An El Al 777 Descended Toward the Wrong Place. Could Cyber Interference Explain It?
Six hundred feet. One mile off course. No runway underneath.
On September 7, an El Al Boeing 777 carrying passengers from Paris toward Tel Aviv descended toward Ben Gurion Airport.
Everything should have ended with an ordinary landing on Runway 30.
Instead, the Boeing 777-200 became aligned on a trajectory approximately one nautical mile north of the runway’s actual approach path.
And it kept descending.
1,000 feet.
800 feet.
Eventually, approximately 600 feet above the ground.
There was just one enormous problem.
The runway wasn’t there.
The pilots abandoned the approach, climbed away, repositioned and approximately 20 minutes later landed safely on the actual Runway 30.
Nobody was injured.
The aircraft wasn’t damaged.
And the most important thing the crew did was exactly what aviation safety systems are designed around:
When the approach didn’t look right, they stopped the landing.
But there’s an unanswered question.
How does a modern Boeing 777 approaching one of the most security-conscious airports in the world end up descending approximately a mile away from its intended final approach path?
And given the cyberattacks, GPS interference and electronic warfare increasingly surrounding modern transportation, there’s another question worth examining:
Could someone have hacked or electronically deceived the airplane?
The answer is fascinating.
It’s technically worth investigating.
But based on everything publicly known today, there is no evidence that’s what happened.
First: This Was a Visual Approach
This detail matters enormously.
Available reporting identifies LY324 as conducting a visual approach to Runway 30.
That changes how we should think about the incident.
A visual approach isn’t simply the aircraft blindly following an electronic beam all the way onto the runway.
The pilots ultimately have responsibility for visually identifying and maintaining the appropriate path to the airport/runway.
That makes several decidedly non-cyber explanations immediately plausible:
Visual misidentification.
Incorrect situational awareness.
An erroneous turn onto final.
Confusion with lights, roads or another geographic feature.
Automation-mode misunderstanding.
Incorrectly interpreted navigation information.
Crew coordination issues.
Or some combination of several small errors.
Aviation accidents rarely require one spectacular failure.
Sometimes five ordinary things go slightly wrong at exactly the wrong time.
But Israel Has a GPS Problem
This is where the cybersecurity angle becomes legitimate.
Israel has experienced substantial GNSS interference during periods of conflict.
GPS signals arriving from satellites are incredibly weak by the time they reach Earth.
That makes satellite navigation susceptible to two particularly interesting forms of interference.
Jamming prevents a receiver from reliably hearing the satellite signal.
Spoofing is considerably more sinister.
Instead of simply making GPS disappear, an attacker transmits counterfeit navigation signals designed to make the receiver calculate an incorrect position.
Your navigation system doesn’t necessarily say:
GPS unavailable.
It can potentially say:
You’re here.
When you’re actually somewhere else.
That’s an entirely different security problem.
Imagine Waze Lying About Where You Are
Suppose you’re driving toward an exit.
Waze shows your car exactly where you expect it.
Turn right in 500 feet.
You turn.
Everything on the screen looks perfectly normal.
Except your actual car is one mile away from the location shown on the map.
That’s approximately the conceptual danger of successful GNSS spoofing.
Now replace the Honda with a Boeing 777.
That’s why investigators should absolutely examine the aircraft’s navigation data.
But there’s an extremely important distinction:
GPS spoofing is not the same thing as hacking the Boeing 777.
Nobody necessarily penetrates the airplane’s computers.
Nobody needs malware inside the flight-control system.
Nobody needs to remotely “take over” the aircraft.
Instead, the navigation system receives bad external information.
That’s closer to convincing someone’s security camera that it’s noon when it’s actually midnight than remotely controlling the camera.
Could Someone Hack the Flight Controls?
Theoretically, cyber compromise of aviation systems is an important security concern.
But jumping from this incident to:
“Hackers took control of an El Al 777”
would be unsupported.
