{"id":36765,"date":"2026-09-05T01:40:13","date_gmt":"2026-09-04T14:40:13","guid":{"rendered":"https:\/\/www.kaspersky.com.au\/blog\/?p=36765"},"modified":"2026-09-05T01:40:13","modified_gmt":"2026-09-04T14:40:13","slug":"hacking-boeing-737-airplane","status":"publish","type":"post","link":"https:\/\/www.kaspersky.com.au\/blog\/hacking-boeing-737-airplane\/36765\/","title":{"rendered":"How to hack a Boeing 737 in 60 seconds for just $100"},"content":{"rendered":"<p>Security researchers have found a <a href=\"https:\/\/www.usenix.org\/system\/files\/usenixsecurity26-crow.pdf\" target=\"_blank\" rel=\"noopener nofollow\">way to hack a Boeing 737<\/a> with a device no bigger than a coin. The 737 is one of the most widely used airliners in the world, so chances are you\u2019ve flown on one yourself at least once.<\/p>\n<p>The attack requires installing a small device in a port that\u2019s accessible through a hatch on the <em>outside<\/em> of the plane. According to the researchers, this port is regularly within reach not just of maintenance crews, but of other airport and airline staff too. And installing the device takes less than 60 seconds. So let\u2019s talk about what this mysterious little device actually is, what it can do, and whether it\u2019s still safe to fly on a Boeing 737.<\/p>\n<h2>Why hacking a plane is harder than hacking a car<\/h2>\n<p>Most of us have gotten used to the idea that our computers and phones can be hacked. It\u2019s probably the most common topic on this blog. But we\u2019ve also covered attacks on less common targets: <a href=\"https:\/\/www.kaspersky.com\/blog\/car-botnet-malware-for-head-units-with-android\/56296\/\" target=\"_blank\" rel=\"noopener nofollow\">cars<\/a>, <a href=\"https:\/\/www.kaspersky.com\/blog\/yarbo-robot-lawn-mower-hacked-2\/56067\/\" target=\"_blank\" rel=\"noopener nofollow\">robot lawnmowers<\/a>, <a href=\"https:\/\/www.kaspersky.com\/blog\/hacked-card-shufflers\/54865\/\" target=\"_blank\" rel=\"noopener nofollow\">automated card shufflers<\/a>, <a href=\"https:\/\/www.kaspersky.com\/blog\/how-to-hack-bicycles-shimano-di2-wireless-shifting-technology\/52026\/\" target=\"_blank\" rel=\"noopener nofollow\">bikes<\/a>, and even <a href=\"https:\/\/www.kaspersky.com\/blog\/how-to-hack-a-smart-mattress\/53232\/\" target=\"_blank\" rel=\"noopener nofollow\">mattresses<\/a>. In today\u2019s world, all of these (and many other) devices contain tiny (or not-so-tiny) computers.<\/p>\n<p>Airplanes are no exception. A modern airliner is packed with computers \u2014 some of which handle critical functions: from calculating takeoff parameters to controlling the flight itself. But there\u2019s one key difference: airliner manufacturers, unlike the makers of most smart home gadgets, take security very seriously, which makes it far harder to reach these systems from the outside.<\/p>\n<p>Maybe that\u2019s precisely why the idea of hacking a real plane has been tempting the most inquisitive security researchers for years. A team at the University of California San Diego and Oberlin College \u2014 the researchers who finally pulled it off \u2014 spent more than a decade wrestling with the problem. As mentioned above, the main challenge in hacking a plane is that its critical systems aren\u2019t connected to the external internet. Because of that, studying plane-related attack vectors wasn\u2019t seen as especially promising within the cybersecurity research community: reaching isolated systems remotely is extremely difficult, and the odds of an attacker gaining physical access were considered very low.<\/p>\n<p>Two other successful projects changed that assumption for UC San Diego researchers Kirill Levchenko and Aaron Schulman: a <a href=\"https:\/\/www.wired.com\/2015\/09\/gm-took-5-years-fix-full-takeover-hack-millions-onstar-cars\/\" target=\"_blank\" rel=\"noopener nofollow\">hack of the Chevrolet Impala<\/a>, and research into <a href=\"https:\/\/krebsonsecurity.com\/2019\/08\/meet-bluetana-the-scourge-of-pump-skimmers\/\" target=\"_blank\" rel=\"noopener nofollow\">payment card skimmers<\/a>. The car hack led their team to buy secondhand Boeing 737 computer components and build their own test rig. The skimmer research gave them the idea for a small physical device that could plug directly into the plane\u2019s internal systems.