FAA Ground Stops and the Warning on Air Traffic Radio Security

The Federal Aviation Administration ordered a ground stop at about 10 a.m. on Monday, Sept. 21, 2026, for Newark Liberty International, Philadelphia International and Teterboro airports. Arrivals and departures at Newark were delayed during the stop.
Some radio frequencies at the Philadelphia Terminal Radar Approach Control (TRACON) were affected until the early afternoon on Sept. 21, according to the most recent reporting on the incident The Guardian. A TRACON is the control facility that guides aircraft flying near airports. The FAA had reported a telecommunications issue at Philadelphia TRACON Area C on Sept. 18.
Ground stops are the most restrictive form of traffic management. Under the FAA definition, they hold all aircraft covered by the stop at their departure points.
The disruption coincided with publication of a Government Accountability Office report, GAO-26-108439, on spectrum security in national airspace communications. Spectrum here means the radio waves used for voice and data links between controllers and pilots. The GAO found the FAA has yet to finish risk assessments or update security documentation covering spoofing, jamming and other radio spectrum attacks. Spoofing means sending fake signals. Jamming means blocking real ones. Seven of eight reviewed systems lacked a formal assessment.
The GAO also found the FAA lacks a real-time system to detect all spectrum threats and can generally only investigate incidents after they are reported. Two systems used to send text messages to aircraft predate modern cybersecurity standards and lack common protections such as encryption, the scrambling that keeps messages private and hard to forge. In that configuration, the GAO warned, a hacker could send fraudulent messages to aircraft, such as false cancellations of flight clearances, with potential to cause delays, disrupt airspace or create safety risks.
The scale of the system under review is large. The FAA handles more than 44,000 flights a day and about 3 million passengers, according to the GAO. Loss of voice or data link, even brief, forces traffic managers toward ground stops and airborne holding.
The GAO made nine recommendations. They include formal risk assessment of seven of eight reviewed systems, continuous monitoring for interference, spoofing and jamming, and formal guidance on information sharing. The Department of Transportation, replying for the FAA, agreed with all nine recommendations.
Sen. Ron Wyden said the FAA's failure to require the aviation industry to use secure communications is "a major threat to US national security, the economy and the safety of the flying public." He said the FAA needs to "issue new standards as soon as possible to protect the security of airline communications."
Prior Newark disruptions and TRACON architecture
Newark has had repeated air traffic control disruptions. In April 2025, an outage blanked controllers' screens for roughly 60 to 90 seconds and cut their contact with aircraft, prompting the FAA to halt departures affecting Newark. The FAA later moved the Philadelphia TRACON to a new fiber-optic link with New York on two separate paths. Separately, the FAA moved the Newark sector out of New York TRACON into the Philadelphia TRACON.
Other constraints on Newark throughput predate the Sept. 21 ground stop. The FAA has stated it has been slowing arrivals and departures at Newark Liberty International Airport due to runway construction at Newark. A Newark ground stop attributed to 'volume' had been lifted, as reported by the FAA on March 20, 2026. In FY2024, LaGuardia (LGA), Newark (EWR), and Denver (DEN) had the highest number of ground stops. Incoming flights to Newark and Teterboro airports were ground-stopped due to FAA equipment issues until 12:30 p.m. in an August 2025 incident.
A longer audit trail
The Sept. 21 findings extend audits going back more than a decade. In January 2015, the GAO reported that the FAA had taken steps to protect its air traffic control systems from cyber-based threats but that significant security-control weaknesses remained. In report GAO-15-221, the GAO recommended that the FAA take 168 specific actions to address weaknesses in security of air traffic control systems GAO. FAA acquisition management policy requires air traffic control systems to obtain security assessments, certification, and accreditation by the time they are operational.
The GAO stated in report GAO-21-86 that aviation cybersecurity vulnerabilities could occur from not patching commercial software and from insecure supply chains GAO. More recently, the GAO issued product GAO-26-107693 on aviation cybersecurity concerning collaboration between the FAA and TSA GAO.
The broader context here is structural rather than episodic. Spectrum-based air-ground voice remains largely unauthenticated, like an open radio channel with no login, while the controller-pilot text systems cited by auditors lack encryption by design. That architecture assumes a cooperative radio environment. Spoofing and jamming violate that assumption at low cost. Detection after user report leaves a gap between injection and mitigation, during which controllers must treat voice and text instructions as potentially unreliable.
Looking at what this means for operators and regulators, three questions carry weight. First, whether continuous monitoring for interference, spoofing and jamming can be fielded across TRACONs without adding nuisance alerts that erode controller trust. Second, whether new standards for secure communications will apply to aircraft equipage, ground infrastructure, or both, and on what retrofit timeline. Third, how information sharing will work between the FAA, carriers, avionics vendors and federal security agencies when an event affects frequencies rather than enterprise networks. The Department of Transportation's agreement to all nine recommendations settles direction. Implementation will define risk.


