From next month, US airlines will not owe passengers meal vouchers or hotel accommodation when a flight is cancelled or delayed because of a cyberattack, provided the carrier is in compliance with applicable cybersecurity regulations. The change flows from a Transportation Department rule published on 3 September establishing a new "cause of delay" category for tracking information, which also designates ten events โ including cybersecurity attacks and unscheduled maintenance โ as "not controllable", removing carriers' obligation under their own customer service plans to provide amenities or compensation for disruption from those causes. Those plans are not legally binding, but DOT has maintained it will hold airlines to their published pledges, and the compliance condition attached to the cyberattack category is broad enough that the specific regulation in play will depend on the nature of the incident. Consumer groups are split: FlyersRights objected that the change was made without public comment and argued cybersecurity is an airline responsibility, while the National Consumers League welcomed the certainty the rule gives passengers but said DOT appears to be easing obligations on carriers. The rule assigns the cost of cyber-disruption to passengers in the country with the largest aviation market, at a time when the EU has moved in the opposite direction by making vendors report exploited product vulnerabilities within 24 hours, and when Australian carriers and consumers continue to rely on the Australian Consumer Law and conditions of carriage rather than a prescriptive disruption-compensation regime.
| Attribute | Detail |
|---|---|
| Sector | Transport |
| Date | 2026-09-13 |
| Source | CyberScoop |
| Reliability | Tier 2 |