Years of Salt and Metal | The crash of Hop-a-Jet flight 823

· Medium ·

70 min read Original article ↗

Admiral Cloudberg

Press enter or click to view image in full size

Hop-a-Jet N823KD burns on Interstate 75 in Naples, Florida following its crash landing. Photo: Mike Hudson for WINK news

On the 9th of February 2024, a business jet was maneuvering for final approach into Naples, Florida, when out of the blue, both engines lost power for no apparent reason. With just 90 seconds to impact and no chance of reaching the airport, the pilots faced the most difficult decision of their careers, a split-second choice of landing site that carried life-or-death consequences. In the end, met with no better options, they put their plane down in the southbound lanes of Interstate 75, leading to a dramatic and fiery crash landing that claimed their own lives and left the cabin attendant and passengers fighting a desperate battle to escape an airplane that quickly became a death trap.

The crash of Hop-a-Jet flight 823 was caught on video and shared widely around the world, but the harrowing images did little to explain why both engines suddenly failed. Investigators would later rule out all the obvious causes, including fuel exhaustion, bird strike, or even an accidental fuel shutoff. Instead, they found that the crash in Naples was something that as far as I am aware has never happened before, something so out-of-left-field that the final report, published in early 2026, almost requires the reader to suspend disbelief. The engines of flight 823 failed not because of some common component of the fuel system or some external influence, but rather because both engines possessed an identical latent mechanical flaw that made them both independently vulnerable to failure under the same specific operating conditions.

What follows is the story of how that was allowed to happen — and how it could have been prevented.

◊◊◊

_______________________________________________________________

[Download this article as a PDF]

This article uses in-line citations for all claims other than general information and the author’s personal opinions. Citations use the format [1] for a source containing few or no pages, and [1:74–76] to identify the relevant page or page range in a source containing many pages. References link to the attached Bibliography.

No AI tools were used to research, format, or write any part of this article.

This article was reviewed for factual accuracy by two aerospace engineers and a former Bombardier Challenger pilot prior to publication. However, I am human and so are they. If you spot an error, please let me know by private message or email.

This article was written concurrently with a Mentour Pilot video on the same accident, which is upcoming at the time of publication; similarities between this article and the video are because I wrote both of them. See this post for more information about my role at Mentour Pilot.

_______________________________________________________________

◊◊◊

In 1976, former US Navy pilot and WWII veteran Harvey Hop founded a business jet charter company in Fort Lauderdale, Florida, which he humbly christened Hop-a-Jet, after himself.[2] Fifty years later, and 27 years after Mr. Hop’s own passing, his company is still in operation, and its website advertises worldwide on-demand charter flights using a fleet consisting of midsized Learjet 60s, larger Bombardier Challenger 350s, and even larger Challenger 604s and 605s,[3] which can carry up to 12 passengers nonstop to just about anywhere in the continental United States.[4] The cost of a trip is not listed; you can call to get a quote, but if you have to ask, you can’t afford it.

Hop-a-Jet is actually a parent company that owns several subsidiaries, of which its charter business, Ace Aviation Services,[7] operates under the Hop-a-Jet brand.[1:5] Ace Aviation Services differs structurally from some other popular business jet charter companies in that it resembles a traditional operator. For instance, NetJets, the largest business jet charter company in the world, sells fractional ownership in its aircraft, which are then made available on demand to the shareholders;[5] alternatively, some companies enter lease agreements with private owners to sell trips on their aircraft to third parties. By contrast, Hop-a-Jet owns all its own aircraft, performs all its own maintenance,[2] and charges per trip, much like an airline. The company appears to run a fairly tight ship with a good safety culture, since none of the people interviewed by the NTSB had anything negative to say about their experience there,[6] and up until 2024 Hop-a-Jet had operated for 48 years without a fatal accident.

Press enter or click to view image in full size

Harvey Hop with one of his jets. Photo: Hop-a-Jet

Nevertheless, Aaron Baker, equity trader and Vice President of investment firm Scioto View Partners, never intended to fly with Hop-a-Jet on the 9th of February, 2024. The young executive had booked a flight for himself and his girlfriend Audra Green on that date from Ohio State University Airport in Columbus, Ohio to Naples Airport in Naples, Florida through NetJets, not Hop-a-Jet. But four days before the flight, NetJets informed him that due to high demand for its business jets ahead of the upcoming Super Bowl LVIII, his requested aircraft would be unavailable, but they could upgrade him to a Bombardier Challenger 604 operated by Hop-a-Jet instead,[8:19–20] presumably through some kind of inter-company agreement. Baker had never heard of Hop-a-Jet before, but he agreed.

The plan was for Hop-a-Jet to fly one of its Challenger 604s, registration N823KD, up to Columbus from the company’s home base at Fort Lauderdale Executive Airport; pick up the passengers; fly them to Naples; then ferry the plane back to Fort Lauderdale.[9:13] For this trip sequence, a single crew was rostered, consisting of two pilots and a cabin attendant.

Press enter or click to view image in full size

N823KD, the aircraft involved in the accident, pictured at Fort Lauderdale-Hollywood International Airport. Photo: Paul Watson

The pilot in command for the trip was 50-year-old Ed Murphy, an experienced business jet pilot who had spent much of his career flying Learjets[6:23] and Challengers, although he also had a helicopter rating. With 10,380 flying hours, including nearly 2,700 on the Challenger, he probably knew both the airplane and the industry like the back of his hand,[1:7] although few people at the airline said they knew much else about him — one first officer described him as a “real quiet guy” and stated that “it was kind of difficult to have a conversation with him about anything other than the airplane, even in cruise.”[6:93] But we probably all know someone like that; it was just the cut of his jib. He was a professional through and through.

The second in command was 65-year-old Ian Hoffman, a recently retired airline pilot who had spent decades flying large airliners but had switched to flying business jets[6:41–42] after hitting the mandatory retirement age under Part 121 of the federal aviation regulations. Part 135, which governs on-demand charters and air taxis, including Hop-a-Jet, does not have the same age restrictions, so it’s not uncommon for older pilots who really love their jobs to spend a few more years flying under Part 135 just because they can. Hoffman appeared to be one of these, as his records showed a very impressive 24,851 total flying hours, but only 116 hours on the Challenger 600 series.[1:7]

The third member of the crew was the cabin attendant, 27-year-old Sydney Bosmans.* Bosmans was not legally a flight attendant because she didn’t have a flight attendant certification from the FAA, nor was she expected to possess one, since a certificate was not required to serve as a cabin attendant on a business jet under Part 135 of the federal aviation regulations.[1:7][9:9] Her role was officially listed as “cabin server — no safety functions,”[9:13] but during her interview with the National Transportation Safety Board, she stated that she was there “for safety,”[9:16] implying that certain informal safety expectations were nevertheless placed upon her.

Perhaps in part because of these expectations, Bosmans took what she called a “personal and professional development decision” to undergo flight attendant safety training from Aircare International, which was not required for her position.[10] Although the possibility of an emergency must have been on her mind when she signed up for the training course, she could not have imagined just how crucial that “personal decision” would turn out to be.

*Note: The NTSB report erroneously lists her age as 23. Bosmans herself gave her age as 27 at the time of the accident.

Press enter or click to view image in full size

The cabin of one of Hop-a-Jet’s Challenger 604 aircraft, from their company website. Very different from the airplane interiors most of us are used to.

On the morning of the 9th of February, the three crewmembers boarded N823KD and took off for the empty leg up to Columbus. No problems with the airplane were noted, and with no passengers to serve, the atmosphere on board was relaxed. Bosmans spent most of the flight reading a book.[9:32]

Flight 823 — Hop-a-Jet flight numbers are based on the airplane’s registration number, not the route — arrived at Ohio State University Airport in Columbus sometime around noon local time. At the airfield, which is owned and operated by the Ohio State University system, the crew met the two passengers, who took their seats in the mostly empty Challenger. While the pilots prepared the aircraft for the next leg, a recorded audio safety briefing played over the cabin speakers, but there would not have been a safety video or demonstration like on a passenger airliner.[9:60–61]

Bosmans soon discovered that this would be an easy trip with a light workload. The passengers had brought their own food, so there was no need for her to prepare any, and they largely cleaned up after themselves. Once the flight took off, headed south toward Florida, there was little else left for her to do but watch and wait to see whether anything happened.[9:71–72]

She could not have known that N823KD carried another, less pleasant passenger, in the form of a mechanical flaw that would soon throw everyone aboard into a fight for survival.

