It seems that you can’t open your computer or personal device without finding scam emails in your inbox about an urgent matter needing “immediate attention,” to verify an account, password, setting or whatever.
And while the bait may not hook you, sooner or later, someone will bite. And that’s why cyber-phishing is becoming the weapon of choice for cybercriminals the world over.
“Statistically, the cyber-phishing threat is growing about 600% year-over-year in your general life,” said Josh Wheeler, NBAA Security Council member and senior director, cybersecurity and entry-into-service for Gogo. “In business aviation, I’d say that it’s doubling each year, so it’s definitely a threat that flight operations need to be aware of.
“Business aircraft make attractive targets today because there is so much more data traveling on and off the aircraft than ever before,” Wheeler said. “Real-time teleconferences, schedules, social media interactions… where you are and what you’re doing… it’s all there, if someone wants to get it.”
“Statistically, the cyber-phishing threat is growing about 600% year-over-year... But, in business aviation, I’d say that it’s doubling each year. ”
JOSH WHEELER Gogo Senior Director, Cybersecurity and Entry-Into-Service / NBAA Security Council Member
Joshua Crumbaugh, founder and CEO of PhishFirewall, has spent his career as an “ethical hacker,” learning the tricks and teaching government agencies and companies how to spot and avoid even the most polished phishing schemes.
“AI-enabled phishing schemes have gotten a lot smarter. It understands context and people’s roles in their organizations, and where I’m concerned about business aviation is that we have a lot of VIPs, and knowing who is in the air at what time means I know who can’t verify things,” he said. “Hackers can use that data to digitally impersonate that person and demand things on their behalf. I think that’s where a big threat can come from.”
“AI-enabled phishing schemes have gotten a lot smarter... Hackers can use that data to digitally impersonate that person and demand things on their behalf. ”
JOSHUA CRUMBAUGH ‘Ethical Hacker’ / Founder, CEO of PhishFirewall
An example he shared was where the hacker knew “Barry” was on the company airplane and couldn’t be reached to confirm an instruction, which gave the hacker a window of time with absolute digital authority. They then posed as the CEO and contacted a company executive, instructing them to wire funds to close a pending deal “immediately.”
Lest you think that a scam like that is far-fetched, the hacker did pull it off, to the tune of $25 million.
Beware of AI-Faked CEO Impersonations
Spotting a fake email is getting harder. “Pixel-perfect” reproductions of texts and emails that you routinely receive, and probably act on automatically, are the most common phishing tactics in play today.
Unfortunately, armed with AI, cybercriminals are upping their game with deep-fake voice impersonations. “I only need a few minutes of audio to create a deep fake of your voice, and you can’t tell it apart from the real thing,” Crumbaugh explained. “I don’t know a C-level executive who is not public-facing today, and everything is on the web somewhere. That makes it easy for hackers to get the voice sample they need.
“I don’t know a C-level executive who is not public-facing today, and everything is on the web somewhere. That makes it easy for hackers to get the voice sample they need.”
JOSHUA CRUMBAUGH ‘Ethical Hacker’ / Founder, CEO of PhishFirewall
“We work with a major global company, and their call centers get these deep-fake calls on a nearly daily basis,” Crumbaugh added. “It’s becoming a regular thing, and what makes it worse is that the entire thing can be AI-automated with no human interaction.”
And if that weren’t scary enough, higher-end cybercriminals are now adding AI-created videos of people – and even pets – being held “hostage.” They send a video of the loved one, with the loved one’s voice pleading for help. In a moment of stress, few people can spot the difference between the real thing and an AI simulation. And that’s just what the cyber-scammers are counting on.
‘Fast Brain’ vs. ‘Slow Brain’
“If you don’t recognize the email or text you received, just slow down and think. If it still doesn’t seem right, just delete it,” Wheeler said. “If it’s a credible problem with your bank or other established account, then the party will reach out to you again. Real businesses don’t just delete accounts with no reason.”
“Hackers are trying to use emotion, urgency, authority or fear to get to you.”
