As airlines continue to navigate the challenges of cybersecurity threats, passengers may soon find themselves without a safety net when flights are delayed or canceled due to cyberattacks. Starting next month, the US Department of Transportation (DOT) will give airlines clearance to not provide meal vouchers or hotel accommodations in such cases, provided they can demonstrate compliance with applicable cybersecurity regulations.
This change is part of a broader rule published last week that establishes new categories for tracking information and reduces air carrier responsibilities to customers for 10 types of events. Cybersecurity attacks are among these events, which the DOT has deemed “not controllable.” This means that airlines will no longer be obligated under customer service plans to provide amenities or compensation when disruptions arise from these specific causes.
The rule is the result of a Federal Aviation Administration authorization law signed by President Joe Biden in 2024, which directed the DOT to make changes. Airlines have long been expected to take steps to prevent cyberattacks, and this new rule reflects that expectation. In fact, the Biden administration imposed cybersecurity regulations on airports, aircraft owners, and operators in 2023 due to “persistent cybersecurity threats” in the sector.
The change has sparked debate among consumer advocacy groups. FlyersRights, an organization that advocates for airline consumers, is skeptical of the rule, arguing that it gives airlines too much leeway without sufficient public input. “Cybersecurity is an airline responsibility,” said Paul Hudson, president of FlyersRights. “If a flight is delayed or canceled due to a cyberattack, it should be clear that the delay was not due to carrier neglect.”
On the other hand, some groups see the rule as a necessary step towards providing clarity and certainty for consumers. The National Consumers League, for example, appreciates that the rule gives passengers “certain rights” regardless of which airline they are flying with. However, the group is also concerned about the potential for airlines to abuse the ambiguity surrounding one of the 10 events, “unscheduled maintenance,” to avoid compensating consumers.
It’s worth noting that while there is no formal accounting of how often cyberattacks have caused delays or cancellations, hackers have targeted airlines and flights before. Cyberattacks have become a growing concern in the aviation sector, with some incidents causing significant disruptions. The Transportation Department has maintained that it will hold airlines “accountable” for their compliance with cybersecurity regulations.
Ultimately, this new rule highlights the importance of airline cybersecurity measures and passenger rights. As the aviation sector continues to grapple with the challenges of cyber threats, passengers should be aware of their rights and responsibilities. If you’re flying soon, it’s essential to understand that meal vouchers or hotel accommodations may not always be available in cases of flight delays or cancellations due to cyberattacks.
To stay informed and prepared, consider checking your airline’s customer service plan and familiarizing yourself with the DOT’s rule changes. Additionally, if you experience a delayed or canceled flight due to a cyberattack, don’t hesitate to reach out to your airline and express your concerns. By staying vigilant and advocating for our rights as passengers, we can help ensure that the aviation sector remains safe and secure for everyone.
Source: CyberScoop — 2026-09-11