<\/p>\n<p>After studying the Boeing 737\u2019s circuit diagrams, the researchers found a port accessible from outside the plane \u2014 protected only by an unlocked hatch. That port connects to a data channel called the <a href=\"https:\/\/en.wikipedia.org\/wiki\/ARINC_429\" target=\"_blank\" rel=\"noopener nofollow\">ARINC 429<\/a> bus, which links the plane\u2019s <a href=\"https:\/\/skybrary.aero\/articles\/flight-management-computer-fmc\" target=\"_blank\" rel=\"noopener nofollow\">flight management computer (FMC)<\/a> to its <a href=\"https:\/\/skybrary.aero\/articles\/multifunction-control-and-display-unit-mcdu\" target=\"_blank\" rel=\"noopener nofollow\">multifunction control and display unit (MCDU)<\/a>.<\/p>\n<div id=\"attachment_56348\" style=\"width: 2198px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/102\/2026\/09\/05012311\/hacking-boeing-airplane-737-1.jpg\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-56348\" class=\"wp-image-56348 size-full\" title=\"How to reach the Boeing 737's port\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/102\/2026\/09\/05012311\/hacking-boeing-airplane-737-1.jpg\" alt=\"How to reach the Boeing 737's port\" width=\"2188\" height=\"956\"><\/a><p id=\"caption-attachment-56348\" class=\"wp-caption-text\">The port sits in the electronics bay beneath the cockpit. From outside the plane, it\u2019s covered only by an unlocked hatch. <a href=\"https:\/\/www.usenix.org\/system\/files\/usenixsecurity26-crow.pdf\" target=\"_blank\" rel=\"nofollow noopener\"> Source <\/a><\/p><\/div>\n<p><strong>[alt-title]<\/strong> How to reach the Boeing 737\u2019s port <strong>[\/alt-title]<\/strong><\/p>\n<p>\u00a0<\/p>\n The port sits in the electronics bay beneath the cockpit. From outside the plane, it\u2019s covered only by an unlocked hatch. &lt;a href=\u201dhttps:\/\/www.usenix.org\/system\/files\/usenixsecurity26-crow.pdf\u201d rel=\u201dnofollow noopener\u201d target=\u201d_blank\u201d&gt; Source &lt;\/a&gt; <strong><strong>\n<p><\/p><\/strong><\/strong>\n<p>\u00a0<\/p>\n<h2>\u00a0A \u201cbus driver\u201d at the controls<\/h2>\n<p>On their test rig, the researchers checked what would happen if they connected to the ARINC 429 bus through this port and sent electrical signals more powerful than the ones the Boeing\u2019s components normally exchange with one another. It turned out that doing so let them override legitimate commands with their own. From there, all that was left was building a device small enough to fit into the port they\u2019d found.<\/p>\n<p>Step by step, the team built a device compact enough to slot into the unprotected port. The finished version set them back less than US$100, and appears to have been built largely from off-the-shelf parts: a small microcontroller, electronics for communicating with the bus, and a Wi-Fi module. That last part could potentially help the device connect to the plane\u2019s public in-flight Wi-Fi network, giving the attacker access over the internet, and eventually letting them control the device remotely. And the whole thing takes less than a minute to install into the port.