July 17, 2025 | Policy Brief

U.S. Rail Systems at Risk After Industry Ignored Decades-Old Cybersecurity Vulnerabilities

July 17, 2025 | Policy Brief

U.S. Rail Systems at Risk After Industry Ignored Decades-Old Cybersecurity Vulnerabilities

U.S. rail system controls are not safe. While industry slept, security researchers discovered decades ago that hackers can remotely access the radio communications equipment that controls a train’s braking systems. On July 10, the Cybersecurity and Infrastructure Security Agency (CISA) issued a public warning about the vulnerability. While the freight rail industry is planning to address these flaws, solutions will not begin rolling out until 2027.

Rail Communication Systems Lack Encryption and Authentication

CISA’s advisory formally acknowledges a longstanding security flaw in freight rail’s braking systems. The agency credited Eric Reuter and Neil Smith, security researchers not affiliated with CISA, for showing that the radio signals used for communication between devices at the front and back of freight trains are unencrypted and vulnerable to hacking.

Working independently, both researchers found that without end-to-end encryption or authentication, hackers can transmit fake radio commands from a distance to trigger braking at the front of the train. CISA’s notice highlighted the severity of the findings, noting that “a sudden stoppage of the train” could disrupt operations or lead to brake failure. Smith also added that hackers could disrupt “the entire national railway system” using gear that costs less than $500.

Efforts To Expose Vulnerabilities Face Skepticism

Reuters first disclosed the issue in 2018, while Smith claimed that he discovered the same vulnerability in 2012. Smith later learned that another researcher had identified it as early as 2005, noting that the American Association of Railroads (AAR), an industry trade group, largely ignored these concerns. In 2016, AAR’s then-Vice President for Security, Tom Farmer, argued that industry had not experienced “a cyber-driven derailment” outside of testing environments and questioned the need to address these risks.

Under ongoing pressure from CISA, AAR announced in May plans to replace outdated radio communications equipment. However, Smith estimates that a full replacement with these upgrades could take more than five years and cost more than $7 billion.

Gaps Remain Between Federal Agencies and Industry Implementers

Freight rail plays a critical role in supporting both trade and military mobility. More than 40,000 miles of track make up the Strategic Rail Corridor Network, a network of commercially operated rail lines the Department of Defense has designated for moving troops and equipment to more than 140 military installations.

The Transportation Security Administration (TSA) — the lead federal agency responsible for rail security — issued proposed cybersecurity rules in November 2024 that would require railroad and pipeline operators to establish cyber risk management programs. This rule would impact about 70 of 600 freight rail companies, with the six largest operators subject to the requirements.

AAR has argued that TSA’s directives have included “very limited industry input,” especially around funding and the capacity for small rail operators to implement TSA’s requirements. But given AAR’s past resistance to cybersecurity reforms, its criticisms warrant skepticism.

In fact, TSA’s stakeholder engagement efforts — including monthly calls to clarify compliance requirements, discuss cybersecurity policy, and share threat intelligence — have been well-received by surface transportation operators.

Federal Agencies Must Prioritize Collaboration and Information-Sharing With Industry

To address these cybersecurity risks, TSA should deepen collaboration with rail operators to build trust and develop sector-informed solutions.TSA should continue working closely with both large and small rail operators to develop clear cybersecurity requirements that account for operational realities. Stakeholder engagement would help TSA understand that the cost of meeting compliance requirements of the proposed rule — estimated to cost rail companies $1 million per year — may be a feasible expense for large operators but unaffordable for many smaller operators with limited resources.

In the meantime, TSA and CISA should continue to facilitate information sharing between government and industry for early threat detection and coordinated incident response. By providing cybersecurity best practices, such as end-to-end encryption and authentication, federal agencies can strengthen partnerships and build capacity before incidents occur, reducing cyber risk to the nation’s rail network as operators await new security directives and equipment upgrades.

Jiwon Ma is a senior policy analyst at the Center on Cyber and Technology Innovation (CCTI) at the Foundation for Defense of Democracies (FDD). Stefan Videnovic is a CCTI intern. For more analysis from the authors and CCTI, please subscribe HERE. Follow Jiwon on X @jiwonma_92. Follow FDD on X @FDD and @FDD_CCTI. FDD is a Washington, DC-based, nonpartisan research institute focusing on national security and foreign policy.