A ransomware attack targeting Collins Aerospace's passenger processing software caused widespread disruptions at major European airports, including London Heathrow, Berlin Brandenburg, and Brussels. The attack, which began on September 19, affected the ARINC SelfServ cMUSE and MUSE systems used for check-in and baggage handling, forcing airports to switch to manual processes and resulting in hundreds of flight cancellations and extensive delays. The UK's National Crime Agency arrested a man in West Sussex on suspicion of Computer Misuse Act offences in connection with the incident, though the investigation remains ongoing. RTX Corporation, the parent company of Collins Aerospace, confirmed the attack and stated that the affected systems operate on customer-specific networks outside the main RTX enterprise network. The incident highlights the significant operational impact ransomware can have on critical aviation infrastructure.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
UK law enforcement arrested a man in connection with the cyberattack on Collins Aerospace software that disrupted airport operations. Multiple outlets reported the arrest as a key development in the investigation into the Heathrow-related incident.
The attack caused operational disruption at Heathrow Airport and elsewhere, leading to flight chaos and check-in problems as affected software became unavailable. News reports describe the incident as having a significant knock-on effect on airport operations.
A cyberattack targeted Collins Aerospace systems used for airline check-in and related airport operations, disrupting services relied on by multiple airports and carriers. The incident was later linked in reporting to RTX, Collins Aerospace's parent company.
5 references tracked. Mallory keeps watching after this page renders.
go.theregister.com
Open sourceindependent.co.uk
Open sourcebleepingcomputer.com
Open sourcescworld.com
Open sourcebankinfosecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.