<\/p>\n<div id=\"attachment_56347\" style=\"width: 1610px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/102\/2026\/09\/05012316\/hacking-boeing-airplane-737-2.jpg\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-56347\" class=\"wp-image-56347 size-full\" title=\"A prototype of the Bus Driver device\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/102\/2026\/09\/05012316\/hacking-boeing-airplane-737-2.jpg\" alt=\"A prototype of the Bus Driver device\" width=\"1600\" height=\"1066\"><\/a><p id=\"caption-attachment-56347\" class=\"wp-caption-text\">The device the researchers built to connect to Boeing 737 systems. A coin sits next to it for scale. <a href=\"https:\/\/www.wired.com\/story\/this-coin-sized-device-can-hack-a-boeing-737\/\" target=\"_blank\" rel=\"nofollow noopener\"> Source <\/a><\/p><\/div>\n<p>The researchers dubbed their attack \u201cBus Driver\u201d, apparently a play on words: \u201cbus\u201d refers to both a passenger vehicle and the data channel that lets a system\u2019s components talk to each other. The attack lets someone step into that channel and swap out the commands being sent \u2014 effectively controlling the bus.<\/p>\n<h2>What the improvised Boeing 737 hacking device can actually do<\/h2>\n<p>An unprotected port, a coin-sized device, access to the bus: that\u2019s all and well and good, but what did the researchers actually manage to pull off? What kind of damage can this tiny implant do? As it turns out, quite a lot \u2014 potentially even fatal. By gaining the ability to tamper with the data flowing between the flight management computer and the control and display unit, the researchers found they could interfere with several critical aspects of how the plane operates.<\/p>\n<div id=\"attachment_56346\" style=\"width: 1610px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/102\/2026\/09\/05012320\/hacking-boeing-airplane-737-3.jpg\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-56346\" class=\"wp-image-56346 size-full\" title=\"Testing the Bus Driver attack\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/102\/2026\/09\/05012320\/hacking-boeing-airplane-737-3.jpg\" alt=\"Testing the Bus Driver attack\" width=\"1600\" height=\"1066\"><\/a><p id=\"caption-attachment-56346\" class=\"wp-caption-text\">Researchers testing Bus Driver on real Boeing 737 avionics hardware. Their attack interface is running on the MCDU screen. <a href=\"https:\/\/www.wired.com\/story\/this-coin-sized-device-can-hack-a-boeing-737\/\" target=\"_blank\" rel=\"nofollow noopener\"> Source <\/a><\/p><\/div>\n<p>First, the implant can alter the data used to calculate takeoff and landing parameters. For example, it can change the plane\u2019s recorded <a href=\"https:\/\/en.wikipedia.org\/wiki\/Zero-fuel_weight\" target=\"_blank\" rel=\"noopener nofollow\">zero-fuel weight<\/a>, which throws off the calculation of the speeds needed for a safe takeoff.<\/p>\n<p>The device can also manipulate the <a href=\"http:\/\/www.b737.org.uk\/assumedtemp.htm\" target=\"_blank\" rel=\"noopener nofollow\">assumed temperature value<\/a> pilots use to determine how much engine thrust is needed at takeoff. Feed the system the wrong numbers, and under certain conditions the plane could end up with insufficient thrust to take off safely \u2014 potentially even going off the end of the runway. Faulty calculations during landing carry similarly serious risks.<\/p>\n<p>The implant can also change the route the autopilot is following. On a long flight, a deviation of just a few degrees \u2014 subtle enough to go unnoticed \u2014 could be enough to send the plane badly off course so it runs out of fuel somewhere over open ocean.<\/p>\n<p>Beyond that, an attacker could use the device to steer the plane into the airspace of a country that isn\u2019t part of its approved flight path. That kind of deviation can also have deadly consequences: the history of civil aviation has seen <a href=\"https:\/\/en.wikipedia.org\/wiki\/Category:Airliner_shootdown_incidents\" target=\"_blank\" rel=\"noopener nofollow\">more than one case<\/a> of a passenger plane being mistakenly shot down by the military after straying into restricted airspace.<\/p>\n<p>Of course, the odds of a deviation like this slipping past both pilots and air traffic control are very low, but disasters tend to happen exactly when several human errors line up.