JOSH WHEELER Gogo Senior Director, Cybersecurity and Entry-Into-Service / NBAA Security Council Member
“I’ve never been involved with an incident where someone involved didn’t say that they ‘knew’ something was off,” said Crumbaugh. “Hackers are trying to use emotion, urgency, authority or fear to get to you. We have a fast brain and a slow brain. Use your slow brain to evaluate the situation and understand it before you act.”
Review NBAA aviation cybersecurity resources at nbaa.org/cybersecurity.
Actionable Steps to Bolster Aircraft Cybersecurity
Safeguarding aircraft connectivity systems from relentless and clever pirates trying to steal sensitive and potentially valuable data is easier said than done. Especially when you consider that the weakest link in your cybersecurity chain may be executives or passengers accidentally sharing information that could be used in nefarious ways.
“Cybersecurity (or the lack thereof) is not a technology problem, it’s a human problem,” said PhishFirewall founder and CEO Joshua Crumbaugh. “I’ve seen a lot of cybercrimes, and I cannot find a single issue that can’t be traced back to a human’s error. If we can stop the mistakes, we can greatly reduce the threat.
“A lot of executives are tempted to exempt themselves from the various security steps like passwords or multi-factor authentication protocols because they have administrative assistants to ‘take care of that,’ and besides, it’s too much work,” Crumbaugh said. “It’s not that they don’t care; it’s just that cybersecurity is something they don’t think about. They expect the IT people to take care of it.”
“We make hackers’ jobs easy,” said Josh Wheeler, NBAA Security Council member and senior director, cybersecurity and entry-into-service for Gogo. “All too often, the targeted individuals go on social media or LinkedIn and post where they are going. With that, hackers can easily find their aircraft. Between social media, AI and ChatGPT, hackers can easily find almost anyone.
“Then, once the hacker knows the aircraft’s destination, they can go to the FBO, get its Wi-Fi password, and just wait for the aircraft to arrive,” Wheeler said. “Since most aircraft leave their Wi-Fi on, and many don’t bother with passwords, they could easily hack their way into the network.
“They’re not trying to take down aircraft – that can’t happen – but what they do want is access to passenger data such as: what are they doing and where are they going, proprietary information, intellectual property and trade secrets,” said Wheeler. “That’s where the money is.”
It’s Simpler Than You Might Think
Step one in beefing up business aviation cybersecurity is making sure company leaders and system users know and execute best practices.
“In business aviation, we live and die by the chain of command and checklists,” Crumbaugh said. “But these two pillars actually become vulnerabilities if they aren’t handled correctly, so, if you want to get your CEO or aircraft owner to take the need for increased cybersecurity seriously, it all comes down to speaking the language of risk – not the language of technologies and procedures. For example, if you say they need a password on the aircraft’s network to protect their identity from being hijacked, they usually listen.”
A good place to begin is having your aircraft connectivity provider introduce the cybersecurity issue to the C-suite to ease the transition. Consider starting with the company IT team and then share their findings with senior executives.
“At Gogo, one of our trademark services is to offer a variety of educational courses on networking and cybersecurity geared towards business aviation needs,” said Wheeler. “We find these courses are important for customers who clearly don’t realize the risks. And, like recurrent flight training, each member of the flight operation needs continual refresher training.”
Consider implementing these Wi-Fi best practices for the flight crew:
- Turn off the aircraft’s Wi-Fi immediately after landing.
- Change passwords frequently.
- Ensure network caching systems have the latest security updates.
- Don’t sit on the ramp and surf the web.
- Don’t piggyback on the FBO’s free Wi-Fi.
Also, ask your connectivity provider what steps they’re taking to protect your data when it’s transmitted off the aircraft and onto their network. Ask how it is backed up and where. Find out if they have additional security protocols you can implement.
“You can’t force the CEO or aircraft’s owner to change their online practices, but the flight operation can develop and implement its own best practices for crew and maintenance devices,” Wheeler said. “Then if there’s ever a breach of the network, you can say you did all you could to keep the data. If you apply your best efforts, then you’ve done all you can do.”

International Business Aviation Council Ltd.