❌

Reading view

There are new articles available, click to refresh the page.

Cyberattack causes a flight delay? Airlines won’t owe you a hotel or meal

Beginning next month, if a flight is canceled or delayed because of a cyberattack, feds will give airlines clearance not to hand out meal vouchers or hotels.

The change is the result of a broader rule the Transportation Department published last week that establishes a new “cause of delay” category for tracking information, but that also reduces air carrier responsibilities to customers for 10 kinds of events. Among them: “cybersecurity attacks (provided that the air carrier is in compliance with applicable cybersecurity regulations).”

The 10 events, including those cyberattacks, are deemed “not controllable,” meaning that “carriers are no longer obligated under [customer service] plans to provide amenities or compensation when disruptions arise from these specific causes,” as Sophie Hayashi, counsel at Crowell & Moring in the transportation group, wrote in a client alert.

Those airline-authored customer service plans aren’t legally binding, although DOT has maintained it will hold airlines “accountable” for their pledges.

One airline consumer advocacy organization, FlyersRights, was skeptical of the change, saying it came without giving the public a chance to comment and that it would be monitoring the impact on airline customers and tracking any reduction in amenities. 

Specifically, “cybersecurity is an airline responsibility, so if a flight is delayed or cancelled it should be clear that the delay was not due to carrier neglect, as cyberattacks are constant,” Paul Hudson, president of the group, told CyberScoop. “We have previously urged stress tests for airline computer systems that are going down often.”

Another group, the National Consumers League, had a more mixed view about the rule’s effects on flyers. On one hand, it could be good for them, said John Breyault, vice president of public policy for the group.

‘What we appreciated about this being put into a rule was that it gave consumers certainty that regardless of which airline they were flying, they would know that they have certain rights, and they weren’t beholden to the whims of the airlines who may or may not decide to provide them with a hotel if there’s a delay or cancelation,” he said.

On the other, though, “it’s clear to us that the DOT seems inclined to try and make the rules a little less onerous for the for the airline industry,” Breyault said, and in particular was worried about how airlines could potentially abuse the ambiguity related to one of the 10 events, “unscheduled maintenance,” to find a way to avoid compensating consumers.

The provision might still protect consumers because of its condition on compliance with applicable cybersecurity regulations, Breyault said. Carriers who can’t demonstrate compliance will be subject to customer and other requirements, Hayashi said.

“The final rule’s language regarding applicable cybersecurity regulations is notably broad,” said Kate Growley, partner at Crowell & Moring. “This may have been deliberate to account for the unpredictable nature of cybersecurity attacks. Different regulations may apply depending on the exact circumstances of the attack, such as what information or operational capabilities were affected.”

There’s no formal accounting of how often cyberattacks have caused delays or cancellations that then prompted airlines to provide meal vouchers or hotels. Hackers have targeted airlines and flights before, such as Scattered Spider’s attacks last summer.

Cyberattacks have caused flying delays and cancellations, although sometimes those attacks have been aimed at third parties, such as in last year’s attack on Collins Aerospace led to delays in Europe. Attackers also have targeted other elements of the aviation sector. The 2024 IT outage related to the cybersecurity company CrowdStrike that grounded flights wasn’t a cyberattack, but did lead to airlines providing some compensation to travelers; the Transportation Department determined that incident was within airlines’ control.

The Biden administration notably imposed cybersecurity regulations on airports, aircraft owners and aircraft operators in 2023 due to “persistent cybersecurity threats” in the sector. 

The newly-published Department of Transportation (DOT) rule stems from a Federal Aviation Administration authorization law that President Joe Biden signed in 2024. 

“Congress explicitly directed DOT in the FAA Reauthorization Act of 2024 to make these changes,” a Department of Transportation spokesperson said. “These 10 specific types of flight disruptions will now … be tracked in a brand-new reporting category to ensure government delay data accurately reflects what airlines can and cannot control.”

The Aviation Information Sharing Analysis Center said it appreciated the elements of the rule related to reporting incidents.

“The Aviation ISAC supports efforts to simplify and harmonize cybersecurity reporting across numerous government agencies,” said Jeff Troy, president and CEO of the organization. “This rule is a move in the right direction.”

Hayashi told CyberScoop the rule change looks to be positive for both airlines — because of the clarity it provides them about disruptions not under their control — and consumers.

“This actually is beneficial for everyone, and particularly consumers, because it makes it clear if you’re looking at airlines delay and cancellation rates, this is going to give you the most accurate picture of carrier delays,” she said.

The post Cyberattack causes a flight delay? Airlines won’t owe you a hotel or meal appeared first on CyberScoop.

Delta investigates in-flight Wi-Fi spoofing on post-DEF CON flight from Las Vegas

Delta Airlines said Tuesday it’s investigating an incident on a Monday flight where a passenger reportedly used an unidentified device to spoof the airline’s in-flight Wi-Fi network, leading to severe delays and authorities to board the plane once it arrived at its destination.

Various posts on several social media networks went viral early Tuesday detailing the incident, claiming that passengers on Delta flight 591 from Las Vegas to Atlanta used an unidentified device to create a rogue Wi-Fi network that could be used to steal people’s sensitive data or personal information.

Messages from the plane’s Aircraft Communications Addressing and Reporting System (ACARS) show that the crew informed personnel on the ground that a passenger set up a network called “Delta WiFi Fast” and was “trying to scam the other passengers.”

Morgan Durrant, a Delta spokesperson, told CyberScoop that the cabin crew deactivated the aircraft’s WiFi functionality for approximately 30 minutes, the flight’s safety was never in question and no aircraft operating systems were affected.

“We are fully investigating to gather a complete set of facts, which will take time,” Durrant told CyberScoop. “We will partner with federal law enforcement and aviation regulators to ensure the incident is thoroughly investigated. We thank our crew for their professionalism and our customers for their understanding.”

The Atlanta office of the FBI, along with the Federal Aviation Administration, said it was aware of the incident, but did not provide further comment. The Transportation Security Administration referred CyberScoop to the FBI. Homeland Security Investigations did not respond to a request for comment.

The incident bears the hallmarks of an “evil twin attack,” where an attacker deploys a rogue Wi-Fi access point that masquerades as a legitimate, trusted network by cloning its name and network settings. Often paired with deauthentication attacks that forcefully disconnect devices from the real network, the fraudulent hotspot tricks nearby laptops and smartphones into automatically connecting to it instead. Once a device connects to the rogue point, an attacker can monitor unencrypted internet traffic, execute man-in-the-middle attacks, or display spoofed login portals designed to harvest sensitive user credentials and personal data.  

The timing of the incident comes as the annual DEF CON cybersecurity conference concluded in Las Vegas on Sunday. The flight, originally scheduled for Sunday, did not leave Las Vegas until 8:30 a.m. Monday.

Monika Hathaway, head of press for DEF CON, told CyberScoop that Delta nor any federal authorities have reached out about the incident. However, she said this year’s conference had trouble with similar attacks.

“Our conference this year also suffered from multiple similar ‘deauthorization’ Wi-Fi attacks and it impacted some of our operations,” Hathaway told CyberScoop. “If we had caught them doing this at DEF CON we would have removed and banned them from the conference.”

The post Delta investigates in-flight Wi-Fi spoofing on post-DEF CON flight from Las Vegas appeared first on CyberScoop.

❌