Modern commercial aircraft don’t operate like a Tesla where someone on the internet simply obtains the right IP address and starts steering.
A Boeing 777 has multiple independent systems, redundant navigation sources and human pilots sitting in the cockpit.
An attacker causing a specific lateral deviation through compromise of actual flight-control or flight-management systems would represent an extraordinary aviation cybersecurity event.
And if that occurred, investigators would expect potentially valuable evidence inside the aircraft’s recorded data.
There is currently no public evidence of that.
There’s a More Interesting Cyber Possibility
Don’t hack the airplane.
Lie to it.
That’s a much more realistic framework for thinking about transportation cybersecurity.
Attackers don’t necessarily have to control a system if they can manipulate the information upon which that system makes decisions.
We’ve seen versions of this everywhere.
Phishing doesn’t hack your brain.
It gives your brain fraudulent information.
DNS poisoning doesn’t necessarily compromise your browser.
It tells the browser the wrong destination.
GPS spoofing doesn’t necessarily compromise the navigation computer.
It gives navigation equipment false positioning information.
Sometimes attacking the sensor is easier than attacking the machine.
For aviation, that’s an important distinction.
But GPS Alone Shouldn’t Be Enough
Commercial aircraft don’t navigate using one lonely GPS receiver.
The Boeing 777 has layers of navigation and instrumentation.
And on an approach, pilots have multiple opportunities to cross-check what the airplane believes against:
Airport/runway geometry.
Navigation displays.
Heading.
Altitude.
ATC instructions.
Visual references.
Published procedures.
Other navigation sources.
And eventually their own eyes.
That’s exactly why redundancy exists.
If one source says:
You’re here
while several independent sources say:
No, you’re not,
the discrepancy itself becomes a warning.
It’s the aviation equivalent of Zero Trust.
Never trust one source when the consequence of being wrong is catastrophic.
There Are Several More Ordinary Possibilities
Before invoking hackers, investigators will likely need to reconstruct something much more mundane:
What did the pilots think they were looking at?
Wrong-surface approaches have happened before.
Pilots have mistaken taxiways for runways.
They’ve lined up with parallel surfaces.
They’ve misidentified airports.
They’ve continued approaches despite subtle indications that the geometry wasn’t right.
That’s one reason stabilized-approach criteria and go-arounds exist.
LY324’s crew ultimately recognized that the approach wasn’t working and went around.
That’s the safety system succeeding after something earlier went wrong.
Another possibility is automation or flight-management-system interaction.
Not hacking.
Just humans and automation disagreeing about what the airplane is doing.
A mode can be selected incorrectly.
A waypoint can be misunderstood.
A heading can be entered incorrectly.
A visual approach can be flown differently than anticipated.
One crew member can believe the other has identified the runway.
ATC and the cockpit can have different mental pictures.
None of those possibilities should be assigned as the cause without the investigation.
But historically, they’re much less exotic than someone remotely hacking a Boeing 777.
And There’s Another Possibility: The Environment
Nighttime lighting can be deceptive.
So can haze.
So can terrain.
So can highways and industrial lighting.
Runways are designed to be recognizable, but human perception isn’t perfect.
The interesting question investigators can answer isn’t merely:
Why were they one mile north?
It’s:
What were the pilots following?
That distinction could reveal almost everything.
If the pilots believed they visually saw Runway 30 somewhere it wasn’t, that’s one investigative path.
If their navigation display showed them somewhere they weren’t, that’s another.
If the aircraft’s recorded position was accurate but the aircraft flew the wrong heading, that’s another.
If onboard systems and ground radar disagreed about the airplane’s location, suddenly electronic interference becomes considerably more interesting.
The Black Boxes Can Tell an Extraordinary Story
This is why aviation investigations can be so forensic.
Investigators can potentially reconstruct what was happening through recorded aircraft and operational data.
They can compare the airplane’s actual trajectory against what its systems were reporting.
