Publications /
Policy Brief

Back
The Flydubai Flight FZ1073 Incident: Towards a New Generation of Threats to Civil Aviation?
Authors
October 2, 2026

The incident involving Flydubai Flight FZ1073 between Dubai and Tel Aviv does not yet support any definitive attribution. It does, however, provide a useful warning sign: as aviation security closes off traditional avenues of intrusion, threats may shift towards alternative pathways by exploiting the people, service providers, and systems that the aviation ecosystem must necessarily trust. 

Introduction: Questions Left Open by the Flydubai Incident 

On September 30, 2026, Flydubai Flight FZ1073, traveling from Dubai to Tel Aviv, was diverted to Tabuk, Saudi Arabia, following a violent incident in the cockpit. According to information available as of October 1, 2026, the co-pilot allegedly assaulted the captain and caused the aircraft to descend extremely rapidly before being subdued. Other Flydubai pilots on board reportedly then took over and landed the aircraft. Emirati authorities have opened an investigation focusing in particular on whether the act was premeditated and whether it may have had a terrorist motive. At this stage, the motive has not been established, and no link to any organization or state has been demonstrated. [1]

This caveat is essential. Strategic analysis should neither pre-empt the judicial investigation nor turn chronological coincidence into causality. It can, however, use an event that remains only partially understood to identify the vulnerabilities it exposes and the hypotheses it makes relevant. 

The Flydubai case therefore raises four questions. Could civil aviation once again become a preferred target of political violence, albeit in forms different from the hijackings of the 1960s to the 1980s? Does the context of confrontation surrounding Iranian aviation justify keeping an Iranian hypothesis under consideration, without at this stage allowing any attribution? Could terrorist organizations seek to infiltrate, recruit, or turn not only pilots or cabin crew, but the full range of personnel with privileged access to the aviation ecosystem? Finally, is the increasing digitalization of this ecosystem shifting part of the risk towards systems, data, digital service providers, and technology supply chains? 

These questions share a common thread: they call for consideration not only of how to protect the aircraft, but also of how to protect the entire ecosystem that supports civil aviation and enables it to operate. Aviation security has historically been built around controlling physical access. It must now also address the legitimate access granted to insiders, as well as digital access to critical functions. [2]

A History of Aviation Security Shaped by Successive Adaptations 

The international framework for combating acts of unlawful interference with civil aviation took shape in response to the sharp rise in hijackings during the 1960s. Following the Tokyo, Hague, and Montreal Conventions, the International Civil Aviation Organization (ICAO) adopted the first Standards and Recommended Practices of Annex 17 to the Chicago Convention in March 1974. The Annex became applicable in 1975. Its purpose is to protect passengers, crews, ground personnel, and the public against acts of unlawful interference. [3]

Understanding Annex 17 and its importance requires viewing it as an evolving framework rather than a static text. ICAO revises it regularly in response to changes in threats and technologies. Its history therefore reveals aviation security as a dialectical process: a threat exposes a vulnerability; regulation closes or reduces that vulnerability; the hostile actor then seeks another point of access; and regulation must adapt once again. 

  • Initially, from the 1960s through the 1980s, the dominant threat was intrusion. 

An individual seeks to bring a weapon or explosive on board, take hostages, or hijack an aircraft. The response therefore prioritizes passenger and baggage screening, access controls for restricted areas, aircraft security searches, and the protection of cargo and supplies. 

  • The September 11, 2001 attacks marked a further turning point. 

The aircraft was no longer merely the object of a hijacking; it could become the weapon itself. In the United States, the Aviation and Transportation Security Act of November 2001 created the Transportation Security Administration (TSA) and federalized security screening. Landmark measures included screening 100% of checked baggage, expanding the Federal Air Marshal Service, and reinforcing cockpit doors. In parallel, the Federal Aviation Administration (FAA) strengthened requirements for flight deck resistance to intrusion. [4] et [5]

  • Europe followed a different but convergent approach. 

After September 11, Europe transformed a set of national practices into common standards. The first Community framework dates from 2002; Regulation (EC) No. 300/2008 subsequently consolidated common aviation security rules and their oversight. It covers, among other areas, passenger and baggage screening, airport security, checks on aircraft, cargo, mail, in-flight and airport supplies, as well as staff recruitment and training. [6] 

These measures have made conventional attacks considerably more difficult. Yet the success of these measures raises a different question: what happens when a potential perpetrator does not need to force their way in because they already have authorized access? 

Flydubai and the Iranian Hypothesis: Keeping the Question Open Without Manufacturing an Answer 

The incident occurred within a geopolitical sequence that calls for a methodical assessment of competing hypotheses. 

