Skip to main content
COSMICBYTEZLABS
NewsSecurityHOWTOsToolsTraining
StudyProjectsNewsletterHire MeAbout
Subscribe

Press Enter to search or Esc to close

News
Security
HOWTOs
Tools
Training
Study
Projects
Newsletter
Hire Me
About
RSS Feed
Reading List
Subscribe

Stay in the Loop

Get the latest security alerts, tutorials, and tech insights delivered to your inbox.

Subscribe NowFree forever. No spam.
COSMICBYTEZLABS

Your trusted source for IT intelligence, cybersecurity insights, and hands-on technical guides.

2774+ Articles
166+ Guides

CONTENT

  • Latest News
  • Security Alerts
  • HOWTOs
  • Checklists
  • Projects
  • Exam Prep

RESOURCES

  • Search
  • Browse Tags
  • Newsletter Archive
  • Reading List
  • RSS Feed

COMPANY

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CosmicBytez Labs. All rights reserved.

System Status: Operational
  1. Home
  2. News
  3. Cyberattack causes a flight delay? Airlines won't owe you a hotel or meal
Cyberattack causes a flight delay? Airlines won't owe you a hotel or meal
NEWS

Cyberattack causes a flight delay? Airlines won't owe you a hotel or meal

A new DOT rule lets compliant airlines skip hotel and meal compensation for delays caused by cyberattacks.

Dylan H.

News Desk

September 12, 2026
4 min read

DOT Reclassifies Cyberattacks as "Not Controllable" Delays

The Department of Transportation published a final rule last week that reshapes what airlines owe passengers when a cyberattack disrupts a flight. As reported by CyberScoop, the rule creates a new category of "not controllable" delay causes and, for the first time, places cyberattacks inside it — provided the airline can show it was in compliance with applicable cybersecurity regulations at the time.

The rule was published on September 3, 2026, and takes effect October 19, 2026. It implements Section 511(b) of the FAA Reauthorization Act of 2024, which directed DOT to define which disruption causes count as within an airline's control versus outside it. Because Congress mandated the change, DOT issued it as a final rule without the usual notice-and-comment period — a point consumer advocates have specifically criticized.

Cyberattacks are one of ten newly listed "not controllable" events, alongside things like extreme-weather aircraft damage, sabotage, certain baggage-system outages, unexpected government system failures, medical emergencies, and specific unscheduled-maintenance scenarios. When a delay or cancellation falls into one of these buckets, airlines are no longer expected to treat it the way they treat delays within their own control.


What Changes for Passengers

ScenarioMeals / Hotel Typically ExpectedAfter the New Rule
Delay/cancellation deemed within airline's controlMeal vouchers and hotel accommodations for significant disruptions, per each carrier's customer service planUnchanged
Delay/cancellation caused by a cyberattack, airline compliant with applicable cybersecurity regulationsN/A (previously would likely have been treated as controllable)Classified "not controllable" — meal/hotel obligations reduced or eliminated
Delay/cancellation caused by a cyberattack, airline not compliant with applicable cybersecurity regulationsN/ACybersecurity carve-out does not apply; normal customer-service obligations still apply

A few caveats worth flagging:

  • These amenity commitments come from each airline's own customer service plan, not a federal law guaranteeing meals and hotels — DOT has said it holds carriers "accountable" to those pledges, but they aren't independently binding.
  • The rule's compliance bar is deliberately broad. Kate Growley, a partner at Crowell & Moring, has noted the final rule's language on "applicable cybersecurity regulations" isn't narrowly defined, likely to account for the range of frameworks that could apply depending on the airline and the nature of an attack.
  • The United States still has no EU-style legal mandate requiring meals, hotels, or cash compensation for every delayed or canceled flight, unlike the EU's 2026 agreement reinforcing passenger care obligations.

Why This Matters

The rule is explicitly designed to reward airlines for cybersecurity investment: comply with the applicable rules, and a cyberattack-driven meltdown gets treated like a hurricane rather than a self-inflicted IT failure. That logic has real precedent. The July 2024 CrowdStrike update failure — not itself a cyberattack, but a global IT outage — grounded roughly 7,000 Delta Air Lines flights over five days and disrupted travel for more than a million passengers. DOT determined that incident was within Delta's control, and the airline faced scrutiny and passenger claims over its response.

Consumer groups see the new carve-out differently. FlyersRights argues that cybersecurity is fundamentally an airline responsibility, not an external shock like weather, and objects that the rule was finalized without public comment. It says it will track whether the change leads to reduced amenities for stranded travelers. The National Consumers League welcomed the added clarity but warned airlines could lean on adjacent categories, like "unscheduled maintenance," to sidestep compensation even when the underlying cause is murkier than a clean-cut cyberattack.

The tension is straightforward: incentivizing airlines to harden their systems is a reasonable regulatory goal, but doing so by narrowing what passengers are owed shifts real financial risk onto travelers precisely when an airline's own security posture is in question. Whether "compliance with applicable cybersecurity regulations" becomes a meaningful bar — or a broad enough exemption to swallow the rule — will likely only become clear after the next major airline outage.

Sources

  • CyberScoop — Cyberattack causes a flight delay? Airlines won't owe you a hotel or meal
#Aviation#Regulatory#DOT#Cyberattack#Consumer Protection

Related Articles

Japan Airlines Confirms Data Breach Affecting 28,000

Japan Airlines reveals unauthorized access to its Same-Day Baggage Delivery Service reservation system compromised personal data of up to 28,000...

4 min read

Malaysia Airlines Listed by Qilin Ransomware Group

The Qilin ransomware-as-a-service group has listed Malaysia Airlines on its leak site, claiming access to passenger records, personnel files, and...

4 min read

Coupang Hit with Record $409 Million Data Breach Fine in South Korea

South Korea's Personal Information Protection Commission has fined e-commerce giant Coupang a record 624.6 billion won — approximately $409 million —...

4 min read
Back to all News