◊◊◊

Back on the 15th of January 2024, just under one month ago, a different crew was preparing to fly a different set of passengers out of Fort Lauderdale aboard N823KD. While sitting on the ramp with the engines already running, the pilots received word from air traffic control that there would be a delay of undetermined length, so they shut down the engines and waited for updates. Fortunately, the delay proved blessedly short, and after just 15 minutes they were released for startup and taxi. So, for the second time that day, the pilots ran through the normal engine startup sequence — but this time neither engine spooled up to the minimum idle speed, despite lighting off and achieving some rotation. The crew shut the engines down and tried again, only to achieve the same result. Eventually, after several more failed attempts, the №1 engine did spool up to idle power, but the №2 engine still would not accelerate. Frustrated and out of options, they transferred the passengers to another airplane, and N823KD was handed over to the South Florida Jet Center, Hop-a-Jet’s wholly-owned maintenance facility, to begin troubleshooting the problem.[11:43]

What the crew of N823KD experienced that day is called a “hung start.” And to understand what that is and why it might happen, you, the reader, must undergo a five minute crash course on how a turbofan engine works. I promise that I’ll make this fun.

At the simplest level, a turbofan engine produces thrust by triggering rapid expansion of air inside a confined space, which causes the velocity of that air to increase.

Press enter or click to view image in full size

An abstraction of a generic turbofan engine, so you can picture where all the parts are in relation to each other. The turbine is connected to the compressors and the fan by concentric shafts running down the center of the engine. Source: Pilot Institute

As air is drawn into the engine, a series of escalating compressor rotors increase its pressure. This highly pressurized air is then fed into the combustion chamber, where the ignition of fuel increases the temperature of the air, causing it to rapidly expand. This rapid expansion increases its velocity as it escapes from the combustion chamber, where that energy is used to spin the turbine (or turbines), which in turn powers the compressors, creating a self-sustaining feedback loop. The turbine also powers the fan, which forces bypass air around the exterior of the engine core, generating most of the thrust.

Getting this feedback loop started isn’t intuitive, because the compressors provide the air that powers the turbine that spins the compressors, creating a bootstrapping problem. That’s why engines have a starter system that helps spin up the core until it’s drawing in enough air to power the turbine, at which point the starter disconnects and the turbine takes over. From there, the process is self-sustaining as long as the engine maintains a constant supply of both air and fuel.

In order to produce enough thrust to propel a multi-ton aircraft through the air at a significant percentage of the speed of sound, the fan needs to displace air really, really fast. That means the turbine needs to spin really fast too, which requires a huge amount of energy; and to provide that energy, the engine needs to expand a vast quantity of air every second. The compressor section solves this problem by pressurizing the air before it enters the combustion chamber, which increases its density; i.e., the mass of air per unit of volume. The greater the pressure (read: density) of the air, the greater the mass that can be expanded per unit of time, the faster the turbine can spin the fan, and the greater the thrust that the engine will produce.

The compressor section consists of a series of fan-like rotors that progressively increase the pressure of the air as it travels from fore to aft. Each of these is called a “stage,” and there are typically a large number of them; for instance, on the General Electric CF-34–3B engines installed on the Bombardier Challenger 600 series, there are 14 compressor stages.[11:34] Regardless, the important thing to understand about the compressor section of a turbine engine is that it is an affront to god; it does its job not because it wants to work, but because engineers much smarter than me have somehow tricked it into working. The compressor section has to maintain a steep pressure gradient across its length, while maintaining airflow into, rather than away from, the area of highest pressure, an inherently unstable arrangement that yearns to collapse at the slightest provocation.

On the CF-34–3B engine, each of the 14 compressor rotors rotates at the same speed, but the gas path — the space through which the air flows — becomes increasingly constricted with each stage, which is why the air pressure increases. And to keep forcing the air deeper into this ever-constricting passage, the rotors are equipped with dozens of individual blades, each of which is an airfoil, much like a wing. Whereas the air acts against a wing to push the plane up, a compressor blade acts against the air to push it onward into the next stage.

One of the actual compressors from the accident aircraft, with all the surrounding structure stripped away so that you can see the 14 compressor rotors. Stage 1 is at the bottom and Stage 14 at the top. The engine is standing on end. Photo: NTSB

Of course, one of the fundamental characteristics of any airfoil is that it can stall. A stall occurs when the angle of attack of the airfoil — essentially, the relative angle between the airfoil and the direction of airflow — becomes too high, causing the wing to lose its ability to generate lift; or in the case of a compressor blade, causing it to lose its ability to force air backward. Should that occur, then the mass of air moving through the compressor will rapidly decrease, the pressure gradient will collapse, the combustion chamber won’t be able to expand enough air, and the whole turbine-fan-compressor feedback loop will start to spool down. Alternatively, if the blades are stalled from the very beginning, the engine might never spool up in the first place, which is what is known as a “hung start.”

Visualization of a compressor blade at its design angle of attack and in a stalled state. Source: Combined Cycle Journal

A hung start, where the engine lights off and begins rotating but never spools up to minimum idle speed, can occur for a variety of reasons: for instance, if the starter disconnects too early, before the feedback loop becomes self-sustaining; or if the fuel is contaminated and won’t burn cleanly enough to expand the required amount of air; or if airflow into the engine is constricted; or if the compressor blades are damaged, increasing their angle of attack.[1:9] The list goes on and on.

The large number of possible causes makes diagnosing the source of a hung start somewhat labor-intensive. To assist, General Electric provided a troubleshooting procedure containing a logic tree that helped mechanics rule out possible causes, with repeated successful engine starts considered a terminating condition; i.e., proof that previous troubleshooting steps had been successful.[11:15]

After both engines on N823KD experienced hung starts on January 15th 2024, mechanics from the South Florida Jet Center implemented the troubleshooting procedure, which began with a fuel check. If both engines experience a hung start at the same time, the fuel is the most obvious common culprit, but initial visual inspection of the fuel on January 15th revealed no anomalies, and further testing on the 17th ruled out the fuel as a possible cause.[11:43–44]

The day after the hung start incident, mechanics tried starting both engines, and this time they started up normally, even though no corrective actions had been taken. The South Florida Jet Center then contacted GE, who suggested that they change the fuel filters and attempt a “heat soak” start. Because the engines had only been shut down for 15 minutes and were therefore still hot when the pilots attempted to restart them during the incident, GE had the technicians run the engines at high power to heat them up, followed by shutdown and immediate restart, in an attempt to reproduce the problem; however, this tactic was unsuccessful. Technicians then carried out a visual inspection of the engines, which revealed no anomalies. At that point, since the engines continued to start up and run normally, the logic tree advised termination of the troubleshooting process, even though the cause of the hung starts had not been identified. As a result, the work was concluded on January 18th, and with the assent of General Electric, N823KD was returned to service.[11:43–44]

In a later interview with the NTSB, which was conducted before the cause of the incident had been identified, one of the pilots who experienced the January 15th hung start event expressed disquiet in hindsight with this outcome. “Say you’re driving in your car, and your car shuts off,” he said. “You bring it to the mechanic, and the mechanic goes, ‘you know, I can’t find anything wrong with it. You know, maybe it was a glitch. We checked the fuel that was in the tank. Everything’s okay. Here’s the keys. See you later. Have a good day.’ How would you feel? … Do I just mark it up as an electronic gremlin, which it seems like with electronics, there are electronic gremlins. There are items that do happen, and you cannot duplicate them.” But then he added, “This was not an electronic gremlin. There was nothing electronic about that system.”[6:105] His comments really hit the crux of the issue: if the engines repeatedly hang during startup, and there’s nothing amiss with the fuel, then you have to start seriously considering the possibility that something is mechanically wrong. And if you can’t find anything that’s mechanically wrong, does that mean you throw up your hands and say, “I guess we just won’t worry about it?” Or does it mean you haven’t looked hard enough yet?

That is, of course, a rhetorical question. In fact, if the troubleshooting procedure had been continued, the technicians eventually would have reached Maintenance Practice 68, a functional check of the variable geometry system actuating pressure, which would have blown the whole case wide open. But because the logic tree permitted them to return the aircraft to service after testing the fuel, swapping the filters, conducting a heat soak start, and visually inspecting the engines, they never got to Maintenance Practice 68.[11:15, 44]

So, what was really going on here? What is the variable geometry system? And why would Maintenance Practice 68 have identified the culprit? To answer those questions, we need to dive even deeper into how a compressor actually works.

◊◊◊

As I said earlier, a compressor is a fickle machine that will pounce on any excuse to stop doing its job. The compressor is happiest when the blade angle of attack is within a narrow range, which we’ll call the design range; this normally corresponds to the climb to cruise thrust regime because that’s where an engine is going to be operating most of the time. You could build a compressor that’s happiest at low power if you wanted, but that would be kind of stupid.