  • On September 23, 2026, several countries in the region suspended Iranian flights amid a tightening of U.S. sanctions targeting Iranian aviation. 

  • According to Reuters, on the same day, Mohsen Rezaei, Secretary of Iran's Supreme National Security Council, publicly warned neighboring countries of the consequences of participating in U.S. restrictions and raised the possibility of disrupting the operation of their airports. [7] 

  • A few days later, the incident involved an aircraft operated by an Emirati airline on a Dubai-Tel Aviv route. This sequence may justify formulating a working hypothesis, but it is not sufficient to establish attribution. 

The temporal proximity, the airline's nationality, the Israeli destination, and the Iranian statements are circumstantial elements. They demonstrate neither direction nor facilitation, nor even a political motive on the part of the alleged perpetrator. 

The appropriate method is therefore to maintain several competing hypotheses: an individual act without political motivation; individual radicalization; an act inspired by a group; an organized act involving accomplices; and, finally, an act facilitated or directed by an external actor. The Iranian hypothesis falls into this last category and, by definition, requires the highest standard of evidence. 

Such caution strengthens rather than weakens the analysis. Even if the investigation were to rule out any Iranian connection and any terrorist motive, the incident would remain valuable for analyzing a vulnerability: a person with legitimate access to a critical function may be able to bypass physical barriers designed primarily to keep external actors out. 

From Intrusion to Infiltration: The Insider Threat Extends Across the Entire Ecosystem 

Amendment 17 to Annex 17, adopted in 2019 and applicable from 2020, strengthened provisions addressing insider threats, including background checks, vulnerability assessments, information sharing, and the screening of persons other than passengers. These provisions notably address risks associated with individuals who have legitimate access to security restricted areas. [8] 

  • This approach is by no means limited to the airline. It extends across the entire civil aviation ecosystem. Pilots and cabin crew are its most visible component, but the same logic applies to ground handling, maintenance, cleaning, catering, refueling, baggage and cargo handling personnel, as well as suppliers, technical service providers, IT operators, and, more broadly, anyone whose role provides physical, informational, or digital access to a critical civil aviation function. 

  • Three mechanisms can contribute to the insider threat: 

  • Infiltration consists of deliberately placing a person within this ecosystem. 

  • Recruitment consists of securing the cooperation of someone already within it. 

  • Radicalization or turning an insider may lead a person who initially had legitimate access to use the privileges granted by the system against it. 

A hostile organization would therefore no longer necessarily need to 'get a terrorist onto the aircraft'; it could instead seek to place, or recruit, an actor somewhere along the chain that enables access to the aircraft. 

The European framework already illustrates this expansion of the security perimeter. Regulation (EC) No. 300/2008 requires access controls, provides for background checks for persons with unescorted access to security restricted areas, and subjects persons other than passengers to screening measures. It also covers supplies intended for airports and aircraft, precisely because flight security depends to a large extent on logistics chains outside the cockpit. [9] 

The challenge then becomes one of sustaining trust over time. The aviation system cannot function without granting access rights. Mechanics must work on aircraft; catering staff must bring supplies on board; cleaning staff must enter the aircraft; baggage and cargo handlers must operate in sensitive areas; and pilots must, of course, control the aircraft. Potential vulnerability is therefore inseparable from normal operations. 

The nature of security thus changes. Screening a passenger is a one-time operation; assessing over time the risk associated with thousands of authorized individuals requires a framework built around personnel security, security culture, supervision, reporting, and continuous reassessment. Such monitoring can draw, in particular, on physical and digital access logs, behavioral anomalies, and unusual system use. [10] 

From Insider Threats to Cyber Threats: Protecting the Digital Chain of Trust 

This latest development extends the previous one. If an external actor seeks to bypass physical controls, and an insider exploits legitimate professional access, a cyber threat creates the possibility of affecting certain functions within the ecosystem without any physical presence on board. 

Spectacular scenarios should nevertheless be avoided. To date, there is no basis for presenting the complete remote takeover of a modern airliner over the Internet as an established terrorist capability. Yet the cyber threat to aviation is real because civil aviation depends on an increasingly dense network of interconnected systems: airline operations, maintenance, communications, navigation, air traffic management, airports, databases, suppliers, and software supply chains. 

ICAO has already incorporated this development. Annex 17 includes Standard 4.9.1 and Recommended Practice 4.9.2 on cybersecurity; the Organization has also developed a strategy, an action plan, and cyber-risk management documents for the aviation sector as a whole. This institutional recognition underscores the significance of the threat: protection against acts of unlawful interference is no longer solely a matter of screening checkpoints, badges, and doors.

Insider threats and cyber threats can also converge. An authorized person may misuse credentials, introduce a device, divert remote access, or facilitate the actions of an external actor. Conversely, a digital compromise may exploit the trust placed in a supplier, software, an update, or a connection regarded as legitimate. 

