Security News

New US Rule Lets Airlines Skip Compensation for Cyberattack-Related Delays

CyberScoop · 12 Sept 2026
Key Takeaway Small businesses that depend on airlines or other service providers for time-sensitive operations should build in contingency plans, since cyberattack-related disruptions may no longer come with guaranteed compensation.

Starting next month, US airlines will not be required to provide meal vouchers or hotel stays to passengers whose flights are delayed or cancelled due to a cyberattack, under a new Transportation Department rule. The rule creates a 'cause of delay' category that lists 10 types of events, including cybersecurity attacks, as 'not controllable', provided the airline is complying with applicable cybersecurity regulations. This effectively reduces airline obligations under their own customer service plans, which are not legally binding but which the department says it monitors for accountability.

The change has drawn mixed reactions. FlyersRights, a consumer advocacy group, criticised the rule for being introduced without public consultation and said it would track any resulting reduction in passenger amenities. Its president argued that airlines bear responsibility for their own cybersecurity resilience, noting that attacks are a constant and ongoing risk that companies should be prepared for. The National Consumers League took a more balanced view, noting that a clear national rule at least gives passengers certainty about their rights rather than leaving compensation up to individual airline discretion.

While this rule targets the aviation sector specifically, it highlights a broader trend: regulators and industries are increasingly treating cyberattacks as a recognised operational risk category, similar to weather events, rather than an anomaly. For businesses reliant on transport or logistics providers, this is a reminder that supply chain disruptions from cyberattacks may not always come with compensation.

aviation cyberattack regulation business continuity consumer rights
Answering for this at board level? Our cyber governance framework ->

Summarised by CISO AI from CyberScoop. We link back to every original so you can read it yourself.