CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Cyberattack causes a flight delay? Airlines won’t owe you a hotel or meal

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 7128

As cited

Copy frozen at (site build).

regulatory

Cyberattack causes a flight delay? Airlines won’t owe you a hotel or meal

The U.S. Department of Transportation published a rule that classifies cyberattacks as one of ten "not controllable" causes of flight delays and cancellations, exempting airlines from providing meal vouchers or hotel compensation when such incidents occur (provided the carrier complies with cybersecurity regulations). The rule, which takes effect next month, stems from the Federal Aviation Administration Reauthorization Act of 2024 and establishes a new reporting category to distinguish between disruptions within and outside carrier control. Consumer advocacy groups expressed mixed views, with some questioning whether airlines might exploit ambiguities in the rule to avoid compensation, while others noted the clarity it provides to travelers regarding their rights across carriers.

Why it matters: Airline customers and compliance officers need to know that cyberattacks causing flight disruptions may no longer trigger automatic meal and hotel reimbursements, though airlines must demonstrate compliance with cybersecurity regulations to invoke this exemption; non-compliance could restore customer service obligations.

VendorsCrowdStrike
Actorsscattered spider
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary