Airline passengers stranded during the July 2024 global outage linked to CrowdStrike security software are now asking the United States Supreme Court to revive their lawsuit, in a test of how far federal airline law shields technology providers from claims tied to air travel disruptions.

Get the latest news straight to your inbox!

Stranded CrowdStrike passengers take outage fight to Supreme Court

The July 19, 2024 outage originated with a faulty update to CrowdStrike’s Falcon security software for Microsoft Windows, which caused widespread system crashes across airlines, banks, hospitals and public services. Aviation systems relying on affected Windows machines saw check-in terminals, crew scheduling tools and other critical infrastructure go offline, triggering cancellations and delays at major hubs from Atlanta to Manila.

Delta Air Lines experienced some of the most severe operational fallout, with days of cancellations, missed connections and stranded passengers as the carrier struggled to restore its crew-management and IT systems. Publicly available filings and executive comments indicate Delta has estimated roughly 500 million dollars in costs tied to the disruption and is separately pursuing claims against CrowdStrike in state court in Georgia.

For passengers, the outage translated into missed holidays, unexpected hotel stays, last-minute tickets on competing carriers and lost workdays. Reports gathered by regulators and consumer advocates describe individual travelers paying hundreds of dollars out of pocket to complete disrupted journeys, with some rerouted multiple times as airlines worked through cascading schedule changes.

Government documents released after the event show that the U.S. Department of Transportation ultimately classified Delta’s CrowdStrike-related cancellations and delays as a controllable event from the airline’s perspective, reinforcing passengers’ rights to refunds and certain accommodations when flights were canceled or significantly delayed.

Lower courts shut down passengers’ lawsuit against CrowdStrike

In the aftermath of the outage, several travelers filed a proposed class action against CrowdStrike in federal court in the Western District of Texas. The case, brought by passenger Julio del Rio and others, alleged that defects in CrowdStrike’s software update led directly to the global outage and to concrete financial losses for affected flyers, including replacement tickets, ground transport and incidental expenses.

The plaintiffs advanced state-law negligence and product liability theories, arguing that CrowdStrike failed to exercise reasonable care in designing and testing the update and should compensate travelers for foreseeable harms arising from the mass disruption of air travel. Court records describe the outage as a “massive disruption of all businesses employing its software,” with air transportation singled out as a particularly visible sector.

In June 2025, the district court dismissed the case in its entirety. The judge concluded that the Airline Deregulation Act, a federal statute enacted in 1978 to prevent states from regulating airline “rates, routes, or services,” preempted the passengers’ claims because their alleged damages were inseparable from disrupted air services, even though CrowdStrike itself is not an airline.

The U.S. Court of Appeals for the Fifth Circuit affirmed that reasoning in May 2026. The appellate panel held that, because the asserted injuries centered on canceled and delayed flights, the claims “related to” air carrier services within the meaning of the Airline Deregulation Act and therefore could not proceed under state tort law, effectively shielding CrowdStrike from passenger lawsuits tied to the outage.

Petition to the Supreme Court challenges scope of airline preemption

Earlier in September 2026, the stranded passengers filed a petition asking the Supreme Court to review the Fifth Circuit’s decision, now captioned Julio del Rio et al. v. CrowdStrike Inc. The docketed filing presents a single, sharply framed question: whether the Airline Deregulation Act’s preemption of claims related to an air carrier’s services extends to state-law suits against an independent third-party software vendor with no direct relationship to passengers.

The petition argues that lower courts have stretched the statute beyond its text and purpose by using it to block claims against entities that do not sell tickets, operate aircraft or set airfares. According to publicly available summaries of the filing, the travelers contend that the Act was designed to prevent states from reimposing economic regulation on airlines, not to insulate upstream technology providers from ordinary product liability rules when their software fails.

Passenger lawyers also highlight what they describe as a growing tension among federal courts over how broadly to apply the “related to” language in the Airline Deregulation Act. In their view, allowing technology vendors to invoke airline preemption in cases arising from IT failures creates an accountability gap for travelers, particularly as airlines increasingly depend on complex digital systems supplied by outside firms.

CrowdStrike has not yet filed its formal response in the Supreme Court, but in earlier proceedings the company has pointed to the structure of the statute and existing precedent that broadly construes preemption where claims are closely linked to flight operations, regardless of the defendant’s identity. If the Court ultimately declines to hear the case, the Fifth Circuit’s ruling would stand, limiting passenger recourse against CrowdStrike for the July 2024 disruption.

Travelers weigh airline remedies while waiting on the Court

While the Supreme Court considers whether to accept the petition, most practical options for affected passengers remain with the airlines and existing consumer protection rules rather than with CrowdStrike itself. Following the outage, several carriers, including Delta, American and United, published travel waivers, refund policies and reimbursement guidelines on their websites, offering to waive change fees, refund unused tickets and in some cases cover reasonable hotel and meal costs for disrupted trips.

For U.S. travelers, Transportation Department rules require cash refunds when flights are canceled or significantly changed and a passenger chooses not to travel, regardless of the cause. Agencies have emphasized that airlines remain the primary point of contact for passengers seeking financial redress, even when disruptions originate with external technology failures.

In other jurisdictions, passenger rights regimes such as European Union Regulation 261/2004 and Canada’s Air Passenger Protection Regulations continue to shape what compensation is available. Public guidance issued in the wake of the CrowdStrike outage indicated that, in some cases, regulators viewed the incident as an extraordinary circumstance limiting statutory compensation, even as airlines were expected to provide care, rerouting or refunds.

Consumer advocates note that many travelers still face a tedious documentation process, often needing to supply receipts for hotels, meals and alternative transport, and to navigate differing airline policies on expense reimbursement. The outcome of the Supreme Court petition will not alter those immediate processes, but could influence whether future technology vendors can be held directly liable in U.S. courts for travel chaos tied to software failures.

What the case means for tech liability in future travel disruptions

The CrowdStrike petition arrives at a moment when aviation systems, airport operations and border controls are increasingly dependent on third-party software and cloud services. The July 2024 outage showed how a single flawed update can simultaneously ground flights, snarl baggage handling and delay crew scheduling across continents.

Legal analysts following the case suggest that, if the Supreme Court narrows the reach of airline preemption, passengers might gain a clearer path to sue technology providers whose products are alleged to have caused widespread travel disruptions. That could reshape risk calculations for cybersecurity and software companies serving the aviation sector, encouraging more intensive testing and contingency planning around critical updates.

If the Court declines review or upholds the lower courts, the prevailing view would strengthen the position that passengers’ remedies for IT-driven meltdowns lie primarily in contract and consumer protection rules governing airlines, not in direct product liability claims against upstream vendors. In that scenario, carriers would remain the central point of responsibility to the traveling public, even as they seek indemnity or contribution from suppliers through private commercial arrangements.

The Supreme Court is expected to decide in the coming months whether to take up the case. For travelers who slept on airport floors or paid steep last-minute fares during the CrowdStrike outage, the outcome will determine not only whether their own lawsuit can move forward, but also how future disruptions at the intersection of aviation and technology are addressed in U.S. law.