Nevertheless, a compressor must be able to operate under a range of power settings and environmental conditions that have primary, secondary, or tertiary effects on the compressor blade angle of attack. For instance, let’s say the airplane is descending with the engines at flight idle but a high forward airspeed. That means the compressor rotors are spinning relatively slowly, so they’re not forcing as much air backward, but the high forward airspeed means a lot of air is coming in through the inlet anyway. This would cause air to build up in front of the compressor like water in a clogged drain, resulting in a local decrease in airflow velocity. But the compressor blades are designed so that the angle of attack is optimized when the airflow velocity is high; therefore, for a given rotor speed, as airflow velocity decreases, the angle of attack increases. Soon the angle of attack will get too high and you’ll get a compressor stall. (Not a dissimilar principle to the well-trod relationship between airspeed and wing angle of attack at a constant altitude and aircraft weight — as forward airspeed decreases, angle of attack must rise.)

The purpose of the variable geometry or VG system is to prevent this from happening, not just in the scenario I described above, but in countless others as well. This system consists of two main sets of components: the inlet guide vanes, or IGVs; and the variable geometry (VG) stator vanes.

The VG stator vanes are non-rotating sets of vanes spaced in between the compressor stages to redirect the airflow exiting the previous stage so that it impacts the next stage at the correct angle of attack. On the CF-34–3B, the first five stages are articulated so that they can open and close like a set of Venetian blinds; stages six through 14 are fixed in place. All 14 sets are called stator vanes and they all perform basically the same function, but the term “variable geometry vane” only refers to the first five stages that are articulated.[11:109]

Press enter or click to view image in full size

A close-up cross-section of some variable stator vanes alternating with the compressor rotors. Source: Rolls Royce

The IGVs are structurally similar to the VG stator vanes, except they’re positioned ahead of the first compressor stage, and their main purpose is to regulate the amount of air that enters the compressor. When the IGVs are fully open, as they would be during climb or cruise power, they present almost no obstruction to the inlet airflow, since this is the compressor’s design condition. And when the engine is at lower power settings, the IGVs close, blocking a substantial portion of the inlet airflow, ensuring that the mass of the air entering the compressor section is commensurate with the amount that the compressor is able to force backward. Similarly, the VG stator vanes fully open at higher power settings and fully close near idle.

Press enter or click to view image in full size

An example of open inlet guide vanes (left) versus closed inlet guide vanes (right) on a gas turbine. These pictures aren’t from jet engines; they’re from stationary gas turbines, but this is just to illustrate the principle so you can picture it. Source: Power Plant Guru

Before continuing, I want to briefly go over how the VG system mechanically operates, because it’s important for understanding what happened to N823KD.

On the CF-34–3B engine, a mechanical cam responds in real time to compressor rotor speed (N2) and inlet temperature (which affects airflow velocity) to open and close a valve that supplies pressurized fuel to the VG actuator. (That is, the actuator uses hydraulic principles, but is driven by fuel pressure instead of hydraulic fluid.) The greater the supplied fuel pressure, the more open the VG stator vanes and IGVs will be.[11:86]

In order to open or close the vanes, the actuator rotates a shaft, which is connected by a series of turnbuckles to six actuating rings, one for each VG stator vane stage and the IGVs. The actuating rings translate circumferentially around the outside of the cylindrical compressor case that contains the compressor section. Each actuating ring is attached in turn to dozens of small lever arms, one for each individual vane. The opposite end of each lever arm is attached to a spindle, which connects to the vane itself through a hole bored in the compressor case. Therefore, as the actuating ring translates around the compressor case, it actuates the lever arms, which rotate the vanes.[11:91–93]

Press enter or click to view image in full size

This photo of the actual VG actuating system from one of N823KD’s engines, and this inset diagram, help illustrate how the system works. The actuator shaft rotates -> the turnbuckles pull on the actuating rings -> the actuating rings translate left/right, pulling on the lever arms -> the lever arms rotating the guide vanes. Note that in the photo, the stages 3, 4, and 5 turnbuckles have been disconnected from the actuator shaft. Photo: NTSB; Diagram: Applied Sciences

So, with this background in mind, let’s roll back the clock to 2005. On new year’s day that year, N823KD was delivered brand new from the factory to Suzuki del Caribe, an owner-operator in Puerto Rico. For much of the next 15 years, the aircraft was based at Grantley Adams International Airport in the Caribbean island nation of Barbados.[11:31] Like most privately owned business jets, it presumably spent most of its time parked at its operating base, which was just a stone’s throw from the Atlantic Ocean in a hot, humid climate. During this time, saltwater worked its way into both engines and left behind salt deposits that reacted with metal engine components in the presence of oxygen, leading to corrosion. This process continued after the airplane was sold to Hop-a-Jet in 2020 because that company’s operating base in Fort Lauderdale was also adjacent to the ocean in a humid subtropical region.[1:2, 8]

The worst affected area of each engine was the inside of the high pressure compressor case, and especially at the holes bored in that case to accommodate the spindles for the stages 4 and 5 VG stator vanes.[1:2] The corrosion was thought to be worse in those areas because the higher operating temperatures in those stages sped up the chemical reaction process.[11:120–121]

Press enter or click to view image in full size

Images of some of the corrosion that was found on N823KD’s engines. Photos: NTSB/GE

As corrosion built up on the inside of the spindle bore holes, it reduced the holes’ diameter, constricting the bushings that accommodated the spindles within the holes. This in turn caused interference that made it harder to rotate the vanes.[11:106] Inspections after the accident revealed that at stage 5 in both of N823KD’s engines, the corrosion was so far advanced that the force required to move the VG actuator to the fully closed position was far outside the manufacturer’s specifications,[11:99] and even with the actuator fully extended, the stage 5 VG stator vanes did not fully close.[11:102] Furthermore, because the entire VG system is interconnected through the VG actuator, this meant that neither the IGVs nor the other four VG stator vane stages could fully close either. Therefore, the IGVs and VG stator vanes would remain slightly open during startup and at idle power when they should be fully closed.

The technical term for this is an off-schedule condition, and it’s a concept that requires some explaining.

First of all, a compressor has something called an operating line, which is a mathematical equation depicting the pressure ratio (compressor exit pressure over inlet pressure) that is achieved for a given air mass flow rate. For our purposes, consider mass flow rate to be a facsimile for compressor rotor speed; the faster the rotors spin, the more air they push backward. As the mass flow rate increases, the achievable pressure ratio also increases because the compressors are compressing more air; more air in the same volume means higher pressure. Alternatively, you can achieve a higher pressure ratio without changing the mass flow rate by increasing the blade angle of attack. This is kind of the same concept as a wing, where you can increase lift either by increasing airspeed (i.e., the amount of air passing over the wing per unit of time, in other words mass flow rate) or by increasing the wing’s angle of attack.

However, if the angle of attack becomes too high, the blades will stall; this is the compressor stall condition I talked about earlier. The pressure ratio at which this happens for a given mass flow rate is a separate mathematical equation called the stability limit line or surge line. If the operating line surpasses the stability limit line, then a compressor stall will occur.

Press enter or click to view image in full size

An abstraction of the operating line vs. stability limit line concept. Source: Own work

The IGVs, VG stator vanes, compressor rotors, and so on are choreographed such that the operating line should not surpass the stability limit line within the intended operating envelope of the engine. This choreography is the schedule.

If the IGVs are slightly too far open for the current power setting, then they will let too much air into the compressor, throwing off the schedule. Since the compressor rotor speed is based on the power setting, and mass flow rate is (to the extent that we need to worry about it for the purposes of this article) dependent on rotor speed, the extra airflow beyond what the rotor speed can accommodate will result in a buildup of air like the analogy of the clogged drain that I used earlier. As the air backs up, its velocity will decrease. This decreased air velocity increases the angle of the attack of the blades, and this increase is then compounded at each subsequent VG stator vane stage, where the slightly-too-far-open stator vanes allow the air to continue progressing to each subsequent stage at a higher than intended angle of attack. This higher angle of attack then results in a higher pressure increase at each stage, and therefore a higher overall pressure ratio. And as you hopefully recall, a higher pressure ratio for a given mass flow rate means that the operating line moves closer to the stability limit line.

Press enter or click to view image in full size

Effect of corroded VG stator vanes on the stability margin. Source: Own work

So, coming back to N823KD, we can see that because the IGVs and VG stator vanes were always slightly open when they should have been fully closed, both engines’ operating lines were always closer than intended to the stability limit line during startup and idle. This off-schedule condition then went away at higher power settings where the vanes were supposed to be open anyway. It also did not normally prevent the engines from starting or running at idle, unless some other condition also acted to reduce compressor stability or increase the operating line — such as a higher than normal engine temperature, for instance. A higher engine temperature moves the stability limit line downward due to certain complex effects involving blade tip clearance and compressor loads,[11:43–44] which to be perfectly honest I don’t understand and you don’t need to understand either. Additionally, the extra heat increases the airflow energy (read: velocity), leading to faster turbine spin-up and faster acceleration, which always increases the operating line.[11:44] In fact, any acceleration demand has this effect to some extent, because spinning the turbine faster requires a higher pressure ratio to exist first, and the way you get a higher pressure ratio out of a given rotor speed is by increasing the blade angle of attack, which temporarily eats some of the stability margin until the rotor speed catches up.

