Don’t do SECURITY. Do business SECURELY.

Cyber attack on check-in software disrupts European airports

A ransomware attack on Collins Aerospace's MUSE check-in system disrupts Heathrow, Brussels, Berlin, and other European airports.

A cyber attack on Collins Aerospace, which provides the MUSE software that lets airlines share check-in desks and boarding gates, forced airports including Heathrow, Brussels, and Berlin Brandenburg to switch to manual check-in.

What happened

  • Disruption began on the evening of Friday 19 September 2025, causing delays and cancellations, and Brussels Airport asked airlines to cancel around half of its departures on the following Monday.
  • The EU cybersecurity agency ENISA said the disruption had been caused by a third-party ransomware incident.
  • On 23 September the UK National Crime Agency arrested a man in his forties in West Sussex on suspicion of Computer Misuse Act offences, and he was released on conditional bail.
  • Disruption continued for several days at some airports while systems were restored.

Why it mattered

It showed the aviation sector’s reliance on a few shared software suppliers and how one supplier incident can affect many operators at once. Passengers across Europe experienced the effects of an attack on a company most had never heard of.

Lessons for organisations

Identify shared suppliers that could take down several critical processes at once, and plan manual fallbacks. Exercise these fallbacks regularly so staff can use them under pressure, and agree in advance how suppliers will inform you of incidents.

Sources: TechCrunch, National Crime Agency

Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.

Get our weekly insights by emailA free weekly threat and vulnerability round-up with our threat log spreadsheet, plus legal, regulatory, standards, and AI updates.
Subscribe free

More insights