The insider threat therefore exploits trust placed in a person; the cyber threat exploits trust placed in a system, a digital identity, a supplier, or a connection. In both cases, the attacker no longer necessarily seeks to break through the barrier. Instead, the attacker seeks to appear to the control system in a form that the system has been designed to accept. 

Conclusion: From Protecting the Aircraft to Building Resilience Across the Aviation Ecosystem 

The Flydubai incident may ultimately prove to be an isolated case. The investigation may still conclude that the motive was individual, with no terrorist organization, no external complicity, and no connection to tensions surrounding Iranian aviation. Such a conclusion would invalidate certain hypotheses as applied to this specific case, but it would not eliminate the vulnerabilities that the case brings into focus. 

Since the major waves of hijackings, aviation security has been strengthened in successive layers. Screening responded to the introduction of weapons and explosives; cockpit protection responded to the risk of aircraft takeover; controls on personnel and restricted areas address the insider threat; and cybersecurity now responds to growing digital interconnection. The United States, Europe, and ICAO have followed different institutional paths, but they converge on the same logic: progressively expanding the scope of what must be protected. 

It would therefore be misleading to describe this as a failure of aviation security. Its effectiveness against certain threats partly explains why other methods of circumvention may become more attractive. The progression can be summarized as follows: intrusion, infiltration, digital penetration. 

The real paradigm shift may lie elsewhere. For several decades, security focused primarily on protecting an object: the aircraft. It sought to do so by controlling those who could approach or enter it. It must now protect a system: the aviation ecosystem, made up of people, organizations, service providers, logistics chains, data, software, and networks, all of which must be granted varying degrees of trust. The table below summarizes this evolution and the responses developed to address the different threats. 

Evolution of Threats and Aviation Security Measures 

Type of threat 

Vulnerability targeted 

Representative response 

Conventional hijacking 
(1960s to 1980s) 

Physical access on board 

Passenger and baggage screening, access controls 

Use of the aircraft as a weapon 
(from September 11, 2001 onward) 

Takeover of the cockpit 

Reinforced cockpit doors, TSA, in-flight security officers 

Insider threat 
(risk highlighted by the Flydubai incident) 

Legitimate professional access 

Background checks, staff screening, security culture 

Cyber threat 
(current and evolving risk) 

Systems, data, suppliers, connections 

Cyber resilience and protection of critical functions 

The strategic question raised by the Flydubai incident therefore extends well beyond this single case: how can a global activity be protected when its operation depends precisely on thousands of legitimate points of physical and digital access? The future of civil aviation security will likely depend to a significant extent on how this trust is managed, perhaps even more than on simply strengthening barriers. 

1. Reuters, Sept. 30-Oct. 1, 2026: UAE authorities opened an investigation into the motive, possible premeditation, and a potential terrorist purpose. At that stage, no external link had been established.

2. In its Insider Threat Toolkit, ICAO defines an insider as a full-time, part-time, contractor, temporary, or self-employed aviation-sector worker whose role provides privileged access to, or knowledge of, secure locations, assets, or sensitive information.

3. Annex 17 to the Convention on International Civil Aviation (Chicago Convention) is ICAO's official document on civil aviation security. It sets out the Standards and Recommended Practices aimed at protecting air transport against acts of unlawful interference, including aircraft hijacking, attacks, and sabotage.

4. FAA, AC 25.795-1A, Flight Deck Intrusion Resistance, Oct. 24, 2008; supersedes the original circular issued in January 2002.

5. TSA, 2001-2006 historical overview: ATSA (Nov. 2001), federalization of security screening, 100% screening of checked baggage, Air Marshals, and reinforced cockpit security.

5. European Commission, Aviation Security; Regulation (EC) No 300/2008, which succeeded the common framework established by Regulation No 2320/2002.

6. Reuters, Sept. 23-25, 2026: suspension of Iranian flights and warnings by Mohsen Rezaei. Contextual information, not evidence of a link to Flydubai.

7. ICAO, Amendment 17 to Annex 17: adopted in 2019 and applicable from 2020; strengthened measures to address insider threats.

8. Regulation (EC) No 300/2008: access control, background checks, personnel, cargo, mail, in-flight supplies, and airport supplies are covered by the common framework.

9. ICAO, Insider Threat Toolkit, 2022: a multilayered approach combining security culture, vetting, access control, supervision, and monitoring.

10. ICAO: Annex 17, Standard 4.9.1 and Recommended Practice 4.9.2; Cybersecurity Strategy, Action Plan, and Doc 10213, Global Cyber Risk Considerations.

 

RELATED CONTENT