They can examine cockpit actions and communications.
They can look at navigation-source behavior.
They can examine autopilot and flight-director modes.
They can compare GPS-derived information against other navigation sources.
They can determine when the pilots recognized the discrepancy.
And they can compare LY324 against other aircraft operating around Ben Gurion at the same time.
That last one could be particularly revealing.
If several airplanes simultaneously experienced abnormal satellite-navigation positioning, that would point investigators toward a broader environmental interference event.
If only this aircraft experienced unusual navigation behavior, the investigation becomes different.
If the navigation systems behaved normally throughout, the cyber hypothesis becomes much weaker.
Cybersecurity Investigators Should Ask One Crucial Question
What did the airplane believe?
That’s the question.
Not:
“Was it hacked?”
Ask:
What position did each independent navigation source report as the airplane descended through 1,000 feet?
If the airplane accurately knew it was north of the runway, this probably isn’t a navigation-spoofing story.
If one navigation source incorrectly placed it on the runway centerline while independent sources disagreed, that’s interesting.
If multiple systems received correlated false information, that’s much more interesting.
If the aircraft’s internal systems reported a correct position but the crew nevertheless aligned with the wrong surface, you’re looking elsewhere.
Cybersecurity is about evidence.
Not finding a strange event and inserting “hackers” into the unexplained portion.
And Ben Gurion Makes the Question More Interesting
This wasn’t an aircraft approaching some isolated rural airport.
It was approaching Ben Gurion International Airport in Israel.
That matters because the region operates in an unusually intense electronic-warfare environment.
Navigation interference in and around conflict zones has become an important aviation issue.
That doesn’t make spoofing the explanation.
But it absolutely makes GNSS integrity something investigators should examine.
And there’s a broader cybersecurity lesson hiding inside this incident.
We Keep Connecting the Digital World to the Physical One
Cars depend on software.
Ships depend on software.
Factories depend on software.
Hospitals depend on software.
Power grids depend on software.
Aircraft depend on software and electronic navigation.
Cybersecurity used to primarily protect information.
Increasingly, it protects reality as machines perceive it.
Where am I?
How fast am I moving?
Which direction am I facing?
Is this valve open?
Is this temperature real?
Is this person authorized?
Is this actually the runway?
If an attacker can corrupt the data answering those questions, they may not need direct control over the machine.
Make the machine believe the wrong reality, and it may make the wrong decision itself.
That’s Why This Incident Is Worth Watching
Right now, there is no evidence that hackers commandeered LY324.
There is no public evidence that malware infected its flight-control systems.
There is no evidence that someone remotely steered the Boeing 777 toward the wrong location.
And there isn’t currently public evidence establishing GPS spoofing as the cause either.
What we know is considerably narrower.
A Boeing 777 on a visual approach to Runway 30 became aligned approximately one nautical mile north of the correct approach track.
It descended to roughly 600 feet.
The crew recognized the problem.
They went around.
And twenty minutes later, they landed safely.
Now investigators need to determine why.
Human error?
Visual illusion?
Automation confusion?
Navigation anomaly?
ATC factors?
GNSS interference?
Equipment malfunction?
Or some combination?
Until investigators release evidence, those remain hypotheses—not conclusions.
But in 2026, asking whether a strange aviation incident had a cyber or electronic-warfare component is no longer science fiction.
It’s part of understanding the threat environment.
And the most interesting possibility may not be someone hacking the airplane at all.
It may be someone convincing the airplane that it was somewhere else.
70% of all cyber attacks target small businesses, I can help protect yours.
#Cybersecurity #AviationSecurity #GPS #CyberAttack #DataProtection
An El Al 777 descended to just 600 feet toward a place where there was NO runway. The pilots went around and landed safely—but investigators now have a fascinating question to answer. Was it human error, automation, GPS interference… or could someone have made the airplane believe it was somewhere it wasn’t?