Skip to main content
Compliance

DOT Rule Shields Airlines from Liability for Cyberattack-Related Delays

Commercial airliner on tarmac with airport equipment in background.

“Cybersecurity is an airline responsibility, so if a flight is delayed or cancelled it should be clear that the delay was not due to carrier neglect, as cyberattacks are constant,” Paul Hudson, president of FlyersRights, told CyberScoop.

What the Department of Transportation changed

Beginning next month, the Department of Transportation will allow airlines to treat delays and cancellations caused by cyberattacks as part of a newly created “cause of delay” reporting category and — critically — as one of 10 events deemed “not controllable.” The practical consequence: when disruptions arise from those specified causes, “carriers are no longer obligated under [customer service] plans to provide amenities or compensation,” Sophie Hayashi, counsel at Crowell & Moring in the transportation group, wrote in a client alert.

Which airline obligations are affected

The rule change removes a federal expectation that airlines must hand out meal vouchers or arrange hotel rooms to passengers when a disruption is listed among the 10 "not controllable" events. The category explicitly includes “cybersecurity attacks (provided that the air carrier is in compliance with applicable cybersecurity regulations).” Hayashi told CyberScoop that carriers who can’t demonstrate compliance with those regulations “will be subject to customer and other requirements.”

How industry and consumer advocates responded

Reactions split along predictable lines. FlyersRights expressed skepticism that the change was made without public comment and said it will monitor whether passengers see a reduction in amenities; Hudson warned that cyberattacks are “constant” and reiterated that cybersecurity is a carrier responsibility. The National Consumers League offered a mixed view. John Breyault, vice president of public policy for the group, said the rule could give consumers certainty — that “regardless of which airline they were flying, they would know that they have certain rights” — but also warned that the Department of Transportation “seems inclined to try and make the rules a little less onerous for the airline industry” and worried airlines could exploit ambiguous categories like “unscheduled maintenance.” Breyault added that the compliance condition might still protect consumers.

Legal and practical guardrails: compliance and reporting

The rule conditions the cyberattack carve‑out on carriers’ compliance with “applicable cybersecurity regulations,” language Crowell & Moring partners described as broad. “The final rule’s language regarding applicable cybersecurity regulations is notably broad,” Kate Growley said, suggesting that breadth may be intentional to match the unpredictable nature of cyber incidents and the range of rules that might apply depending on what systems or data are affected. The Aviation Information Sharing Analysis Center welcomed the reporting elements: Jeff Troy, the organization’s president and CEO, said the ISAC “supports efforts to simplify and harmonize cybersecurity reporting across numerous government agencies” and called the rule “a move in the right direction.”

Examples cited in the rulemaking record

The DOT and CyberScoop account referenced several past incidents to illustrate how cyber‑related events have affected air travel. Hackers tied to the group known as Scattered Spider carried out attacks last summer. A cyberattack on Collins Aerospace last year caused delays in Europe. The 2024 IT outage tied to the cybersecurity company CrowdStrike, while not judged to be a cyberattack, grounded flights and led to some traveler compensation; the Transportation Department determined that incident was within airlines’ control. The Biden administration had previously imposed cybersecurity regulations on airports, aircraft owners and aircraft operators in 2023 in response to what the administration called “persistent cybersecurity threats” in the sector.

What this means for travelers, airlines, and cybersecurity teams

  • Travelers: If a disruption is recorded under one of the 10 “not controllable” causes, carriers may no longer provide meal vouchers, hotel stays, or other amenities they otherwise might have offered — unless the carrier cannot demonstrate compliance with applicable cybersecurity rules.
  • Airlines and legal teams: The rule gives carriers clearer reporting categories and a narrower set of customer-service obligations for specific causes, while leaving them responsible for proving they meet applicable cybersecurity requirements if they expect the exception to apply.
  • Cybersecurity teams and regulators: The compliance caveat places a premium on demonstrable adherence to the “applicable cybersecurity regulations” referenced in the rule; the Aviation ISAC signaled support for harmonized reporting that could reduce duplicative notices to multiple agencies.

Congress set this change in motion: a DOT spokesperson said “Congress explicitly directed DOT in the FAA Reauthorization Act of 2024 to make these changes,” and that the 10 types of flight disruptions “will now … be tracked in a brand-new reporting category to ensure government delay data accurately reflects what airlines can and cannot control.” DOT has also maintained it will hold airlines “accountable” for pledges in their customer service plans, even though those plans themselves aren’t legally binding.

The rule tightens the link between cybersecurity posture and consumer remedies: if an airline can show it met applicable cybersecurity obligations, it may avoid providing amenities after a cyber‑related disruption; if it cannot, the usual customer requirements can apply. The change promises clearer data for official delay statistics, but it also shifts more of the burden onto carriers to prove compliance — and gives consumer advocates a clear target to monitor for potential overuse of the exception, particularly around vague categories such as “unscheduled maintenance.”

Original story