Once in a while, the combination of the too-open IGVs and VG stator vanes, a high engine temperature, high ambient temperature, and/or other subtle factors combined to push the operating line past the stability limit line in one or both of N823KD’s engines during startup, leading to a hung start. This is what took place on the 15th of January 2024, when the pilots tried to restart the engines before they had fully cooled down. But that wasn’t the first time it had happened.

Hop-a-Jet maintenance records in fact revealed a long history of hung start events involving N823KD. For instance, in September 2020 the №1 engine experienced a hung start and technicians replaced the fuel filter. In March 2023 the same engine failed to start entirely, and this time the air turbine starter was replaced. Then in mid-April of that same year, the №2 engine experienced three hung starts, resulting in replacement of the stage 10 bleed air shutoff valve and the engine start control valve, while the air turbine starters were swapped between the two engines. Just two days later, though, the №1 engine experienced another hung start, leading to replacement of that start control valve. And in May of that year, the №2 engine hung started yet again, resulting in a second replacement of its engine start control valve, along with the speed switches, the stage 14 bleed air adapter, and the main fuel control unit.[11:45–46] The engines then operated normally for eight months before the problems returned during the January 2024 incident.

The fact that these hung starts kept happening on the same engines despite replacement of multiple components indicated that the replaced components were not the cause of the problem. However, because the hung starts were intermittent and only manifested under certain nebulous conditions, their low reproducibility biased the troubleshooting logic tree toward early termination. Had the troubleshooting process continued to the end, Maintenance Practice 68 — the one I mentioned earlier that set this whole arc in motion — would have required a functional test of the VG system that would have revealed the inability of the vanes to fully close.[11:15] However, VG system corrosion by its very nature prevented this step from being reached, because unless the damage was particularly extreme, the engines would always start up normally while checking the outcome of previous troubleshooting steps, even if those steps had not materially changed anything.

Press enter or click to view image in full size

An excerpt from Maintenance Practice 68, the procedure that would have prevented the accident. Source: General Electric

The decision to put Maintenance Practice 68 near the end of the troubleshooting logic tree was a procedural design error by General Electric. The evidence docket for this accident doesn’t contain any documents that directly address why this error was made; however, we can take an educated guess. According to Hop-a-Jet, checking the functionality of the VG system required specialized equipment that most maintenance facilities at that time didn’t possess, requiring in-person assistance from GE.[12:2] Therefore, it’s possible that this check was placed near the end of the logic tree to ensure that maintenance facilities could complete as much of the troubleshooting process as possible before requesting in-person help. However, it is worth noting that (as you can see in the above image) the version of the procedure that I was able to acquire doesn’t appear to demand anything more specialized than a compressed gas cart.

It’s also possible that when the logic tree was designed, GE assumed that a malfunction of the VG system would be very rare and that it should only be checked after exhausting more plausible explanations. But even so, the fact that an off-schedule condition of the VG system would not reproduce hung starts consistently enough to permit elimination of other possibilities appears not to have been considered during the procedural design process. And as a further massive demerit against this interpretation of the design intent, problems with the VG system on the CF-34 family of engines were not actually rare, and GE knew it.

◊◊◊

In 2018, a Bombardier Challenger with CF-34–3B engines operating as an over-the-sea search and rescue aircraft experienced a dual engine hung start that escalated into an internal investigation by General Electric. The manufacturer found that excessive pressure was required to operate the VG system due to extensive corrosion of the compressor case, spindle bores, and bushings, causing “multiple IGV and VG stator vanes [to become] stuck/seized in multiple stages.”[11:46] The resulting off-schedule condition prevented the engines from starting. GE determined that the corrosion damage was the result of saltwater contamination associated with the aircraft’s unique mission, which required it to operate at low altitudes over the ocean.[11:46]

In response to the incident, General Electric issued a series of service bulletins outlining special maintenance requirements for “engines that operate in saline environments,” which included “reduced VG system inspection intervals, reduced VG assembly servicing activities, addition of VG assembly lubricating procedures, and reduced waterwash intervals.”[11:47]

Water washes are a routine part of the maintenance process for any turbofan engine. Engines constantly suck in dirt and dust and salt and bugs and god only knows what else, so giving them a thorough wash every now and then is necessary to prevent residues from building up. It also happens that regular washes with fresh water will strip away salt deposits caused by salt water ingestion before corrosion can take hold. However, if the engines aren’t washed often enough, these residues become difficult to remove.[11:47–48]

Press enter or click to view image in full size

A Boeing 737 engine receiving a water wash. Photo: TheEluha on YouTube

The General Electric Service Manual for CF-34–3B engines recommended that operators conduct a water wash every 400 operating hours, but it also advised that this interval could be shortened or lengthened “depending on experience.”[11:47] After the 2018 incident, GE issued Service Bulletin 72–0000, which recommended a water wash interval no greater than 300 hours for aircraft operating in “harsh environments,” but General Electric’s definition of “harsh environments” applied to desert regions, not humid, coastal regions, and its intent appears to have been to address dust ingestion.[11:48] A 2021 revision to this service bulletin added a recommended water wash interval of 200 hours for engines operating in “sea/salt” environments or engines that display visible corrosion; however, the service bulletin specified that “sea/salt operations” meant flight in a salty environment at low altitudes, below 3,000 feet. The bulletin didn’t explain how long an aircraft had to fly within that envelope for the recommendation to apply, nor did it mention any risk to aircraft that were frequently parked at airports near saline environments but did not necessarily fly in them.[11:48–49]

For these reasons, and because the inciting incident involved a special operations aircraft with an unusual mission, Hop-a-Jet concluded that this service bulletin didn’t apply to their fleet. According to them, General Electric affirmed that interpretation by emphasizing that the bulletin was meant to be narrowly applied.[12:3] As a result, Hop-a-Jet continued to perform water washes at an interval that was based on in-service experience, presumably through engine performance trend monitoring. Maintenance records showed that between 2016 and 2024, N823KD’s engines were washed every 632 to 884 flight hours, which was much longer than GE’s recommendation, but was the interval that Hop-a-Jet had settled on based on the aforementioned criteria.[11:47, 51] This was not at all unusual among Challenger operators; in fact, a 2001 GE publication for CF-34 engine operators mentioned that many companies used a water wash interval of 800 to 1,000 hours, and records confirmed that, like Hop-a-Jet, Suzuki del Caribe had also tied its water washes to a scheduled 800-hour maintenance checkup.[11:52]

While these practices were normal in the industry and approved by General Electric, they were not consistent with the Federal Aviation Administration’s non-binding advisory circular concerning aircraft corrosion control. That guidance document recommended cleaning aircraft structures and engines every 15 days when operating in what the agency defined as “severe” corrosion environments — a definition that encompassed the entire Caribbean, including South Florida.[11:49–50] If this guidance had been followed, it’s unlikely that N823KD’s engines would have suffered from corrosion. However, when an operator chooses between general FAA guidance and a manufacturer’s guidance for their specific engine model, it makes sense to me that most would go with the latter. This may have been compounded by the fact that, as far as I can tell, the FAA advisory circular’s 15-day interval refers to general cleaning and not specifically to water washing the engines.

Press enter or click to view image in full size

FAA corrosion severity map from the advisory circular. Apparently the FAA doesn’t recognize the existence of Michigan. Source: FAA via NTSB

However, the 2018 incident that led to the new water wash guidance wasn’t the only case of VG system corrosion that had come to GE’s attention. In 2021, a Bombardier CRJ-1000 airliner powered by CF-34–8 engines experienced an in-flight engine shutdown caused by breakage of the VG actuator rod end due to corrosion.[16] The FAA subsequently issued an Airworthiness Directive (AD) mandating inspections of the VG actuator for any aircraft with CF-34–8 engines that had spent at least 250 days out of the preceding two years parked outdoors within 10 miles of a coastline.[17] (The implication appears to have been that accelerated corrosion took place while the aircraft was parked for a long period during the COVID-19 pandemic.) The FAA then followed this up with a second AD in 2022, following two separate events in which aircraft with CF-34–8 engines received “engine degraded” warning messages in flight. In both of those cases, the engines had been operated infrequently over the last two years and had accumulated corrosion on their compressor cases and VG stator vane bushings, resulting in increased vane actuation loads and an off-schedule VG system position. The AD called for a torque check of the VG actuating assembly to verify correct operation.[18] Had this AD applied to N823KD, the corroded VG system probably would have been discovered, but the directive only covered CF-34–8 engines that had recently been parked outdoors; it didn’t apply to CF-34–3B engines, so Hop-a-Jet was never notified.[12:3]

It’s worth mentioning that these are the cases of VG system corrosion that we know about. There could have been others and I wouldn’t know about them because they didn’t result in FAA action and the knowledge remains with GE and the operators involved.

