On September 30, 2026, a flydubai Boeing 737 MAX 8 flying from Dubai to Tel Aviv diverted to Saudi Arabia after the Omani co-pilot allegedly stabbed the Indian captain and tried to crash the aircraft. Passengers and crew overpowered him. Ynet reported that more than 170 people were aboard and that the plane landed safely. On October 1, the Prime Minister's office said Israel would identify and run security checks on every pilot flying into the country, foreign and Israeli carriers alike. Israeli media also reported that dozens of Omani pilots had flown the route despite a restriction on pilots from countries with no diplomatic relations with Israel.
The strongest case for tougher vetting
The case for acting is strong. Oman has no diplomatic relations with Israel, and Prime Minister Netanyahu acknowledged that "there was a loophole." A rule that exists on paper but is not checked against individual pilots protects no one. A pilot is the one passenger-adjacent person who can bring down an aircraft, and states have long applied heavier screening to aircrew than to riders. If a carrier's operating agreement says every pilot must come from a country that has normalized relations with Israel, checking that is an ordinary regulatory task, not an intrusion.
On that narrow point we agree with the government. Checking pilot identity and nationality against a known condition is proportionate and aimed at a specific risk.
The gap was institutional, not informational
The more important finding is that Israel's problem was not a lack of data. It was that nobody clearly owned the task. According to Ynet's account, the Civil Aviation Authority grants foreign carriers' operating permits and inspects them. The Transportation Ministry's Aviation Security Operations Center coordinates procedures. The Shin Bet oversees Israeli airlines but not foreign carriers such as flydubai. Ynet's own summary notes that licensing mechanisms do not mean "every foreign pilot operating a commercial flight to Israel undergoes an individual Israeli security background check before each flight."
The State Comptroller had flagged the structure two years earlier. Its May 2024 report on the security of international civil aviation from and to Israel covered an audit run from April 2022 to June 2023. It recommended that the National Security Council, working with the Transportation and Finance Ministries, the Civil Aviation Authority, the Shin Bet and the Police, conduct a comprehensive review of the "entire spectrum" of aviation security, including incoming foreign aviation. It added that government and security cabinet decisions on the subject, "some of which were made as early as the 1970s," should be re-examined. The Knesset subcommittee released only excerpts, citing national security.
That is a description of diffuse accountability. Several agencies each hold a piece of the job, so each can assume another is checking.
What the statute allows, and where the risk lies
The Shin Bet's legal remit is broad but defined. Under the General Security Service Law, 5762-2002, section 7(b)(2) charges it with "protecting persons, information and places determined by the Government," and section 8(a)(1) lets it "receive and collect information." Section 4(c) says it must "operate in a stately manner" with no mission imposed for "party-political interests." Oversight runs through a ministerial committee and the Knesset's intelligence subcommittee. The subcommittee's sessions are privileged, so publication of what is said in them is barred unless the committee decides otherwise after hearing the Shin Bet chief.
This is the concern. Extending vetting to "every pilot" of every foreign carrier is a defined, finite population, and it can be handled with a clear rule. The risk is that the response expands beyond aircrew to passenger data. Israeli media reported that the Tax Authority's traveler-screening center received flydubai's passenger list. Using manifests for border and customs screening is routine. Adding them to a security-service data pool without published limits is a different step. Passengers on a diverted flight were victims of the attack, not suspects.
Israel also has a modern privacy statute. Amendment 13 to the Privacy Protection Law took effect on August 14, 2025, and the Privacy Protection Authority said it would begin enforcing it. We have not verified how the amended law treats state security bodies. Whatever the answer, a security response to a single incident should not become a back door around the data rules the country has just adopted.
A proportionate response
The evidence points to four concrete steps:
- Name one accountable owner for foreign-carrier crew vetting, as the Comptroller's 2024 report recommended, so that a restriction cannot lapse between agencies.
- Vet crew, not crowds. Check pilot and cabin-crew identity and eligibility against a published, narrow criterion such as nationality or diplomatic status. Do not expand passenger-data collection by default.
- Set retention and sharing limits in writing, including who inside government may see manifest data and for how long it is kept.
- Report back to the Knesset subcommittee, and publish at least a summary of how many pilots were checked and how many were flagged.
The flydubai attack was a failure to enforce a rule that already existed. The Comptroller had warned that responsibility for incoming foreign aviation was spread across too many agencies. Closing that gap is the right fix. Broad new surveillance powers would not address it, and they would carry costs for privacy and for the open, connected aviation market that Israel's regional air agreements were meant to build. According to Ynet, flydubai suspended its Israel flights through October 15. The decisions made before they resume will show whether Israel chose accountability or simply more collection.