# UC San Diego researchers hack into a Boeing 737 in under 60 seconds

> Source: <https://www.mercurynews.com/2026/08/28/ucsd-researchers-hack-into-a-boeing-737-in-under-60-seconds/>
> Published: 2026-08-28 17:10:55+00:00

**Getting your**

[Trinity Audio](//trinityaudio.ai)player ready...As a kid, Sam Crow loved playing with toy airplanes. As an adult, he stood before a panel of Boeing engineers, showing them how he’d hacked into a real one.

Crow was a doctoral student at UC San Diego whose school project brought him to Boeing’s test lab, where he demonstrated how he could take over the aircraft with a device the size of a quarter. It would take Crow only about 60 seconds to gain remote control of the aircraft’s mainframe computer.

This espionage-like engineering feat was not an act of sabotage, but a research project under the guidance of UCSD computer scientist and cybersecurity expert Aaron Schulman.

During the six-year program, Schulman oversees a handful of doctoral students who research vulnerabilities of critical infrastructure.

The students are told to hack into important objects on behalf of the good guys, “because it’s going to happen sooner or later,” said Schulman. A few months ago, one of his students found a security gap in an automotive safety system — ironically, [cars with the installed KARR anti-theft program were easier to steal](https://www.sandiegouniontribune.com/2026/07/21/this-anti-theft-auto-system-makes-it-easier-to-steal-cars-ucsd-professor-finds/).

It’s safer to discover vulnerabilities in critical systems before real attackers do, said Schulman.

During his research, Crow pored through the wiring diagrams of the Boeing 737 and eventually found a plausible connection to the aircraft’s mainframe.

“He was like, ‘Hey, wait a minute. If you plug something into that, that directly connects to this computer called the flight management computer,’” Schulman remembered.

In the real world, accessing this port would be relatively easy. This key electronic system is located in the maintenance bay, just under the plane’s nose. The bay is usually left unlocked and within reach for anyone on the tarmac, Schulman said.

Crow was able to test his theory by playing with old computers from Boeing planes. The research team bought old aircraft computers from aviation auctions online, said Schulman. It took some time, but Crow’s theory worked.

Once Crow plugged his transmitter into the computer, he could change the plane’s flight path and alter data that could make takeoff conditions unsafe. Crow then encoded his hack, which made his changes inconspicuous, so pilots wouldn’t be able to tell that changes were made to the computer.

The team alerted Boeing to its findings in April 2020. Their [published research](https://cseweb.ucsd.edu//~savage/papers/UsenixSec26-429.pdf) was presented Aug. 13 at the USENIX Security Symposium in Baltimore.

After initial delays due to COVID, Boeing engineers invited the UCSD team to their test lab and watched as the doctoral student hacked into a 737 testbed in December 2023, Schulman said.

Boeing was surprisingly proactive, “especially given how sensitive the finding was,” said Stefan Savage, co-author of the paper and professor in the UC San Diego Department of Computer Science and Engineering.

When presented with this kind of information, a company can react in two ways: “They could close down and pretend it’s not happening, or try to get you, as the researcher involved, to find what’s wrong and potentially help with the fix,” Savage said.

Boeing thanked the UCSD research team for making them aware of the issue and proceeded to ensure that their planes are safe.

“Our technical experts are confident that the layers of protection in place on the airplane … provide sufficient mitigation to significantly limit the feasibility and risk of real-world attacks,” Boeing said in the UCSD research paper. “Safety is the foundation of everything we do, and we take threats to our products seriously.”

In the ethics section of the research paper, the team acknowledges the potential threats of educating attackers of this vulnerability, but they weighed that risk “against the benefits from understanding these risks and helping to mitigate similar threats in the future.”

UCSD also omitted certain details about its hack in its published work to eliminate the possibility of an attacker duplicating their efforts.

Due to Federal Aviation Administration security and disclosure compliance, Boeing did not share how or if it secured the vulnerability, but researchers said they’re confident Boeing, the airlines and the FAA are all aware and have taken action.

“Thankfully we’re in advance of people hacking airplanes, but in some sense that’s exactly the right time to be doing the kind of research,” Savage said.

The research team wrote in the paper that they “routinely travel on Boeing 737 aircraft and expect to continue doing so.”