Either way, it seems that corrosion of the VG system on the CF-34 family of engines may not have been confined to a handful of isolated incidents. The question of how much GE knew, when they knew it, and whether they should have done more to warn operators and improve maintenance procedures is now part of an ongoing lawsuit that I’ll discuss in more detail near the end of this article.

◊◊◊

Regardless of the above, regular inspections should have eventually caught the corrosion on N823KD’s engines, and the reason why they didn’t is a fascinating rabbit hole of its own.

In general, maintenance tasks required by the FAA are contained in an Airworthiness Limitations document applicable to a specific aircraft type and configuration.[13] In the case of N823KD, the Airworthiness Limitations stated that the engines must be maintained in accordance with Bombardier’s Time Limits/Maintenance Checks (TLMC) Manual and the GE Service Manual. The TLMC lists the tasks subject to Airworthiness Limitations, and it in turn refers to GE’s CF-34BJ (Business Jet) Turbofan Engine Maintenance Manual.[11:32] That business jet designation, as it turns out, is absolutely crucial to understanding why this accident was allowed to happen, so let’s dive into that a little deeper.

Most of the time, an engine manufacturer specifies a maximum Time Between Overhauls, or TBO, after which the engine must be overhauled, meaning stripped down to its subject components and put back together again, like new. If the TBO is specified in the Airworthiness Limitations, then overhauls are mandatory under the federal aviation regulations.[13] But in the case of N823KD, if we follow the trail all the way down to that GE CF-34BJ Engine Maintenance Manual, we will find that there is no TBO specified in it. Instead, this manual permits operators to maintain their engines according to a “Task-Oriented Maintenance Program” that explicitly does not require scheduled engine overhauls. Instead, N823KD’s engines were maintained “on-condition,” meaning that components were to be replaced, repaired, or overhauled based on their condition as observed during routine inspections rather than according to a predetermined whole-engine overhaul interval.[11:32] Under such a program, the engines might never be removed from the airplane or disassembled at any point during their entire service life, as long as the inspections continued to confirm the engines’ airworthiness.

Here’s where that business jet designation comes in. There isn’t actually any significant difference between a CF-34–3B engine installed on a business jet and a CF-34–3B engine installed on a commercial airplane, such as the CRJ 200, which uses the same engine model.[14] Instead, it’s a purely operational designation: the FAA defines a business jet as “a jet aircraft owned by a single or a group of individuals/corporations, and which is usually not operated in a schedule,” whereas the CRJ 200, for instance, is a regional jet, defined by the FAA as “a commercial jet aircraft carrying fewer than 100 passengers.”[11:32] However, because General Electric publishes separate Engine Maintenance Manuals for business jets and regional jets, the on-condition maintenance program option is able to be offered specifically for business jets, rather than for the CF-34–3B engine type as a whole. Commercial operators flying regional jets with CF-34–3B engines presumably do have to overhaul their engines on regular intervals because as far as I am aware that’s an Airworthiness Limitation for anything that gets to call itself a commercial airplane.

Anecdotally, this arrangement is very common in the business jet industry in the United States, and it appears to be US-specific. Petter Hornfeldt (the presenter over at Mentour Pilot, where I also work) told me that he recently attended a business jet owner/operator event in Europe, where he learned that many European business jet owners register their airplanes in the USA specifically because business jets there are not required to undergo regular engine overhauls, which can be very expensive.[15] So my interpretation is that other engine manufacturers who produce engines used on business jets probably offer similar task-oriented on-condition maintenance programs under their FAA-approved Airworthiness Limitations.

So, even though N823KD wasn’t receiving water washes often enough to prevent saltwater corrosion, such corrosion would have been caught and repaired at regular engine overhauls had the airplane been operated as a regional jet. But because it was a business jet, no overhauls were required, and none were performed. In fact, neither of N823KD’s engines had ever been removed from the airplane. By February 2024 they had been in service for 19 years and had spent every one of those years attached to the same airplane, in the same locations, under the same conditions, and they had exactly the same number of operating hours and cycles since new.[11:37] Consequently, the location, type, and degree of corrosion in both engines was near as makes no difference identical.[11:92–106]

Nevertheless, the regular inspections required under General Electric’s on-condition maintenance program should have revealed the presence of corrosion. GE recommended a borescope inspection of the compressor blades and VG stator vanes every 3,200 flight hours, but the procedure did not mention corrosion of the compressor case or the spindle bores nor did it specify how much corrosion, if any, was acceptable. The procedure noted that the condition of the compressor case could be estimated by checking stages 1, 6, 9, and 12; however this would not have included the area of stages 4–5, where most of the compressor case corrosion on N823KD was concentrated.[11:53]

Press enter or click to view image in full size

These documents certifying that the very components involved in the accident were free of defects are now Exhibit A in the post-accident lawsuit. Source: NTSB

The last borescope inspection of the compressor sections of N823KD’s engines was conducted just 357 hours before the accident flight, apparently by a third party vendor. This inspection failed to identify the corrosion in either engine.[11:54] There are several theories about why this might be the case; for instance, the Hop-a-Jet pilot who experienced the January 15, 2024 hung start event said during his NTSB interview that he had heard from “people at GE” that “it’s almost impossible to gain access [with a borescope] to where the guide vanes are because of the location.”[6:114] However, according to Hop-a-Jet itself, GE maintained an official position that the borescope inspections were never intended to identify corrosion at all. Hop-a-Jet believes that this position was post-accident ass-covering, because GE’s borescope inspection procedures identify corrosion as a defect subject to inspection; and furthermore, if the 3,200-hour borescope inspections weren’t supposed to look for corrosion, then there would be, as Hop-a-Jet put it, “no corrosion detection program … in place for these engines.”[12:3–4]

According to Hop-a-Jet’s submission to the NTSB evidence docket, after the accident they were able to view archived borescope imagery from an unspecified pre-accident borescope inspection, and the corrosion near the VG stages 4 and 5 bore holes was visible.[12:3–4] Hop-a-Jet says that this corrosion was “not identified or reported during pre-accident borescope inspections conducted by GE or GE-authorized vendors,”[12:3] and as if that wasn’t weird enough, the NTSB airworthiness group findings mention that a typical borescope inspection report would include attached imagery, but that for the report on the last inspection prior to the accident, the images were missing and could not be found.[11:54] Hop-a-Jet later filed a lawsuit against three companies involved in those inspections.[16]

No matter what exactly transpired during the final unsuccessful inspection, the result was that N823KD returned to service with the corrosion still unaddressed and with the compressor stability margins in both engines still compromised. The January 15th hung start event then occurred, but VG system corrosion was still not suggested by GE as a possible cause. The aircraft was then returned to service, but it would make it only three more weeks before disaster struck.

◊◊◊

As flight 823 cruised southward en route to Naples, there remained no indication that anything was wrong with its engines. The big, luxurious jet just hummed along as it always did, across the southeast US and into Florida, from cruise into the descent, as the pilots maneuvered through clear skies toward Naples Airport.

At 15:06 local time, Fort Myers Approach cleared flight 823 for a visual approach to runway 23 at Naples with a five mile final, and First Officer Ian Hoffman reported the field in sight. Descending toward 2,000 feet, they maneuvered onto the downwind leg, heading opposite to the approach direction, anticipating an imminent right turn onto the base leg and final approach. While Captain Ed Murphy handled the controls, the pilots configured the airplane to bleed off speed, extending the flaps to 20 degrees and then 30.[19:25–26] Each time they extended the flaps, the pilots selected a lower target airspeed, and the autothrottle[11:84] responded by decreasing thrust, followed by a re-acceleration sometime later as the plane approached the target airspeed.[21:6–7]

Press enter or click to view image in full size

ADS-B data from FlightAware shows the downwind leg, base turn, base leg, and turn onto final undertaken by flight 823. The end of the green line represents the end of reliable data; the white line was wishful thinking on the part of FlightAware’s path prediction algorithm. Source: FlightAware

At 15:08, Captain Murphy called for gear down, and the cockpit voice recorder captured the sound of the landing gear extending. Engine power increased audibly to compensate for the extra drag. Murphy confirmed that the landing gear was down and all three gear indicators were showing green, while Fort Myers approach instructed Hoffman to contact Naples Tower on 128.5. He immediately switched the frequency over and announced that he was on a right downwind for runway 23, at which point Naples Tower cleared flight 823 to land. In the background, the engines could be heard rolling back down again as Murphy steered the plane onto the base leg.[19:27]

At 15:09 and 1 second, Murphy announced that he was visual with the runway, which was off to his right and just under 7 miles away. Moments later, at about 15:09 and 14 seconds, the flight data recorder captured another decrease in thrust, consistent with the thrust levers being moved to idle[20:4–5] as the aircraft straightened out from the base turn and accelerated slightly above the target airspeed of 160 knots.[21:7] It was not at all obvious that disaster was now only eight seconds away.

Hoffman continued running through the landing checklist, and with the runway in sight, Murphy disconnected the autopilot and began flying manually as he eyeballed the turn onto final. “Landing flaps,” he ordered.

Hoffman moved the flap lever to 45 degrees, the landing position, and both pilots confirmed landing flaps.[19:29] At around that same time, at 15:09 and 22 seconds, the airspeed fell back to the target 160 knots, and the autothrottle commanded an increase in thrust.[21:7] In response, the compressor speed (N2) in both engines initially began to increase from a minimum of about 63% (barely above idle) to a value of about 65%. But then, just one second after the command to increase thrust, the acceleration trend suddenly reversed, and both engines began to roll back.[1:1]

An analysis of 56 previous flights captured on N823KD’s flight data recorder revealed that this particular sequence of deceleration and re-acceleration, spaced over 8 seconds, was subtly different from any other similar sequence captured in the archival data. The event deceleration was slightly quicker over the entire speed range of the deceleration (from the initial speed to final speed), and then the acceleration was initiated before the engine had fully stabilized at idle.[20:4]

Press enter or click to view image in full size

Data from flight 823 shows the fast deceleration, failure to stabilize at idle, brief re-acceleration, and total collapse of the compressor balance. N2 = compressor rotor speed. Source: General Electric via NTSB

At that point, with the compressor approaching idle, the IGVs and VG stator vanes should have been fully closed, but they were not. Therefore, too much air was being allowed into the compressor and the blade angle of attack was too high. Subsequently, the command to re-accelerate came before the compressor’s thermal state had time to cool down from its previous higher power setting, effectively mimicking the conditions of a heat soak start. The extra heat also caused the compressor to re-accelerate faster than in other recorded events. All three of these factors tended to increase the operating line or reduce the stability limit line; either way, decreasing the available stability margin. Nothing about the event deceleration and re-acceleration was outside the engine’s operating envelope,[20:4] but because the corroded VG system had latently reduced the stability margin whenever the engines operated at low power, it was just enough to push both engines over the edge. Furthermore, because the damage in both engines was almost identical and their transient performance during the event was, per GE, “remarkably well matched,”[20:4] this same process occurred in both engines simultaneously.

When the operating line overtook the stability limit line, the compressor blades in both engines started to stall, the air mass flow rates collapsed, the turbines spooled down, and the engines decelerated rapidly before finally stabilizing in a sub-idle state.[1:14] From that point onward they would generate no useful thrust, and the only way to regain power would have been to shut the engines off, allow the compressors to stabilize, and then attempt the full relight procedure. However, with the dual engine failure taking place at just 1,800 feet, it would have been impossible to recover thrust before hitting the ground.[1:2]

Initially, the pilots didn’t react to the strange engine behavior, because the autothrottle was still engaged and they were focused on the landing checklist, confirming again that the gear was down and all the indicators were green.[19:30] But after about ten seconds, the engines spooled back to the point that they could no longer power the engine-driven oil pumps, triggering left and right engine oil pressure warnings about one second apart. The master warning light immediately illuminated, a triple chime sounded, red ENGINE OIL warning messages appeared on the Engine Indicating and Crew Alerting System (EICAS) display, and an automated voice called out “engine oil!”[1:5]

Captain Murphy glanced down at his engine instruments and exclaimed, “What the hell, what — oh, right engine just quit!”

“Looks like,” Hoffman agreed.

As the master warning continued to chirp, Murphy said, “It’s overtemp.”[19:30–31] At this point, with the mass flow rate drastically reduced but the thrust levers still positioned forward, feeding more and more fuel into the engine, the internal temperature continuously increased[1:1–2] past redline levels.

“Say again?” Hoffman asked.

“Overtemp, overtemp,” Murphy repeated.

“#, all right, all right,” Hoffman cursed. Then he said, “Uh, no engines, huh? Okay, we’re gonna have to land.” It was the first indication that either pilot recognized a dual engine failure.

“Declare an emergency,” Murphy ordered.

“I am,” said Hoffman, jumping on the radio to report, “Okay, uh Challenger uh, Hop-a-Jet eight two three…”

“Lost both engines,” Murphy said.

“…Lost both engines, emergency, I’m making an emergency landing,” Hoffman finished.

The First Officer was already looking out the window, scanning for a place to make a forced landing. With the runway still six miles away and the airplane rapidly losing altitude, it was obvious that they wouldn’t make it. After a few seconds he spotted some kind of lake or canal and called out, “There’s water right there.”

The tail end of a radio transmission from the tower emerged out of a moment of interference: “…emergency, clear to land runway two three, is that Hop-a-Jet eight two three?”

“Eh, we’re clear to land, but we’re not gonna make the runway, we’ve lost both engines,” Hoffman replied.[19:31–32]

Without engine thrust, the Challenger’s speed dropped quickly, and if Murphy didn’t intervene, the airplane would stall. With no other choice, he pitched forward to sacrifice altitude for airspeed, and the rate of deceleration slowed. But now they were descending at 1,500 feet per minute with just 60 seconds to impact.[1:14] There would be no time for indecision.

◊◊◊

As this emergency unfolded, cabin attendant Sydney Bosmans was sitting in the cockpit jump seat, as she always did during landing, per company policy.[9:16, 55] When the engines rolled back, she heard the alarms, saw the red text on the EICAS display, and noticed some engine instruments spooling down, so she knew immediately that some kind of engine malfunction had occurred. Then when she heard the pilots discuss losing both engines, she realized that a crash landing was all but certain — so she leaned forward and twice asked, “Should I prepare the cabin?”[9:17–18][19:33]

Captain Murphy didn’t have time to respond in detail, so he just said “brace for impact.”

“Okay, hey, let me take over, land in this water,” Hoffman suggested.

“Negative, I’m landing right here,” Murphy said, his voice suddenly accompanied by the ominous rattle of the stick shaker, warning that they were flying too slowly and were at risk of stalling.

“Where?” Hoffman asked.

“Straight ahead, on the r — on the # runway,” said Murphy.

“What!?” said Hoffman. “We’re not gonna make the runway!”[19:33]

In hindsight, I’m not quite sure what to make of this conversation. It seems unlikely to me that Murphy really thought he could make the runway because it would have been obvious by this point that they were sinking too fast. In fact, later comments suggest he was not talking about the runway at all, but under intense stress, he simply misspoke.

While the pilots discussed where to land, Bosmans realized that they didn’t have time to give her instructions, and she was on her own. At that point, her voluntary safety training from Aircare International kicked in. She remembered that during an emergency landing, she was supposed to sit in the left forward aft-facing seat in the cabin, because it provided better protection against impact forces than the cockpit jump seat, and it would be easier to see out the windows. So in a split second decision that would end up having huge consequences, she got up out of the jump seat, went into the cabin, and strapped herself into one of the aft-facing seats, next to Ms. Green and across from Mr. Baker.[9:74–75]

Acting quickly, she told the passengers that both engines had failed and that they needed to put on their seat belts and get into the brace position.[8:16] For the passengers, this was probably the first indication they had that something was wrong, because even in a sub-idle state the engine noise still would have been audible. So Baker was shocked to hear that both engines had failed, and he initially asked Bosmans if she was serious, but she affirmed that she was, and began demonstrating the brace position.[9:75]

Up in the cockpit, the enhanced ground proximity warning system (EGPWS) burst into life, calling out “SINK RATE” as the plane descended in excess of 1,500 feet per minute. Still trying to articulate his plans, Captain Murphy said, “Not the runway, the # run — ”

“FIVE HUNDRED,” called out the EGPWS. “SINK RATE!”

“No, no the road’s got traffic on it, man,” Hoffman protested.[19:34]

This exchange is what leads me to believe that Murphy never intended to say that he would try for the runway. The fact that he immediately said “not the runway” but then started to say the word “runway” again anyway is what tells me that he was misspeaking while under stress. Furthermore, Hoffman’s reply about a road shows that Murphy likely gave up trying to verbally articulate his plan and might have simply pointed out the window at his intended landing site.

