A cyberattack targeting Collins Aerospace, a key provider of check-in and boarding systems, caused significant operational disruption at major European airports including Heathrow, Brussels, and Berlin. The attack rendered automated check-in and baggage drop systems inoperable, forcing airports to revert to manual processes, resulting in widespread delays and cancellations. No evidence of data theft or ransomware has been reported, but the incident highlights the critical risk posed by third-party vendor vulnerabilities in aviation infrastructure.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
Subsequent reporting said ENISA identified the attackers' initial access path as coming through one of Collins Aerospace's third-party providers. This introduced a new supply-chain dimension to the ransomware incident affecting the ARINC vMUSE platform.
UK authorities announced the arrest of a man in connection with the cyberattack that disrupted European airports. The arrest marked the first known law enforcement action publicly tied to the incident.
Reporting indicated Collins Aerospace was deploying a software update to recover the Muse system and restore airport operations. Despite progress, some delays were still lingering into Monday.
The EU cybersecurity agency ENISA said the Collins Aerospace incident behind the airport disruptions was a ransomware attack. This clarified the nature of the attack after initial reporting had described it more generally as a cyberattack.
By Sunday, some affected airports reported easing conditions, though operational delays and restoration work continued. Collins Aerospace, ENISA, and the UK National Cyber Security Centre were involved in recovery coordination.
RTX, the parent company of Collins Aerospace, acknowledged a 'cyber-related disruption' impacting the Muse platform at select airports. The statement confirmed the vendor-side incident behind the airport operational problems.
On Saturday, major European airports including Heathrow, Brussels, Berlin, Dublin, and Cork reported delays, cancellations, and check-in disruption linked to the Collins Aerospace incident. Airports and airlines switched to manual processes while recovery efforts began.
A cyber incident struck Collins Aerospace's Muse airport software late Friday, disrupting the platform used for check-in and related airport operations. The attack affected select airports relying on the system.
29 references tracked. Mallory keeps watching after this page renders.
upguard.com
Open sourcebbc.co.uk
Open sourcetherecord.media
Open sourcehackread.com
Open sourcegovinfosecurity.com
Open sourcehackread.com
Open sourcebankinfosecurity.com
Open sourceblog.sucuri.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.