Security researcher's hack caused airplane to climb, FBI asserts

The FBI said Chris Roberts hacked in-flight entertainment systems 15 to 20 times over three years

A United Boeing 737

A United Boeing 737

The FBI contends a cybersecurity researcher said he caused an airplane's engine to climb after hacking its software, according to a court document.

The researcher, Chris Roberts, was questioned by the FBI on April 15 after he wrote a tweet that suggested he was probing aircraft systems on a United Airlines flight he took earlier that day.

The FBI interviewed him after he flew into Syracuse, New York, and seized his electronics. Two days later, the agency then filed an application for a search warrant to examine Roberts' gear, which has been published in federal court records.

The application contains rich detail describing three of the agency's interviews with Roberts, who is co-founder and CTO of the security company One World Labs in Colorado. He has not been charged with a crime, although United Airlines banned him from flying on its planes.

It is not clear when the incident involving the airplane's engine occurred or if the plane might have been in danger as the result of it.

On Sunday, Roberts wrote on Twitter that "Over last five years my only interest has been to improve aircraft security...given the current situation I've been advised against saying much." Roberts is being represented by Nate Cardozo, a staff attorney with the Electronic Frontier Foundation. Cardozo said Roberts was not available to comment beyond what he wrote on Twitter.

One of Roberts' specialties is investigating security flaws in aircraft systems, which the U.S. government has warned could endanger flight safety if not configured correctly.

Regarding the engine incident, Special Agent Mark S. Hurley wrote in the warrant application that Roberts said he connected his laptop to the in-flight entertainment (IFE) system through the Seat Electronic Box (SEB), which is located under some passenger seats.

After hacking the IFE system, he gained access to other systems on the plane, Hurley wrote.

Roberts "stated that he then overwrote code on the airplane's Thrust Management Computer while aboard a flight," Hurley wrote. "He stated that he successfully commanded the system he had accessed to issue the 'CLB' or climb command."

One of the airplane's engines began to climb, "resulting in a lateral or sideways movement of the plane during one of these flights," the warrant application said.

Hurley wrote that Roberts said he had compromised IFE systems 15 to 20 times from 2011 through 2014.

Roberts allegedly said he compromised IFE systems made by Thales and Panasonic with video monitors installed at the back of passenger seats, Hurley wrote.

Roberts' problems started on April 15 when he wrote a tweet that suggested he was probing aircraft systems on a United Airlines flight from Denver to Chicago on a 737/800.

He continued flying that day from Chicago to Syracuse, New York. While en route, United Airlines' Cyber Security Intelligence Department had seen his tweet, which referred to the EICAS system, or Engine Indication and Crew Alerting System.

Read more: ‘The user is today’s new corporate security perimeter’

According to the warrant application, an FBI special agent later examined the first-class cabin where Roberts flew on his way to Chicago. The SEBs under seats 2A and 3A showed signs of tampering.

"The SEB under 2A was damaged," the document said. "The outer cover of the box was open approximately 1/2 inch, and one of the retaining screws was not seated and was exposed."

Roberts told agents that he did not compromise the airplane's network on the flight to Chicago, the warrant application said.

In February and March, the FBI had interviewed Roberts in which he allegedly also told agents he had hacked IFE systems on aircraft before.

Hurley wrote they seized his equipment in Syracuse because "it would endanger public safety to allow him to leave the Syracuse airport that evening with that equipment."

Send news tips and comments to jeremy_kirk@idg.com. Follow me on Twitter: @jeremy_kirk

Join the Good Gear Guide newsletter!

Error: Please check your email address.

Tags United AirlinesOne World LabssecurityExploits / vulnerabilities

Our Back to Business guide highlights the best products for you to boost your productivity at home, on the road, at the office, or in the classroom.

Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Jeremy Kirk

IDG News Service
Show Comments

Essentials

Microsoft L5V-00027 Sculpt Ergonomic Keyboard Desktop

Learn more >

Lexar® JumpDrive® S57 USB 3.0 flash drive

Learn more >

Mobile

Lexar® JumpDrive® S45 USB 3.0 flash drive 

Learn more >

Exec

Lexar® JumpDrive® C20c USB Type-C flash drive 

Learn more >

HD Pan/Tilt Wi-Fi Camera with Night Vision NC450

Learn more >

Lexar® Professional 1800x microSDHC™/microSDXC™ UHS-II cards 

Learn more >

Audio-Technica ATH-ANC70 Noise Cancelling Headphones

Learn more >

Budget

Back To Business Guide

Click for more ›

Most Popular Reviews

Latest News Articles

Resources

PCW Evaluation Team

Azadeh Williams

HP OfficeJet Pro 8730

A smarter way to print for busy small business owners, combining speedy printing with scanning and copying, making it easier to produce high quality documents and images at a touch of a button.

Andrew Grant

HP OfficeJet Pro 8730

I've had a multifunction printer in the office going on 10 years now. It was a neat bit of kit back in the day -- print, copy, scan, fax -- when printing over WiFi felt a bit like magic. It’s seen better days though and an upgrade’s well overdue. This HP OfficeJet Pro 8730 looks like it ticks all the same boxes: print, copy, scan, and fax. (Really? Does anyone fax anything any more? I guess it's good to know the facility’s there, just in case.) Printing over WiFi is more-or- less standard these days.

Ed Dawson

HP OfficeJet Pro 8730

As a freelance writer who is always on the go, I like my technology to be both efficient and effective so I can do my job well. The HP OfficeJet Pro 8730 Inkjet Printer ticks all the boxes in terms of form factor, performance and user interface.

Michael Hargreaves

Windows 10 for Business / Dell XPS 13

I’d happily recommend this touchscreen laptop and Windows 10 as a great way to get serious work done at a desk or on the road.

Aysha Strobbe

Windows 10 / HP Spectre x360

Ultimately, I think the Windows 10 environment is excellent for me as it caters for so many different uses. The inclusion of the Xbox app is also great for when you need some downtime too!

Mark Escubio

Windows 10 / Lenovo Yoga 910

For me, the Xbox Play Anywhere is a great new feature as it allows you to play your current Xbox games with higher resolutions and better graphics without forking out extra cash for another copy. Although available titles are still scarce, but I’m sure it will grow in time.

Featured Content

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?