Advertisement

Cyberattack causes a flight delay? Airlines won’t owe you a hotel or meal

A Department of Transportation rule published last week says that airlines complying with cybersecurity regulations will have reduced customer obligations in the event of an attack.
Listen to this article
0:00
Learn more. This feature uses an automated voice, which may result in occasional errors in pronunciation, tone, or sentiment.
Lonely child sitting on a suitcase and waiting for departure at the airport looking at the arrivals board. (Getty Images)

Beginning next month, if a flight is canceled or delayed because of a cyberattack, feds will give airlines clearance not to hand out meal vouchers or hotels.

The change is the result of a broader rule the Transportation Department published last week that establishes a new “cause of delay” category for tracking information, but that also reduces air carrier responsibilities to customers for 10 kinds of events. Among them: “cybersecurity attacks (provided that the air carrier is in compliance with applicable cybersecurity regulations).”

The 10 events, including those cyberattacks, are deemed “not controllable,” meaning that “carriers are no longer obligated under [customer service] plans to provide amenities or compensation when disruptions arise from these specific causes,” as Sophie Hayashi, counsel at Crowell & Moring in the transpiration group, wrote in a client alert.

Those airline-authored customer service plans aren’t legally binding, although DOT has maintained it will hold airlines “accountable” for their pledges.

Advertisement

One airline consumer advocacy organization, FlyersRights, was skeptical of the change, saying it came without giving the public a chance to comment and that it would be monitoring the impact on airline customers and tracking any reduction in amenities. 

Specifically, “cybersecurity is an airline responsibility, so if a flight is delayed or cancelled it should be clear that the delay was not due to carrier neglect, as cyberattacks are constant,” Paul Hudson, president of the group, told CyberScoop. “We have previously urged stress tests for airline computer systems that are going down often.”

Another group, the National Consumers League, had a more mixed view about the rule’s effects on flyers. On one hand, it could be good for them, said John Breyault, vice president of public policy for the group.

‘What we appreciated about this being put into a rule was that it gave consumers certainty that regardless of which airline they were flying, they would know that they have certain rights, and they weren’t beholden to the whims of the airlines who may or may not decide to provide them with a hotel if there’s a delay or cancelation,” he said.

On the other, though, “it’s clear to us that the DOT seems inclined to try and make the rules a little less onerous for the for the airline industry,” Breyault said, and in particular was worried about how airlines could potentially abuse the ambiguity related to one of the 10 events, “unscheduled maintenance,” to find a way to avoid compensating consumers.

Advertisement

The provision might still protect consumers because of its condition on compliance with applicable cybersecurity regulations, Breyault said. Carriers who can’t demonstrate compliance will be subject to customer and other requirements, Hayashi said.

“The final rule’s language regarding applicable cybersecurity regulations is notably broad,” said Kate Growley, partner at Crowell & Moring. “This may have been deliberate to account for the unpredictable nature of cybersecurity attacks. Different regulations may apply depending on the exact circumstances of the attack, such as what information or operational capabilities were affected.”

There’s no formal accounting of how often cyberattacks have caused delays or cancellations that then prompted airlines to provide meal vouchers or hotels. Hackers have targeted airlines and flights before, such as Scattered Spider’s attacks last summer.

Cyberattacks have caused flying delays and cancellations, although sometimes those attacks have been aimed at third parties, such as in last year’s attack on Collins Aerospace led to delays in Europe. Attackers also have targeted other elements of the aviation sector. The 2024 IT outage related to the cybersecurity company CrowdStrike that grounded flights wasn’t a cyberattack, but did lead to airlines providing some compensation to travelers; the Transportation Department determined that incident was within airlines’ control.

The Biden administration notably imposed cybersecurity regulations on airports, aircraft owners and aircraft operators in 2023 due to “persistent cybersecurity threats” in the sector. 

Advertisement

The newly-published Department of Transportation (DOT) rule stems from a Federal Aviation Administration authorization law that President Joe Biden signed in 2024. 

“Congress explicitly directed DOT in the FAA Reauthorization Act of 2024 to make these changes,” a Department of Transportation spokesperson said. “These 10 specific types of flight disruptions will now … be tracked in a brand-new reporting category to ensure government delay data accurately reflects what airlines can and cannot control.”

The Aviation Information Sharing Analysis Center said it appreciated the elements of the rule related to reporting incidents.

“The Aviation ISAC supports efforts to simplify and harmonize cybersecurity reporting across numerous government agencies,” said Jeff Troy, president and CEO of the organization. “This rule is a move in the right direction.”

Hayashi told CyberScoop the rule change looks to be positive for both airlines — because of the clarity it provides them about disruptions not under their control — and consumers.

Advertisement

“This actually is beneficial for everyone, and particularly consumers, because it makes it clear if you’re looking at airlines delay and cancellation rates, this is going to give you the most accurate picture of carrier delays,” she said.

Latest Podcasts