A new Department of Transportation (DOT) rule, effective next month, will reduce airline obligations to customers for flight delays or cancellations caused by cyberattacks, provided the carrier complies with applicable cybersecurity regulations. This change is part of a broader DOT rule published last week, which establishes a new category for tracking delay information and reduces air carrier responsibilities across ten specific types of events deemed "not controllable."
These ten events, including cyberattacks, mean airlines are no longer obligated under their customer service plans to provide amenities or compensation, such as meal vouchers or hotel stays, when disruptions arise from these causes. The DOT spokesperson indicated that Congress explicitly directed these changes in the FAA Reauthorization Act of 2024, aiming to ensure government delay data accurately reflects what airlines can and cannot control.
The rule's language regarding "applicable cybersecurity regulations" is intentionally broad, according to legal experts, likely to accommodate the unpredictable nature of cyberattacks and the varying regulations that might apply depending on the specific operational capabilities or information affected. Carriers unable to demonstrate compliance with these regulations will still be subject to customer and other requirements.
One airline consumer advocacy group, FlyersRights, expressed skepticism about the change, noting it was implemented without public comment. The group plans to monitor the impact on customers and any reduction in amenities, arguing that cybersecurity is an airline responsibility and delays should clearly not be due to carrier neglect, especially given the constant threat of cyberattacks. They have previously advocated for stress tests on airline computer systems.
Another group, the National Consumers League, offered a mixed view. While acknowledging the rule provides consumers with certainty regarding their rights across different airlines, they also expressed concern that the DOT appears inclined to make rules less onerous for the airline industry. Specifically, they worried about potential airline abuse of ambiguity related to "unscheduled maintenance," another of the ten events, to avoid compensating consumers.
The Aviation Information Sharing Analysis Center (Aviation ISAC) welcomed the elements of the rule related to incident reporting, stating that it supports efforts to simplify and harmonize cybersecurity reporting across government agencies. Legal analysis suggests the rule could be positive for both airlines, by providing clarity on disruptions outside their control, and for consumers, by offering a more accurate picture of carrier-controlled delays and cancellations.
While there is no formal accounting of how often cyberattacks have directly led to flight delays or cancellations requiring compensation, hackers have previously targeted airlines and the broader aviation sector. Examples include attacks by Scattered Spider last summer and an attack on Collins Aerospace last year that caused delays in Europe. The 2024 IT outage related to cybersecurity company CrowdStrike, which grounded flights, was not a cyberattack but did lead to some airline compensation, as the DOT determined that incident was within airline control.
The Biden administration previously imposed cybersecurity regulations on airports, aircraft owners, and aircraft operators in 2023 due to persistent cybersecurity threats in the sector. The newly published DOT rule stems from a Federal Aviation Administration authorization law signed by President Joe Biden in 2024.






