Aviation experts are raising alarms about national security risks as the Federal Aviation Administration (FAA) considers foreign companies with extensive ties to China to build a new air-traffic control system, warning that the U.S. could be vulnerable to cyberattacks if such vendors are allowed to design or operate American ATC infrastructure.
The FAA announced last November that it was seeking proposals for a “single, state-of-the-art platform” known as the common automation platform (CAP), part of Transportation Secretary Sean Duffy’s plan to overhaul the nation’s ATC system. According to industry outlet Air Current, the short list includes U.S.-based Leidos and RTX, Spain’s Indra, and France’s Thales, all of which were reportedly asked to pitch their versions to agency officials in Washington, D.C.
Both Indra and Thales have deep, decades-long involvement in China’s aerospace industry. Indra has been operating in China since 1989, running a wholly foreign-owned subsidiary in Beijing that coordinates air traffic for eight Chinese provinces—an area roughly the size of Western Europe. The company has deployed more than 1,000 navigational aid systems, equipped over 15 ATC towers, and placed 50 radars, covering 60 percent of Chinese airspace and 80 percent of aircraft movements. Thales, which has been in China since 1964, manages 60 percent of the country’s air traffic and operates under an “In China, For China” strategy, co-developing technology with Chinese partners.
The concern is not hypothetical. Between 2020 and 2025, nearly 2,300 cybersecurity incidents in the aviation subsector were reported to the Cybersecurity and Infrastructure Security Agency (CISA), which in 2024 flagged the threat from “malicious cyber actors” acting on China’s behalf. A Department of Transportation inspector general report from April found that the FAA had left many of its high-impact systems “vulnerable to cyberattacks that could cause severe or catastrophic effects on the National Airspace System.”

The Government Accountability Office (GAO) echoed those findings in a July 2026 report, recommending the FAA update its Zero Trust Architecture (ZTA) implementation plan to align with best practices. As cybersecurity firm Palo Alto explains, ZTA’s foundational principle is “never trust, always verify,” treating every user and device as untrusted by default—a departure from traditional security models that assume the network perimeter is safe. Without such measures, the GAO argued, the FAA “cannot ensure that it is effectively managing cybersecurity risks, including during NAS modernization.”
The House Appropriations Committee’s THUD panel has stepped in, mandating that the FAA consult with federal agencies to vet risks posed by third parties involved in the CAP project—specifically calling out those with “legal or business relationships with the People’s Republic of China (PRC)” or entities controlled by the PRC government. The panel also requires the FAA to report to Congress on any such relationships, detailing the risks to personnel, equipment, and operations, plus mitigation measures.
Not everyone sees the risk the same way. Thales USA vice president Tony Lo Brutto dismissed concerns about the company’s China ties as a “boogeyman” in a July statement to Bloomberg Government, though he acknowledged the tension when asked how Thales might handle a hypothetical Chinese request for a similar CAP system. “I’m not sure they would get a positive answer to that, given who our customer is,” he told Air Current. Both Indra and Thales previously told Air Current they reject the notion that their systems pose a national security risk, but neither responded to Breitbart News requests for comment.
The stakes are high. The U.S. air-traffic system handles tens of thousands of flights daily, and a successful cyberattack could cripple aviation infrastructure nationwide. Critics argue that allowing vendors with deep ties to China to build the new CAP would hand Beijing a potential lever over American airspace. Supporters, including Leidos, which backs an amendment requiring the FAA to study foreign business ties, say such scrutiny is necessary—while Thales and Indra maintain their operations in China are transparent and their technology is secure.
As the FAA moves forward with its CAP selection, the debate highlights a broader tension between modernization and security. The EU, for context, barred non-EU companies from providing ATC services in member states back in 2024, a step the U.S. has yet to take. With Congress now requiring detailed reporting on any China-related contracts, the FAA faces pressure to balance innovation with vigilance—and the outcome could shape the safety of American skies for decades.
Source: www.breitbart.com — https://www.breitbart.com/asia/2026/09/01/aviation-experts-sound-national-security-alarm-as-faa-considers-air-traffic-control-vendors-with-strong-china-ties/
