As airlines grow more dependent on complex software and cybersecurity tools, travelers are discovering an uncomfortable truth: when a cyber incident snarls flights, carriers in many cases have no legal obligation to pay for your hotel room, meals or other out-of-pocket costs, even if you spend the night on the terminal floor.

Get the latest news straight to your inbox!

Cyberattacks, Flight Delays and Why Airlines Owe You Little

Cyber Outages Are Creating a New Kind of Flight Disruption

The rise of large-scale IT failures and cyber-related incidents has added a new category of disruption to air travel. In July 2024, a faulty update from cybersecurity provider CrowdStrike triggered a global outage of Windows-based systems, affecting airlines, banks, hospitals and governments. Published accounts indicate that Delta Air Lines alone canceled around 7,000 flights across five days and disrupted travel for more than a million passengers as its systems struggled to recover.

According to company disclosures and regulatory filings, the event carried an estimated direct revenue impact of hundreds of millions of dollars for Delta, reflecting both refunded tickets and customer compensation. Publicly available information shows that Delta later sought roughly half a billion dollars in damages from CrowdStrike, underscoring how costly these events can be for carriers themselves.

Yet for stranded travelers, the cost calculus looks very different. While some passengers received hotel and meal vouchers, many reported paying out of pocket for nights in airport hotels, rideshares, replacement flights on other airlines and extra food, with only partial reimbursements at best. The uneven experience has raised a pointed question: when a cyber-related failure delays or cancels your flight, what, exactly, does an airline owe you?

What U.S. Rules Really Guarantee When IT Fails

In the United States, federal rules focus primarily on refunds, not on covering the cascade of expenses that follow a major disruption. The Department of Transportation (DOT) states that when a flight is canceled or significantly changed and a passenger chooses not to travel, the customer is entitled to a refund of the unused ticket and certain fees paid directly to the airline. That right applies regardless of the reason for the cancellation, whether it is weather, a mechanical problem or a software outage.

However, DOT guidance does not require airlines to provide hotel rooms, meal vouchers or ground transportation when delays or cancellations occur, even in cases where the disruption is fully within a carrier’s control. Services like meals and lodging are largely governed by each airline’s individual contract of carriage and customer service policies, which give carriers considerable discretion about when and how such aid is offered.

Some large U.S. airlines publicly pledge to provide food or hotel accommodations for passengers when disruptions are considered controllable. A federal "airline customer service dashboard" highlights these voluntary commitments. But these pledges function as policy promises rather than hard legal obligations and can change over time. Even when a cyber-related disruption is labeled controllable, travelers generally must rely on the specific wording and limits in each airline’s own rules.

DOT has signaled interest in going further. In a recent rulemaking document on airline passenger rights, the department noted concerns that travelers are often left in the dark about what they are owed during long delays and raised the possibility of requiring airlines to provide meals, lodging and other services automatically in certain circumstances. For now, though, those ideas remain proposals rather than enforceable standards.

How Airlines Classify Cyber Events and What That Means for You

Behind the scenes, airlines divide disruptions into different buckets that determine what kind of assistance may be offered. Weather events, air traffic control restrictions and security threats are typically labeled as outside the airline’s control. Mechanical issues, crew scheduling problems and many software failures are more likely to be treated as controllable, at least in principle.

Cyber incidents and large IT outages sit uncomfortably between these categories. In the CrowdStrike-related disruption, public reporting indicates that U.S. regulators later classified the cascade of cancellations at one major carrier as a controllable event, taking the position that the airline’s own IT resiliency and recovery planning played a role. That classification matters because the carrier had promised to provide meals and hotel rooms for passengers facing long delays when the cause was within the airline’s control.

At the same time, airlines often emphasize force majeure or extraordinary circumstances in their contracts. These clauses can cover events such as political instability, severe weather or security risks and are used to limit responsibility for knock-on costs. While many cyber incidents originate with third-party vendors or outside attacks, carrier policies do not always spell out clearly whether such events fall into the controllable or extraordinary category, leaving room for dispute when passengers seek reimbursement.

The result is a patchwork of outcomes. Publicly available statements show that Delta, for example, offered expanded reimbursement for some expenses during the 2024 disruption, including certain hotels, meals and alternative transportation beyond its standard policy. Yet separate coverage has documented lawsuits and complaints from passengers who say they did not receive promised vouchers or timely refunds, illustrating how broad commitments can collide with case-by-case interpretation.

Europe’s Different Approach to Care and “Extraordinary” Events

Travelers flying within or from the European Union face a somewhat different framework. EU air passenger rules, built around Regulation 261/2004 and now in the process of being updated, require airlines to provide care to stranded passengers, including meals and refreshments after a certain delay and hotel accommodation when an overnight stay is necessary. These obligations apply regardless of the cause of the disruption.

Where cause does come into play is in financial compensation. Under EU rules, airlines may be exempt from paying set cash compensation if they can show that a delay or cancellation was caused by "extraordinary circumstances" that could not have been avoided even if all reasonable measures had been taken. Recent guidance from European institutions lists examples such as severe weather, security risks, unexpected flight safety shortcomings and some strikes as potential extraordinary events.

As cyber risk has grown, European lawmakers have moved to clarify how such incidents might be treated. A political agreement on stronger EU air passenger rights reached in 2026 reinforces the obligation to provide care, including meals after a few hours and hotel stays where needed, while refining how extraordinary circumstances are defined. That means an airline may avoid paying cash compensation after a sophisticated cyberattack, but it generally still must feed and accommodate passengers during the disruption.

In practice, this creates a sharp contrast with typical U.S. practice. On many transatlantic journeys, a traveler departing Europe could be entitled to hotel accommodation under EU rules if a cyber incident forced an overnight delay, while a passenger starting a similar domestic trip in the United States might receive only rebooking and a ticket refund if they decided not to fly.

The gap between traveler expectations and legal guarantees becomes most visible after high-profile IT failures. Published coverage of the 2024 CrowdStrike-linked outage shows how quickly airports can turn into makeshift dormitories, with passengers sleeping on terminal floors and lining up for scarce hotel rooms. At the same time, social media posts and consumer reports describe a wide spectrum of outcomes, from full reimbursement of hotels and replacement flights to partial coverage of basic meals, or no aid at all.

For U.S. passengers caught in a future cyber-related disruption, the most reliable entitlement remains a refund if the airline cancels the flight or makes a significant schedule change and the traveler chooses not to complete the trip. Beyond that, assistance with food and lodging hinges on the carrier’s own policies, its assessment of whether the disruption was controllable and the practical ability of staff to issue vouchers during a chaotic outage.

Consumer advocates often urge travelers to keep all receipts for expenses such as hotels, meals, taxis and replacement flights purchased during a disruption, in case the airline later widens reimbursement criteria or regulators encourage broader relief. When disruptions attract political and regulatory scrutiny, some carriers have expanded reimbursement programs or created dedicated claim processes after the fact, as occurred following the CrowdStrike outage.

Even so, the broader lesson is sobering. As airlines rely ever more heavily on complex software and cybersecurity tools, the risk of digital failures will remain. Unless and until regulators impose stricter, automatic obligations for meals and hotels in IT-related disruptions, passengers should not assume that a cyberattack or software outage, by itself, guarantees a paid night in a hotel or a free meal when flights grind to a halt.

U.S. DOT: Refunds for Airline Travelers

Delta Air Lines Contract of Carriage

European Commission: Revised EU Air Passenger Rights Q&A

Council of the EU: Agreement on Stronger Air Passenger Rights

Delta: What We Are Doing for Customers Impacted by CrowdStrike Disruption