<\/p>\n<div id=\"attachment_56345\" style=\"width: 456px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/102\/2026\/09\/05012323\/hacking-boeing-airplane-737-4.jpg\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-56345\" class=\"wp-image-56345 size-full\" title=\"The Boeing 737 implant installed\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/102\/2026\/09\/05012323\/hacking-boeing-airplane-737-4.jpg\" alt=\"The Boeing 737 implant installed\" width=\"446\" height=\"519\"><\/a><p id=\"caption-attachment-56345\" class=\"wp-caption-text\">Once installed, the implant is nearly invisible inside the port and very hard to spot unless you know to look for it. <a href=\"https:\/\/www.usenix.org\/system\/files\/usenixsecurity26-crow.pdf\" target=\"_blank\" rel=\"nofollow noopener\"> Source <\/a><\/p><\/div>\n<p>Finally, the device doesn\u2019t just let someone change flight parameters, it lets them hide those changes from the pilots. For instance, an attacker could load a new route into the flight computer while simultaneously altering what\u2019s shown on the MCDU display, so the pilots keep seeing the original route.<\/p>\n<p>That said, the researchers note that in most cases an attentive crew would catch the discrepancy. The correct data still shows up on other cockpit displays, and switching to manual control lets pilots disengage the autopilot and take back control of the plane.<\/p>\n<h2>So, should we all switch to trains?<\/h2>\n<p>To wrap up, I\u2019ll try to put the longtime aerophobes (and anyone this article has just turned into one) at ease. The researchers themselves say that despite everything they\u2019ve learned, they still fly on Boeing 737s. And to avoid causing any real-world trouble, they deliberately left out exactly which port they used in their experiments.<\/p>\n<p>The researchers also reached out to Boeing back in 2020 to share their findings. Boeing took the information seriously and worked on addressing the issue.<\/p>\n<p>Specifically, the researchers suggested Boeing either remove the vulnerable port or seal it with epoxy resin to physically rule out the possibility of someone plugging in an unauthorized device. There are more involved options too, like redesigning the internal bus\u2019s electrical protections so a rogue device can\u2019t override the real signals, and adding systems that can detect this kind of attack in the first place.<\/p>\n<p>Longer term, the researchers recommend that Boeing, along with other aircraft manufacturers, adopt cryptographic authentication for the messages passed between avionics components.<\/p>\n<p>Whether Boeing acted on this specific advice or came up with its own fixes isn\u2019t publicly known. When Wired reporters asked the company about it, the response was <a href=\"https:\/\/www.wired.com\/story\/this-coin-sized-device-can-hack-a-boeing-737\/\" target=\"_blank\" rel=\"noopener nofollow\">fairly vague<\/a>:<\/p>\n<p>\u201cOur technical experts are confident that the layers of protection in place on the airplane, including within the system design and the operating environment, provide sufficient mitigation to significantly limit the feasibility and risk of real-world attacks.\u201d<\/p>\n<p>So no, there\u2019s apparently no need to swear off Boeing 737 flights just yet. That said, I happen to have a lot of respect for trains, so I won\u2019t try to talk you out of traveling by rail or using other ways of getting around either. I\u2019ve actually written about <a href=\"https:\/\/www.kaspersky.com\/blog\/train-hack-37c3-talk\/50321\/\" target=\"_blank\" rel=\"noopener nofollow\">train hacking<\/a> on this blog before, though in that case the goal was constructive, not destructive.