August 14, 2026

Impact of Cyberattacks on Critical Infrastructure and Air Travel

An American Airlines American Eagle jet flies past the air traffic control tower at Phoenix Sky Harbor International Airport, Nov. 8, 2025, in Phoenix. (Ross D. Franklin, Associated Press file)

Recent cyberattacks on water systems across several states illustrate the risks to cyber physical systems supporting vital infrastructure. Cyberattacks have become frequent, often going unnoticed unless they have direct implications. In 2024 alone, there were over 859,000 cyberattacks, averaging almost 100 every hour. Financial losses reached nearly $17 billion, a significant rise from $2.7 billion in 2018.

Among these attacks, close to 4,900 targeted critical infrastructures essential to both the physical and digital economy. Noteworthy was the ransomware attack on Canvas in May, a platform serving K-12, higher education, and corporate training centers, impacting millions.

Centralized data management sites are particularly vulnerable to disruptions. One such example is air travel, involving over 2.5 million people daily. The passenger service system, central in managing airline reservations and passenger activities, enhances the efficiency of air travel but also exposes it to significant risks.

Past cyberattacks highlight the vulnerabilities. In 2025, air travel disruptions in Europe necessitated manual processing, demonstrating the risk of centralization. Handling 2.5 to 3 million passengers daily with manual methods would severely impair air travel, posing challenges for the Transportation Security Administration in securing the national airspace.

Even non-malicious computer outages, like American Airlines’ incident on July 28, show system vulnerabilities. The 2024 CrowdStrike update bug affected Windows systems, compelling airlines to revert to manual check-ins. Delta Airlines reported a $500 million loss due to flight cancellations, showcasing the economic damages of centralized system failures even without cyberattacks.

Similar centralized or hybrid systems exist across numerous critical infrastructures, optimizing oversight yet increasing susceptibility to cyberattacks. For instance, the Federal Reserve’s hybrid system, though decentralized across 12 banks, processes many transactions. Any disruption could delay payments and impede financial activities.

Centralization boosts efficiency but heightens risks, a tradeoff critical in designing complex systems. Our digital economy requires careful risk-benefit assessments. Despite minimizing risks to avoid worst-case scenarios, issues like the Canvas attack highlight potential negative outcomes.

This balance reflects the cost of partaking in a highly connected digital economy. Rare events, while uncommon, can be highly disruptive and costly, particularly in critical infrastructures.

Sheldon H. Jacobson, Ph.D., a Computer Science professor at the University of Illinois Urbana-Champaign, specializes in data-driven, risk-based decision-making to inform public policy.

TAGS: