Lessons from flydubai FZ1073 and Earlier Cases of Deliberate or Suspected Crew Action
A Low-Probability, Catastrophic-Risk Threat
The 30 September 2026 incident aboard flydubai flight FZ1073 from Dubai to Tel Aviv has reopened one of commercial aviation's most uncomfortable security questions: what happens when the threat is not outside the cockpit, but is a trained, credentialed and trusted person already inside it? UAE authorities have stated that the co-pilot attacked the captain with a crash axe and attempted to seize the flight controls, describing the act as an attempted terrorist attack. The aircraft was eventually brought under control and safely diverted to Tabuk, Saudi Arabia. The investigation into motive, prior planning, possible associates and failures in personnel vetting remains open.
The event should not be used to stigmatised professional pilots. Deliberate hostile acts by flight crew remain extraordinarily rare. However, their potential consequences are catastrophic, and they expose a vulnerability that ordinary hijack-prevention measures cannot address. Reinforced cockpit doors, access codes and passenger screening are designed primarily to keep an unauthorised attacker out. They offer little protection when the attacker already has legitimate flight-deck access.
The Historical Record: Not One Phenomenon, but Several
FZ1073 is not without precedent, although earlier events fall into different evidential and motivational categories. FedEx Flight 705 in 1994 remains one of the clearest insider-threat cases. An off-duty FedEx flight engineer, travelling in the cockpit jump seat, attacked the operating crew to seize the DC-10. Despite severe injuries, the crew fought back and landed safely. The significance is fundamental: the attacker was not an outsider breaching aviation security. He was an authorised employee with technical knowledge and trusted access.
EgyptAir Flight 990, a Boeing 767 that crashed into the Atlantic in 1999, falls into a more complex category. The NTSB concluded that the aircraft's departure from normal cruise and impact resulted from the relief first officer's flight-control inputs, while explicitly stating that the reason for those actions could not be determined. The CVR included repeated religious expressions, but those words cannot be responsibly treated as proof of religious motivation or terrorism. The case demonstrates the need to separate three questions: who manipulated the aircraft, whether the manipulation was deliberate, and why it occurred.
SilkAir Flight 185 is similarly disputed. The Indonesian investigation did not determine a cause, whereas the US NTSB concluded that the evidence was most consistent with deliberate control inputs. It is therefore relevant as a suspected case, but not as an established example of pilot suicide.
LAM Mozambique Flight 470 and Germanwings Flight 9525 are far less ambiguous. Investigators concluded in both cases that a pilot deliberately caused the aircraft to descend while alone in effective control of the flight deck. Germanwings prompted major changes in European policy on pilot psychological assessment, support programmes and substance testing.
Malaysia Airlines MH370 again belongs in a separate evidential category. The loss of normal communications, major route deviation and continued flight for many hours inevitably generated hypotheses involving deliberate human action. Yet the main wreckage, CVR and FDR have not been recovered, and the official investigation could not determine the cause. MH370 therefore illustrates the consequences of the loss of assured control, tracking and communications, but should not be presented as a proven pilot-suicide event.
The Common Vulnerability: Trusted Access
These cases differ in motive and certainty, yet they expose a common structural weakness: aviation systems are built on the assumption that authorised personnel will support the safe completion of the flight. A pilot, engineer, instructor, check pilot or other authorised crewmember can bypass layers of security precisely because the system is designed to trust that individual.
This is why the term “rogue pilot” is too narrow. The more useful concept is the malicious insider threat to the flight deck. It includes operating pilots, deadheading crew, engineers and other employees with privileged access. The risk may arise from terrorism, personal grievance, deliberate self-destruction, coercion or acute behavioural breakdown. These pathways are not interchangeable, nor are their countermeasures.
FZ1073 also raises a specific concern about cross-border personnel information. Modern pilots may train in one country, hold a licence issued by another, and work successively for several international operators. If one State or employer has imposed a serious security-related restriction, that information must not simply disappear when the individual crosses a jurisdictional boundary.
Where Current Defences Remain Weak
ICAO's Insider Threat Toolkit already recognises that background checks should be recurrent and that continuous vetting should be encouraged, including cooperation with authorities in other States. Importantly, ICAO notes that some insiders develop malicious intent only after employment. Pre-employment screening is therefore necessary but insufficient.
The United States Pilot Records Database offers another useful model. It requires covered operators to review available training, qualification, disciplinary and separation records before employing a pilot. It is not a global security database, but it shows that structured, regulated sharing of employment history can be achieved without compromising due process.
The post-Germanwings European response introduced psychological assessment before line flying, pilot support programmes and enhanced drug and alcohol testing. These are valuable aeromedical barriers, but psychological screening must not be confused with security vetting. A terrorist insider, a suicidal pilot and a pilot with a treatable mental-health condition are distinct problems. Treating them as one can both miss genuine threats and discourage pilots from seeking medical help.
A Layered Preventive Strategy
The priority should be an internationally compatible system for recurrent personnel security vetting. National authorities should be able to flag serious aviation security restrictions to one another via secure regulator-to-regulator channels. Airlines need not receive intelligence details; they do need to know when an applicant or serving crew member requires further security review before granting unrestricted cockpit access.
Second, airlines must verify previous employment directly rather than infer it from a CV. Relevant records should include serious disciplinary action, separation from employment, unresolved security restrictions and documented safety-significant behaviour. A non-response from a previous employer should trigger further review, not automatic clearance.
Third, airlines need robust, confidential reporting and peer-support systems. Colleagues often notice significant behavioural changes before management does. Reporting mechanisms should enable instructors, pilots and cabin crew to raise genuine concerns while protecting employees from arbitrary accusations based on nationality, religion, political opinion or routine mental-health treatment. Security assessments must be intelligence-led and behaviour-based, not discriminatory.
Fourth, operators should review cockpit procedures to address malicious interference. CRM traditionally assumes that both pilots ultimately share the objective of safe flight. A hostile crew member violates that premise. Training should therefore address deliberate interference with controls, assault or incapacitation of one pilot, rapid cabin-crew intervention, emergency cockpit access, and communication with ATC. This is not an argument for turning pilots into security officers; it is an argument for recognising an extreme but credible contingency.
Fifth, FZ1073 justifies a technical review of emergency equipment, such as the crash axe. Removing it automatically may create a new hazard, as crews may need it during a fire, structural damage or evacuation. However, its location, retention, accessibility and tamper indication should be assessed against the insider-threat scenario.
Finally, insider threat belongs at the intersection of the airline's Safety Management System (SMS) and Security Management System (SeMS). Safety departments traditionally analyse errors, equipment failures and procedural breakdowns, while security departments focus on hostile acts. FZ1073 shows why these domains must intersect. A malicious insider may exploit normal operational authority to create a safety catastrophe in seconds.
Conclusion
Aviation has spent the past quarter-century making the cockpit extraordinarily difficult for an outsider to penetrate. The next challenge is to ensure that trusted access does not itself become the vulnerability. FedEx 705, EgyptAir 990, SilkAir 185, LAM 470, Germanwings 9525, the unresolved disappearance of MH370, and now FZ1073 show that the issue cannot be reduced to a single motive or medical diagnosis.
The probability of deliberate hostile action by authorised aviation personnel remains very low. However, the consequences could be catastrophic. The correct response is neither suspicion of the pilot profession nor intrusive surveillance of every crew member. It is a layered security architecture: verified international employment histories, recurrent and continuous vetting, regulator-to-regulator information sharing, effective peer-support systems, carefully governed reporting, route-sensitive risk assessment, and explicit insider-threat planning within both SMS and SeMS.
The most important question arising from FZ1073 may therefore be broader than the alleged act itself: if relevant warning information existed before the flight, why did the aviation system fail to turn that information into an effective barrier? The answer will determine whether FZ1073 becomes merely another extraordinary incident - or the catalyst for a more mature global approach to flight-deck insider risk.
Author: GR Mohan