<\/p>\n<blockquote><p><a href=\"https:\/\/www.kaspersky.com\/blog\/car-botnet-malware-for-head-units-with-android\/56296\/\" target=\"_blank\" rel=\"noopener nofollow\">Cars<\/a>, <a href=\"https:\/\/www.kaspersky.com\/blog\/yarbo-robot-lawn-mower-hacked-2\/56067\/\" target=\"_blank\" rel=\"noopener nofollow\">lawnmowers<\/a>, <a href=\"https:\/\/www.kaspersky.com\/blog\/hacked-card-shufflers\/54865\/\" target=\"_blank\" rel=\"noopener nofollow\">card shufflers<\/a>, <a href=\"https:\/\/www.kaspersky.com\/blog\/how-to-hack-bicycles-shimano-di2-wireless-shifting-technology\/52026\/\" target=\"_blank\" rel=\"noopener nofollow\">bikes<\/a>, <a href=\"https:\/\/www.kaspersky.com\/blog\/how-to-hack-a-smart-mattress\/53232\/\" target=\"_blank\" rel=\"noopener nofollow\">smart mattresses<\/a> \u2014 it\u2019s not even an exhaustive list of the devices that hackers have successfully tampered with. What else was hacked? Find out in our other posts:<\/p>\n<ul>\n<li><a href=\"https:\/\/www.kaspersky.com\/blog\/dashcam-hack-botnet-on-the-wheels\/54839\/\" target=\"_blank\" rel=\"noopener nofollow\"><strong>Botnets on wheels: the mass hacking of dashcams<\/strong><\/a><\/li>\n<li><a href=\"https:\/\/www.kaspersky.com\/blog\/perfektblue-bluetooth-car-hack\/54159\/\" target=\"_blank\" rel=\"noopener nofollow\"><strong>Car hacking via Bluetooth<\/strong><\/a><\/li>\n<li><a href=\"https:\/\/www.kaspersky.com\/blog\/top-5-hacks-for-fun\/53740\/\" target=\"_blank\" rel=\"noopener nofollow\"><strong>Five hacks that were (mostly) just for laughs<\/strong><\/a><\/li>\n<li><a href=\"https:\/\/www.kaspersky.com\/blog\/robot-toy-security-issue\/50630\/\" target=\"_blank\" rel=\"noopener nofollow\"><strong>Vulnerabilities in a toy robot permitting snooping. Seriously<\/strong><\/a><\/li>\n<li><a href=\"https:\/\/www.kaspersky.com\/blog\/ecovacs-robot-vacuums-hacked-in-real-life\/52837\/\" target=\"_blank\" rel=\"noopener nofollow\"><strong>Ecovacs robot vacuums get hacked<\/strong><\/a><\/li>\n<\/ul>\n<\/blockquote>\n<input type=\"hidden\" class=\"category_for_banner\" value=\"premium-geek\">\n","protected":false},"excerpt":{"rendered":"<p>Researchers have built a device that can interfere with critical systems aboard a Boeing 737. Here&#8217;s how the attack works, and whether it&#8217;s time you started worrying about flying yet.<\/p>\n","protected":false},"author":2726,"featured_media":36771,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[2646],"tags":[1048,1027,527,658,1021,97,422,268,174],"class_list":["post-36765","post","type-post","status-publish","format-standard","has-post-thumbnail","category-threats","tag-aviation","tag-connected-devices","tag-hacks","tag-internet-of-things","tag-planes","tag-security-2","tag-threats","tag-vulnerabilities","tag-wi-fi"],"hreflang":[{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/hacking-boeing-737-airplane\/36765\/"},{"hreflang":"en-in","url":"https:\/\/www.kaspersky.co.in\/blog\/hacking-boeing-737-airplane\/31027\/"},{"hreflang":"en-ae","url":"https:\/\/me-en.kaspersky.com\/blog\/hacking-boeing-737-airplane\/26051\/"},{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/hacking-boeing-737-airplane\/30857\/"},{"hreflang":"ru","url":"https:\/\/www.kaspersky.ru\/blog\/hacking-boeing-737-airplane\/42610\/"},{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/hacking-boeing-737-airplane\/56341\/"},{"hreflang":"ru-kz","url":"https:\/\/blog.kaspersky.kz\/hacking-boeing-737-airplane\/30999\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/hacking-boeing-737-airplane\/36432\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.com.au\/blog\/tag\/planes\/","name":"planes"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/posts\/36765","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/users\/2726"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/comments?post=36765"}],"version-history":[{"count":2,"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/posts\/36765\/revisions"}],"predecessor-version":[{"id":36772,"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/posts\/36765\/revisions\/36772"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/media\/36771"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/media?parent=36765"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/categories?post=36765"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.com.au\/blog\/wp-json\/wp\/v2\/tags?post=36765"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}