized Wi-Fi network was briefly present on the aircraft. The airline was careful to note that flight safety was never compromised and that no aircraft operating systems were touched. The legitimate onboard Wi-Fi was disabled for about 30 minutes while the situation was sorted out, which, depending on your feelings about airplane Wi-Fi, may or may not count as an inconvenience.

The FBI's Atlanta field office confirmed it is looking into the matter, though as of now no arrests have been made and agents did not meet the plane at the gate. The Atlanta Police Department punted all questions directly to federal authorities, which is a reasonable response when the potential crime involves aircraft and computer fraud statutes.

What is worth noting here is that conducting an evil twin attack on a commercial flight almost certainly crosses several legal lines simultaneously, regardless of how routine the underlying technique is at security conferences. DEF CON has a long-standing ethic around authorized testing — you hack systems you have permission to hack, not the strangers sitting in 24C trying to check their email.

Whether this was a deliberate attack, a demonstration gone sideways, or someone who genuinely did not think through the consequences of bringing their conference energy onto a commercial aircraft, the FBI will presumably have opinions. Flying home from a hacker conference is not, it turns out, an extension of the conference.
Source: Ars Technica

Enjoyed this?

Get stories like this delivered every Tuesday — free.