United Airlines at 6 p.m. on a typical Wednesday was in the center of a nation-wide meltdown in operations. Hundreds of flights were unexpectedly canceled, not because of weather or security issues, but because of a computer system failure that spread out from the airline’s major U.S. hubs. Stranded passengers waited on tarmacs and at gates, venting their frustration on Twitter. As United’s statement said, “The underlying technology issue has been resolved, and, while we expect residual delays, our team is working to restore our normal operations.” But the incident showed just how tightly the destiny of the airline industry is tied to the reliability and susceptibility of its electronic spine Hundreds of United Airlines flights were grounded Wednesday night as the company grappled with a major computer system failure.

Behind the operations of airlines lies a sophisticated interlocking set of systems. At their center are reservation and scheduling systems some proprietary, most using standards dating back decades like EDIFACT that manage everything from seat availability to aircraft weight and balance calculations. They feed data to an interconnected network of other systems, including departure control systems, baggage systems, and flight tracking. As one United spokesperson explained, the glitch “housed information about each flight and fed it to other computer systems, including those that calculate weight and balance and track flight times.” When the central node crashes, the entire network will freeze.
The roots of this vulnerability lie in creating global distribution systems (GDS) and central reservation systems (CRS). The industry’s initial forays into automation, such as SABRE and Apollo, revolutionized ticketing and scheduling but also tied airlines to stationary, monolithic frameworks. GDSs like Amadeus, Sabre, and Travelport, which proved invaluable later on, tied airlines to travel agencies and aggregated flight information worldwide. Yet these platforms remain founded on legacy protocols that are “outdated and rigid,” which hinder the airlines’ ability to innovate or react rapidly to disruptions EDIFACT-based infrastructure is stale and inflexible.
Later efforts at modernization, such as the IATA’s New Distribution Capability (NDC), provide XML-based data exchange with higher flexibility. However, industry-wide migration is still incomplete, and the transition has its pitfalls particularly for major carriers that depend on legacy systems as well as next-gen platforms. The result is a hybrid of new and old, where one point of failure can snowball in both worlds.
System failures are not novel to aviation. In 2022, Southwest’s flight scheduling system collapsed from a winter storm, canceling 16,900 flights and stranding more than two million travelers. The industry has come to learn, sometimes at the cost of billions, that resilience is not about redundant servers, but about the entire ecosystem’s ability to detect, isolate, and recover from failures. As one IT specialist in the aviation industry has pointed out, “In cybersecurity planning, redundancy without testing is no redundancy at all” redundancy without testing is no redundancy at all.
Airline disaster recovery plans are therefore multi-pronged. Large carriers make geo-redundant data centers, failover and failback facilities, and continuous data replication commitments. For example, a major U.S. carrier recently built a disaster recovery data center ground-up, reproducing its production environment and using isolated networks to avoid bottlenecks in performance. Extensive failover and failback testing is essential, as any errors in these mechanisms could lead to data loss or extended downtime during a natural disaster Ensuring the disaster recovery solution could support real-time failovers and failbacks was imperative.
But half the battle is technology. Human error is always there waiting in the wings as a primary cause of outages and breaches. Studies within the industry estimate that human error plays a role in about two-thirds of all outages. Continuous security awareness training, good incident response processes, and rigid endpoint security controls are critical in curbing risk human error accounts for roughly two-thirds of all outages.
Cybersecurity is a rolling concern as well. While United attributed its recent outage to something other than a cyberattack, the industry remains vigilant. Ransomware attacks, DDoS assaults, and supply chain vulnerabilities have all disrupted air travel in the past few years. Experts cite the implementation of “zero-trust architecture,” network segmentation, and persistent scanning for vulnerabilities as a means of defending against increasing sophistication zero-trust architecture.
For tourists, the consequences of IT failure are real and immediate: flight cancellations, delayed arrival, and uncertainty regarding reimbursement. Regulatory regimes are changing, with new regulations to require airlines to “promptly” and automatically give back fares for extended delays or cancellations. Yet, as travel expert John Breyault noted, There is this kind of gray area where we’re at the mercy of what the airline’s policy is. The Department of Transportation has clarified that outages attributable to airline IT or vendor failures are considered “controllable” events, placing the onus squarely on carriers to make passengers whole The Transportation Department determined that the delays and cancellations resulting from the system outage is a “controllable” event attributable to the airline.
Last but not least, the United Airlines debacle is a stark reminder that in air transportation, digital reliability must be equal to physical security. While carriers are building out the IT infrastructure, laying down disaster recovery investments, and beefing up cybersecurity, the industry must also contend with the baggage of its own technological advancement. Only by targeting both the technical and human sides of resilience can carriers expect to keep flights and passengers flying, even when the unexpected occurs.

