As cyber threats creep closer to the heart of aviation systems, passengers may assume that a hacking incident that cancels or delays a flight unlocks hotel vouchers and meal coupons. In most cases, current rules and airline policies say otherwise, leaving travelers to shoulder many of the costs when a cyberattack snarls the skies.

Get the latest news straight to your inbox!

Cyberattacks and Flight Delays: What Airlines Actually Owe You

Cyber Risk Joins Weather and Air-Traffic Failures as Major Disruption Source

Recent disruptions tied to technology failures have highlighted how quickly a digital problem can cascade across the air network. In January 2023, a failure in the Federal Aviation Administration’s Notice to Air Missions (NOTAM) system temporarily halted most U.S. departures and triggered nationwide delays as airlines worked through the backlog of flights. Publicly available information on that event pointed to a corrupted database file rather than a hack, but it underscored the vulnerability of critical aviation systems to IT incidents.

Cybersecurity has since risen on the agenda for regulators and lawmakers. Congressional records show repeated calls to strengthen the resilience and cyber protections of air traffic and alerting systems, including the NOTAM architecture, in response to the 2023 outage. These discussions increasingly mention the potential impact of malicious intrusions, not just accidental failures, on flight operations and passenger mobility.

Despite the rising concern, passenger protections have not fundamentally shifted to treat cyber incidents differently from other causes of disruption. Whether a delay originates with a malicious cyberattack on aviation infrastructure, a software misconfiguration, or a traditional air-traffic control failure, the practical question for travelers is the same: who pays for the meals, hotels, and lost time when flights do not depart as scheduled.

In the U.S., Contract Terms and DOT Dashboard Limit Passenger Entitlements

In the United States, passenger protections during disruptions are largely defined by federal refund rules and each airline’s own customer service commitments. The Department of Transportation’s Airline Cancellation and Delay Dashboard summarizes what major carriers promise during “controllable” disruptions, such as mechanical problems or crew misallocations. Many airlines now advertise meal vouchers when delays run three hours or more and hotel accommodations when passengers are stranded overnight, but only when the airline is responsible for the disruption.

Cyber incidents are likely to fall into one of two categories under these frameworks. If a cyberattack disables an airline’s internal systems, carriers could classify the resulting delays as controllable and voluntarily extend meal or hotel coverage according to their published plans. If, however, the disruption stems from a cyber event targeting government-operated infrastructure, such as air-traffic control or aviation communications, carriers typically treat it as beyond their control and outside the scope of those commitments.

Customer service plans published by major U.S. airlines illustrate this dividing line. Where policies describe assistance, they often distinguish between disruptions caused by the carrier and those resulting from “events beyond our control” such as weather or air-traffic control restrictions. In the latter cases, airlines generally state that passengers are responsible for their own meals, hotels, and incidental expenses, even when they face overnight delays.

Federal rulemaking activity has focused on refunds when flights are cancelled or significantly changed. The Department of Transportation has adopted rules that require automatic cash refunds in certain situations where a passenger chooses not to travel. Those rules do not require airlines to provide hotels or meals after disruptions outside the airline’s control, leaving a gap between passenger expectations and legal entitlements in cyber-related events.

Europe Treats Cyberattacks as Extraordinary, but Duty of Care Still Varies

In the European Union and many countries that mirror EU rules, air passenger rights are governed by Regulation (EC) No 261/2004, commonly known as EU261. Under these rules, passengers on flights departing from the EU or operated by EU airlines may be entitled to fixed cash compensation when their flight is cancelled or heavily delayed and the cause is considered within the airline’s control.

Guidance from European institutions categorizes events such as serious security risks, air-traffic control restrictions, and certain third-party strikes as “extraordinary circumstances” that relieve airlines from paying compensation. Cyberattacks on aviation infrastructure or key operational systems are generally viewed as belonging to this family of extraordinary events, as they are external and not inherent in normal airline operations. In practice, that classification means passengers facing cyber-related disruption are unlikely to receive the standard lump-sum compensation payments.

However, the concept of “duty of care” under EU261 operates separately from compensation. Official notices and court interpretations emphasize that airlines must still provide care in the form of meals, refreshments, and hotel accommodation when necessary, even in extraordinary circumstances. Passengers who had to cover these costs themselves can later seek reimbursement if the carrier did not offer assistance and the expenses were necessary and reasonable.

This creates a contrast with common U.S. practice. In many European scenarios, a traveler stranded overnight due to a cyber incident would have a legal basis to ask the carrier to cover hotels and meals, though not to claim the fixed compensation amounts. The challenge for passengers is documenting the link between the disruption, the airline’s obligations, and any expenses paid out of pocket.

Force Majeure Clauses Shift Cyber Costs Back to Travelers

Across jurisdictions, the fine print of airline contracts of carriage and customer service plans plays a decisive role when cyber incidents disrupt travel. These documents routinely include force majeure or “extraordinary circumstances” clauses listing events that relieve the carrier from certain obligations. Weather, wars, civil unrest, and air-traffic control decisions generally appear on those lists. Increasingly, language related to cybersecurity incidents or failures of third-party IT providers is also being incorporated, placing cyber events alongside traditional force majeure risks.

When a cyberattack is categorized under these provisions, airlines typically limit their responsibilities to rebooking passengers on the next available flight or refunding unused tickets if the traveler decides not to fly. Hotel rooms, meals, and ground transport are commonly excluded. For travelers, that means a sophisticated digital attack that paralyzes an airline’s systems can have much the same financial impact as a severe storm that shuts down a hub.

Consumer advocates caution that such clauses can be broad, and the burden often falls on passengers to challenge denials of benefits. While regulators in both the United States and Europe are examining how to tighten consumer protections during mass disruptions, current frameworks still allow airlines significant leeway to classify cyber events as beyond their control and point travelers back to their travel insurance or personal resources for out-of-pocket costs.

How Travelers Can Protect Themselves in a Cyber-Linked Disruption

Given the current mix of regulations and contractual terms, passengers concerned about cyber-related disruptions have limited guaranteed avenues for recouping expenses. Travel insurance policies vary significantly in how they treat cyber incidents affecting transportation providers. Some products explicitly cover additional accommodation and meal costs when a carrier experiences an equipment or systems failure, while others frame coverage in terms of weather or mechanical issues and may exclude cyber events entirely.

Experts recommend that travelers review both their airline’s customer service plan and any insurance policy documents before departure, looking specifically for language covering “systems failure,” “IT outage,” or “cyber incident.” Credit card travel protections can also play a role, as premium cards sometimes reimburse reasonable expenses when common carriers experience extensive delays, without distinguishing the root cause.

During a disruption, keeping detailed records remains essential. Receipts for meals, hotels, and transportation, along with screenshots or written confirmations of delay notices, can support later claims with airlines, insurers, or credit card issuers. In Europe and jurisdictions with similar rules, travelers can also reference published EU261 guidance to support claims for duty-of-care expenses after extraordinary events.

As aviation agencies and lawmakers work on strengthening the resilience of air travel systems, passenger protection frameworks are evolving more slowly. For now, when a cyberattack delays or cancels flights, most travelers will find that the obligation to cover hotels and meals rests with them unless they benefit from a specific airline promise, a favorable jurisdiction, or an insurance policy that explicitly fills the gap.

U.S. DOT Airline Cancellation and Delay Dashboard

U.S. DOT overview of airline passenger refund and disruption rules

Official EU air passenger rights portal

European Commission interpretative guidelines on EU261