Press enter or click to view image in full size

Overview of the extremely tricky maneuver that Captain Ed Murphy now had to attempt. It cannot be overemphasized how difficult a landing this was. Source: Own annotations on Google Earth

That landing site was Interstate highway 75, which runs south from Fort Myers and into the eastern suburbs of Naples before turning east through the Everglades toward Fort Lauderdale. With three traffic lanes in each direction, a wide grass median, and grass verges on both sides, it was the closest thing to a runway in their projected impact area, which otherwise consisted mostly of forested suburban neighborhoods, golf courses, and canals. However, landing on it would not be straightforward. As Hoffman pointed out, the interstate was not devoid of traffic, and to make matters worse, it was oriented at a 45-degree angle to their flight path, necessitating a last second turn to align with it.

Hoffman might not have thought they had enough time, as he exclaimed, “It’s too late for the — ah #, okay Lord…”

“TOO LOW, TERRAIN,” the EGPWS blared.

Murphy began maneuvering into a left turn to line up with the interstate, his attention completely focused on the monumental task in front of him. In that moment more than any other, he flew the airplane.

Still the EGPWS started to call out “SINK — ” then overrode it with an even more dire “TERRAIN, TERRAIN!”

“A hundred and ten knots,” Hoffman warned. The stick shaker activated intermittently as the plane slowed dangerously below its normal approach speed. “This # airplane…” he muttered, cursing whatever mechanical fault had plunged them into peril.

“PULL UP,” the EGPWS announced.

“Land in the grass,” Hoffman suggested, presumably referring to the freeway median.

“PULL UP!” The stick shaker was rattling continuously now, filling the cockpit with the sound of imminent danger, backing the frantic callouts from the EGPWS and the sound of the pilots’ own heavy, adrenaline-fueled breathing. Seconds later, a loud stall warbler alarm joined that terrifying orchestra, echoing in the pilots’ ears as Murphy rounded the corner and brought the plane in low over I-75.[19:35–36]

Landing a plane as large as the Challenger 604 on a highway is extremely difficult, due to the high probability of striking obstacles such as vehicles, highway signs, guard rails, telephone poles, gantries, sound barriers, and trees. Highways are typically much narrower than runways and the objects surrounding them are not necessarily designed to give way in a collision, as objects near runways are. Historically, emergency landings of large airplanes on highways have not ended well, and to my knowledge nothing the size of a Challenger had even attempted it for many years prior to 2024. (If you know of any cases, please let me know in the comments.) No matter how you slice it, the task facing Ed Murphy and Ian Hoffman was an unenviable one with a high probability of injury or death.

As flight 823 streaked over the freeway, still in a left bank, Bosmans concluded that impact was imminent and began shouting “Brace, brace, brace, brace, brace!”

In the cockpit, the EGPWS again called out “PULL UP,” Hoffman said “Alright,” and then the crash began.[19:36]

Dashcam video of the crash shared by WKYC Channel 3.

At 15:10 and 46 seconds, flight 823 touched down in the southbound lanes of Interstate 75, traveling at a speed of 110 knots (about 203 km/h) and banked 15 degrees to the left. There had not been enough time for Murphy to level out, and when the left main gear hit the pavement, the plane’s vector of motion was still considerably offset from the axis of the road. Traffic was heavy, and with little control over their exact impact point and no way to warn the vehicles ahead, the way was not clear. Catastrophe became almost inevitable from the moment of touchdown.

As the EGPWS continued to call out “PULL UP,” the Challenger slewed to the right across the traffic lanes, overtaking vehicles from behind. The left wingtip impacted a pickup truck, sending it careening across all three lanes and then back into the median, while a second car was hit and damaged in the chaos. The plane then continued off the pavement and onto the grass verge, where the right wing hit a non-frangible steel highway sign, rupturing the fuel tanks. Spilled fuel ignited into a curtain of flame as the plane pivoted about its damaged right wing, causing the jet to slam nose first into the concrete sound barrier wall separating the interstate from an adjacent neighborhood.[22] The impact instantly killed First Officer Hoffman,[1:15] but the plane continued to move, ricocheting off the wall and spinning around 180 degrees, sliding backward across the grass with its nose pointing back the way it had come, until it finally skidded to a halt around 300 meters from the point of first touchdown.[11:58–60]

Press enter or click to view image in full size

The following four annotated photographs assembled by the NTSB tell the story of the crash sequence far better than I can.

Press enter or click to view image in full size

Press enter or click to view image in full size

Press enter or click to view image in full size

(Source: NTSB)

It’s likely that the cockpit was almost entirely ablaze from the moment the plane came to a stop, and possibly even earlier; footage of the crash isn’t clear enough to tell, but it is known that Captain Murphy died due to inhalation of superheated gases,[1:15] indicating that the fire claimed his life very quickly. However, for those in the passenger cabin, a narrow window for survival existed.

Cabin attendant Sydney Bosmans had her eyes closed during the crash and saw none of it, but she recalled hearing and feeling objects being thrown about the cabin, thinking to herself, “I hope nothing hits me.”[9:76] Fortunately, nothing did, and when the plane came to a stop all three occupants of the passenger cabin were still alive with only minor injuries. However, fire was billowing up all around the airplane, and Bosmans could see that the cabin was quickly filling with toxic black smoke. Her training had taught her that the smoke alone would kill them if they didn’t escape quickly, so she immediately got up out of her seat, went to the forward passenger door, and attempted to open it — but the door was jammed and wouldn’t move. Thinking quickly, she went for the overwing exit, where she saw that someone had already ripped the cover panel off, as though trying to access the door opening mechanism; she thought maybe one of the passengers had already tried to open it. But when she tried to pull that door open, it wouldn’t budge either,[9:77] presumably because the fuselage had warped during the crash and was jamming it shut. Bosmans later stated that it was a good thing that exit didn’t open, because she saw “neon flames” shooting up just outside the window, meaning the exit wouldn’t have presented a viable escape route.[9:76–77]

With both of the normal emergency exits jammed, Bosmans knew that there was only one other way out: through the baggage door in the lower aft part of the cabin. The baggage door was normally used to load passenger bags on the ground, and Bosmans had never been specifically trained on its use, but she was familiar with how it worked because she sometimes voluntarily helped pilots load baggage through it.[9:29–30] It was now their only hope.

By that point, having observed Bosmans trying and failing to open the other exits, Baker went back to the baggage door himself,[8:24] but, not being familiar with the door, he was unable to open it. Green shouted to Bosmans for help, and the cabin attendant came rushing to the back, moved Baker out of her way, and tried to open the door herself. Dense, black smoke had filled the cabin now, reducing visibility to near zero, but thanks to her knowledge of the door, Bosmans was able to grab the handle and turn it in the correct direction while working almost blind. But when she tried to pull the unlatched door inward to open it, it wouldn’t move, because fallen baggage or other items were in the way. Desperate, she shouted for a flashlight or a cell phone light, but nobody had one.[9:77–78]

With the window of survival closing, all the while inhaling more of the noxious fumes with each passing second, the cabin attendant and the passengers scrambled to move the fallen items, until finally they had cleared enough of a path for Bosmans to force the door open. Without hesitation, she jumped through the yawning portal, over licking tongues of flame, and back into the world of the living. Standing on the grass beside the plane, she turned and saw Baker jump out a few seconds later, followed by Green, who scrambled down with Baker’s assistance. Bosmans called for them to stick together, and with the passengers at her side, they ran away from the burning plane, scarcely able to believe that they had survived.[9:78–79]

Press enter or click to view image in full size

This still image from a cell phone video shows the cabin attendant and two passengers walking away from the airplane seconds after jumping to safety. Photo: WGCU

Emergency services had yet to arrive at that point, and bewildered motorists had stopped all along the road, some of whom ran to help; others simply stood and filmed; some did both. A huge column of smoke towered over the interstate; burning wreckage lay strewn for hundreds of meters; the crushed pickup truck sat in the median like a piece of crumpled paper, its shocked but only lightly injured driver sitting on the ground beside the remains of what had moments earlier been his vehicle.[9:24–26] For a few minutes, chaos continued to envelop that unremarkable stretch of I-75, until police, firefighters, and paramedics arrived and locked down the scene.

In the end, the two passengers, the cabin attendant, and the driver of the pickup truck were transported to hospital and treated for minor injuries.[1:1] The miracle of their survival was nevertheless tempered by the loss of the two pilots, who flew their stricken plane all the way to the crash site to save the lives of their passengers and crew. In the words of the old aviator’s eulogy, may they find blue skies and tailwinds.

