As of next month, if your flight is canceled or delayed due to a cyberattack, you may not be entitled to meal vouchers or hotel accommodations from the airline. This change stems from a new rule published by the Transportation Department last week, which establishes a “cause of delay” category for tracking information and reduces airlines’ responsibilities to customers in 10 specific circumstances, including cybersecurity attacks.
The rule is part of a broader effort to modernize how airlines handle customer service plans and compensation in cases of flight disruptions. Under the new rule, carriers are no longer obligated to provide amenities or compensation when disruptions arise from “not controllable” causes, such as cyberattacks, provided they are in compliance with applicable cybersecurity regulations. This means that if an airline can prove it was hacked by a third-party attack and had adequate security measures in place, it won’t be held responsible for providing hotel rooms or meal vouchers to affected passengers.
Critics of the new rule, including FlyersRights, an airline consumer advocacy organization, argue that it undermines the airline’s responsibility to protect against cyber threats. Paul Hudson, president of FlyersRights, told CyberNews.work that cybersecurity is an airline’s responsibility and that if a flight is delayed or canceled due to a cyberattack, it should be clear that the delay was not due to carrier neglect. “Cyberattacks are constant,” he said, “and airlines need to take proactive measures to protect against them.”
On the other hand, some experts see the new rule as providing clarity and certainty for consumers. John Breyault, vice president of public policy at the National Consumers League, noted that the rule gives passengers a clear understanding of their rights and reduces the ambiguity surrounding airline customer service plans. However, he also expressed concern that airlines could potentially abuse the provision related to “unscheduled maintenance” to avoid compensating consumers.
The new rule may not be as straightforward as it seems, however. The condition on compliance with applicable cybersecurity regulations is notably broad, which may have been deliberate to account for the unpredictable nature of cybersecurity attacks. As Kate Growley, partner at Crowell & Moring, pointed out, “different regulations may apply depending on the exact circumstances of the attack.”
While there’s no formal accounting of how often cyberattacks have caused delays or cancellations that then prompted airlines to provide meal vouchers or hotels, hackers have targeted airlines and flights before. In fact, some attacks have been aimed at third-party companies, such as Collins Aerospace, which led to delays in Europe.
The new rule stems from a Federal Aviation Administration authorization law signed by President Joe Biden in 2024, which explicitly directed the Transportation Department to make these changes. As cybersecurity threats continue to plague the aviation sector, it’s worth noting that the Biden administration imposed cybersecurity regulations on airports, aircraft owners, and operators last year due to “persistent cybersecurity threats” in the sector.
In practical terms, this new rule means that if your flight is canceled or delayed due to a cyberattack, you should ask the airline for documentation of their compliance with applicable cybersecurity regulations. If they can demonstrate that they were hacked by a third-party attack and had adequate security measures in place, it’s likely they won’t be held responsible for providing hotel rooms or meal vouchers. As always, staying informed about your rights as a passenger is key to navigating these complex issues.
Source: CyberScoop — 2026-09-11