A cyber attack on Collins Aerospace, which provides the MUSE software that lets airlines share check-in desks and boarding gates, forced airports including Heathrow, Brussels, and Berlin Brandenburg to switch to manual check-in.
What happened
- Disruption began on the evening of Friday 19 September 2025, causing delays and cancellations, and Brussels Airport asked airlines to cancel around half of its departures on the following Monday.
- The EU cybersecurity agency ENISA said the disruption had been caused by a third-party ransomware incident.
- On 23 September the UK National Crime Agency arrested a man in his forties in West Sussex on suspicion of Computer Misuse Act offences, and he was released on conditional bail.
- Disruption continued for several days at some airports while systems were restored.
Why it mattered
It showed the aviation sector’s reliance on a few shared software suppliers and how one supplier incident can affect many operators at once. Passengers across Europe experienced the effects of an attack on a company most had never heard of.
Lessons for organisations
Identify shared suppliers that could take down several critical processes at once, and plan manual fallbacks. Exercise these fallbacks regularly so staff can use them under pressure, and agree in advance how suppliers will inform you of incidents.
Sources: TechCrunch, National Crime Agency
Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.