Press enter or click to view image in full size

Fire eventually consumed most of the jet, except for the wingtips and tail. Photo: Chris O’Conner

◊◊◊

In the immediate aftermath of the accident, a number of theories were put forward to explain how both engines on a business jet could have failed simultaneously during final approach. However, most were ruled out quickly. Fuel exhaustion was eliminated right away; after all, the fire alone was proof that there was plenty of fuel on board, and the National Transportation Safety Board swiftly confirmed this. The flight data recorder confirmed that that fuel was reaching the engines, too, because the engines never shut down or flamed out and measurable fuel flow continued.[21:8] Examination of the engines also revealed no evidence of bird strike or ingestion of any other foreign objects, and there was no precipitation that could have affected the engines’ operation at the time of the accident.

Another theory held that if the captain reached across the center console to extend the flaps, while the first officer simultaneously moved the thrust levers back toward idle, the captain’s arm could contact and lift the guard triggers that normally prevent the thrust levers from being moved below idle and into the sub-idle range or even the fuel shutoff position. However, this was also ruled out because the recorded engine behavior was not consistent with thrust lever movement below the idle gate,[11:90] and an accidental fuel shutoff was ruled out by the presence of fuel flow.

The uncertainty over what had happened to their colleagues left Hop-a-Jet pilots anxious and spooked. In his interview with the NTSB, the Hop-a-Jet pilot who experienced the January 15th hung start event described colleagues who were afraid to put the thrust levers into the idle detent for fear that the same mysterious failure would happen again.[6:108] According to the transcript, he practically pleaded with the investigators to find the cause: “There has to be something conclusive, because I have so many people in the industry, friends that fly the planes, they want to know,” he said.[6:111] He didn’t know what caused the hung starts either, but in his gut he knew they had to be related. “I’ll take this to my grave,” he said. “I firmly believe whatever happened to me on the ground [during] start [is] what happened to those two engines again. And, unfortunately, it was in flight.”[6:106–107] In the end he would turn out to be right.

As I have already explained, the NTSB eventually determined that the dual engine failure was the result of symmetrical corrosion of both engines’ VG systems, leading to an off-schedule condition that eroded the compressor stability margin, which led to compressor stalls and rollback to a sub-idle state during a maneuver that demanded a slightly greater compressor margin than previous maneuvers. That conclusion was not obvious and came as a surprise to many. In fact, as far as I am aware, and as far as anyone I have spoken to is aware, this may be the first time in history that anything like this has ever happened. It had been widely held that the likelihood of both engines on a twin-engine jet failing at the exact same time due to mechanical faults within each individual engine was so low as to represent a practical impossibility. This accident demonstrates that that logic doesn’t always hold if the engines are operated identically throughout their entire service lives without ever being overhauled or otherwise removed from the airplane, permitting the development of common faults due to environmental degradation. This was not a possibility that had been widely considered until the NTSB published its findings and probable cause in April 2026.

Press enter or click to view image in full size

Interstate 75 was shut down in both directions while emergency services worked the scene. The destroyed pickup truck can be seen at center right. Photo: Andrew West/The News-Press

Tempting as it would be to call this accident a wildly improbable fluke, such a characterization would be misleading. Many of the factors that led to the accident were systemic throughout the business jet industry and could have led to additional accidents if left unaddressed. Underscoring this fact, in May 2024 seven CF-34–3B engines that had previously experienced hung starts failed a one-time functional check of the VG system conducted in response to an urgent GE service bulletin. Four of those engines belonged to Hop-a-Jet, but three came from other operators.[1:19–20] Later that same month, GE issued another service bulletin prescribing a borescope inspection of the compressor case in the vicinity of VG stage 5 on all CF-34–3B engines; out of 1,085 engines examined as of March 2026, one failed the check and was removed from service.[1:20]

In February 2026, GE issued another service bulletin clarifying the applicability of special sea/salt environment procedures for business jets,[1:20][11:124] and the company plans to add 48-month VG system functional checks into the CF-34–3B’s Airworthiness Limitations.[1:20] The hung start troubleshooting procedure was also revised so that Maintenance Practice 68, the VG system functional check, is now one of the first tasks to be performed.[1:20] Separately, Hop-a-Jet reverse engineered the tooling that GE uses to perform Maintenance Practice 68 so that they can do it themselves.[23]

In September 2025, Hop-a-Jet and its subsidiaries filed a class action lawsuit against General Electric, Bombardier, Learjet, Turbine Engine Specialist Inc., and Duncan Aviation, alleging that problems with VG system corrosion were systemic on the CF-34 family of engines; that the VG systems were difficult to access and inspection procedures were inadequate; and that GE was aware of the issue but “took efforts to cover it up by hiding incriminating evidence.”[16] In fact, Hop-a-Jet claims that instead of warning operators about the corrosion risks, GE instead “limit[ed] corrosion coverage in its service contracts.”[7] The lawsuit also alleges that the latter three defendants failed to identify the corrosion in N823KD’s engines during regular borescope inspections.[16] The outcome of the case is yet to be determined.

In an email statement, a General Electric spokesman wrote, “We extend our deepest sympathies to the families and loved ones of those who lost their lives in this accident. We fully supported the NTSB’s investigation and appreciate the rigor they bring to strengthening safety across the industry. Safety remains our top priority, and we are committed to ensuring operators and maintainers have the clearest possible guidance on inspection and maintenance practices.”

◊◊◊

When the NTSB published its final report on the crash of flight 823, it did not issue any safety recommendations, which came as a surprise to Hop-a-Jet’s president. In his view, further action still needs to be taken, including issuance of an FAA Airworthiness Directive to mandate compliance with GE’s service bulletins.[23] Hop-a-Jet is also concerned about a lack of clarity in the Aircraft Flight Manual, the Quick Reference Handbook, and the Operating Manual concerning the difference between a hung start and a slow start (where the engine eventually spools up after a longer than normal period). This ambiguity could lead pilots to misidentify a hung start as a slow start, causing them to restart the engine and carry on without notifying maintenance. Such a mistake could prevent degradation of the VG system from being discovered in a timely manner.[12:5]

Another safety issue that I’m surprised hasn’t received more attention is the exemption that allows business jets to operate without overhauling their engines. Because many business jets use engine models that are also used by commercial aircraft, the lack of an overhaul requirement for one group of aircraft but not the other strikes me as arbitrary. I presume that business jet operators are happy with this arrangement because it reduces costs, but I have to imagine that after this accident, their clients might be less satisfied to discover that the opulent aircraft that carry them around the globe in relative luxury are powered by engines maintained to a lower standard than the ones that propel the Frontier A320s into which the rest of us pack like sardines.

However, the safety gap that I find most compelling is the lack of any required safety training for business jet cabin attendants. Sydney Bosmans was able to save her own life and the lives of her passengers because she had voluntarily acquired safety training that gave her the presence of mind to leave the cockpit, where she would surely have been killed in the crash;[11:74–75] give the passengers timely instructions; and open the exit door that provided their path to salvation. Had she treated herself as a glorified barista, everyone on board probably would have been killed. It’s to her credit that she saw herself as more than that, going above and beyond the call of duty to ensure that she was prepared, but the training that she underwent is still not a requirement to hold the job, and she had to pay for it out of pocket.[24]

Press enter or click to view image in full size

Sydney Bosmans speaks at her NBAA award ceremony. Photo: Jessica Reed

In October 2024, Ms. Bosmans was honored with the National Business Aviation Association’s Above and Beyond Award for Heroic Achievement in recognition of her actions in the line of duty. She used her acceptance speech to talk about the accident, the trauma she suffered in the weeks and months after, and the lives of the pilots who gave everything for her to be there, but she also leveraged her experience to advocate for mandatory cabin attendant safety training.[25] “I see a day where there’s no such thing as a cabin server with no safety functions,” she told the award ceremony audience. “This entire business of aviation is based on a first-class, high touch experience. So why are you comfortable with not providing safety on a first-class level?”[24]

Normally I would end with a conclusion harking back to those harrowing minutes over Naples and the unique sequence of events that made them possible, and I would wax on about the bravery that was displayed that day, both by those whose survived and those who did not. But I have already done that, and I would rather give Sydney the last word.

“This is not just for my pilots and passengers; this is for the entire flight attendant community. I love you all.”

— Sydney Bosmans, 2024[25]

________________________________________________________________

A massive thank you to all my readers, and especially my supporters on Patreon, whose contributions are crucial to my ability to produce stories like this one. If you give back for the content I freely distribute, my gratitude to you will be immense.

________________________________________________________________

>>>Bibliography<<<

Join the discussion of this article on r/AdmiralCloudberg!

Support me on Patreon (Note: I do not earn money from views on Medium!)

Follow me on Bluesky for regular article updates, accident news, and (occasionally) random thoughts that somehow make it out of my brain and onto the internet.

— Kyra Dempsey / Admiral Cloudberg