The Airforwarders Association (AfA) has urged the US Federal Aviation Administration (FAA) to strengthen the resilience of aviation communications systems following widespread disruption across the US Northeast on 21 September.
The association’s call came after the US Government Accountability Office (GAO) published a new aviation cybersecurity report identifying gaps in the FAA’s risk assessments, threat monitoring and protection of critical aircraft communications systems.
According to the AfA, the Monday disruption delayed or cancelled approximately 7,000 flights and affected freight networks, highlighting the potential consequences of failures involving critical aviation infrastructure.
GAO Identifies Aviation Communications Gaps
The GAO report, published on 21 September, found that the FAA has identified electromagnetic spectrum-related threats to the National Airspace System, including interference, spoofing and jamming.
However, the watchdog said the FAA had not completed system-specific risk and mitigation assessments for the identified threats and did not have a defined real-time monitoring and detection capability covering all spectrum-related threats.
GAO also identified vulnerabilities in aircraft communication applications including ACARS and CPDLC, citing weaknesses related to authentication, encryption and protocol design.
The report warned that exploitation of such vulnerabilities could disrupt communications, degrade situational awareness and contribute to flight delays and other operational disruptions.
The GAO has issued nine recommendations to the FAA covering risk assessment, continuous monitoring, interagency coordination, information sharing, stakeholder participation, authentication and data protection.
The US Department of Transportation, responding on behalf of the FAA, concurred with all nine recommendations.
Equipment Disruptions Hit Northeast Airports
FAA air traffic control records show that equipment-related disruptions affected operations in the Northeast on 21 September.
An FAA advisory for Newark Liberty International Airport recorded a ground stop from 19:53 to 21:45 UTC, with the agency citing an equipment outage. A separate FAA advisory recorded a ground stop at John F. Kennedy International Airport from 21:01 to 22:30 UTC, also identifying equipment/outage as the impacting condition.
The disruptions affected major aviation gateways serving the New York and Philadelphia markets, with consequences extending beyond passenger operations to air freight and express logistics.
The AfA stressed that the September incident was not reported as a cyberattack, but argued that it demonstrated how failures affecting critical communications infrastructure can quickly propagate through the aviation system.
Cargo Networks Exposed to Operational Disruption
The incident is particularly relevant to the freight sector because the affected airports form an important part of the US Northeast’s cargo network.
John F. Kennedy International Airport handled approximately 1.6 million tonnes of cargo in 2025, according to the Port Authority of New York and New Jersey. Newark also operates a major cargo complex with nearly one million square feet of cargo space and a concentration of express operators including FedEx, UPS and DHL.
Philadelphia International Airport handled more than 482,000 tonnes of freight and airmail in 2025, representing a 7.4% increase from the previous year.
For freight forwarders, disruption at major gateways can affect aircraft schedules, cargo acceptance, trucking connections, warehouse operations and downstream delivery commitments even when the underlying problem originates within the aviation communications or air traffic management environment.
AfA Calls for Faster Action
Brandon Fried, Executive Director of the Airforwarders Association, said the GAO findings demonstrated the need for the FAA to address identified weaknesses before they could be exploited.
“The FAA has identified serious threats to critical aviation systems, but this report makes clear that it has not completed the basic risk assessments or built the monitoring needed to address them,” Fried said.
He said the consequences of failures could extend across airports, airlines, freight networks and the wider economy.
The association is calling for implementation of the GAO recommendations, including stronger risk management, continuous threat monitoring and improved protection of aviation communications.
Resilience Becomes a Cargo Priority
The GAO findings extend beyond cybersecurity in the narrow sense. They highlight the growing importance of resilience across the interconnected systems that support modern aviation and air cargo.
GAO noted that the National Airspace System depends on communications links and applications that support the exchange of operational information between aircraft, air traffic controllers and other stakeholders. Disruption to those systems can have consequences well beyond the original point of failure.
For freight forwarders and logistics providers, the issue is particularly significant because time-critical cargo depends on predictable flight schedules and tightly coordinated ground operations.
The AfA said the FAA now has a defined set of recommendations to address the identified gaps. Fried called for the agency to move forward with implementation and strengthen ageing infrastructure rather than waiting for a malicious actor to expose existing weaknesses.
The episode has therefore placed aviation communications resilience back on the agenda for both passenger and cargo stakeholders, with the freight industry watching how quickly the FAA responds to the GAO’s recommendations.










