Major European airports work to restore services after cyberattack on check-in systems

Europe’s busiest airports are still struggling to restore normal operations on Monday after a suspected ransomware attack on a U.S. aviation technology provider crippled check-in systems in London, Brussels, Berlin and Ireland.

The attack targeted Collins Aerospace, a subsidiary of defense giant RTX, whose vMUSE self-service software is used for passenger check-in, baggage tagging and boarding. The disruption, which began Friday night, forced thousands of travelers into long lines at manual counters and led to hundreds of flight delays and cancellations over the weekend.

The European Union’s cybersecurity agency, ENISA, said Monday that the disruptions were caused by a “third-party ransomware incident.” The agency said it identified the type of ransomware but declined to publicly specify it. The threat actor remains unknown. 

Brussels Airport asked airlines to cancel nearly half of Monday’s departures, warning that the outage continued to have a “large impact on the flight schedule.” Dublin Airport said some airlines were still issuing bag tags and boarding passes manually, cautioning passengers that check-in and bag drop would take longer than usual.

London’s Heathrow Airport said the “vast majority of flights” operated on Sunday and Monday, but Collins’ systems were still being restored. British Transport Minister Heidi Alexander said in a post on X that she was receiving regular updates and monitoring the situation.

In Berlin, disruption had eased by Sunday, according to local media reports, though passengers continued to face delays as the airport warned of “longer waiting times” and urged travelers to use online check-in before arriving.

RTX told Reuters the cyberattack’s impact was “limited to electronic customer check-in and baggage drop” and stressed that manual systems provided a workaround. Collins Aerospace said Monday it was in the “final stages” of software fixes.

Collins Aerospace and RTX have not replied to requests from Recorded Future News for comment.

The aviation sector has faced a string of cyber incidents in recent months. Last week, one of Russia’s busiest airports said its website was knocked offline in a cyberattack. In July, Australian airline Qantas disclosed a breach that exposed customer data.

U.S. law enforcement has previously warned that the Scattered Spider cybercrime group has been targeting airlines, including Hawaiian Airlines and Canada’s WestJet.

Get more insights with the

Recorded Future

Intelligence Cloud.

Learn more.

No previous article

No new articles

Daryna Antoniuk

Daryna Antoniuk

is a reporter for Recorded Future News based in Ukraine. She writes about cybersecurity startups, cyberattacks in Eastern Europe and the state of the cyberwar between Ukraine and Russia. She previously was a tech reporter for Forbes Ukraine. Her work has also been published at Sifted, The Kyiv Independent and The Kyiv Post.

 

Total
0
Shares
Previous Post

⚡ Weekly Recap: Chrome 0-Day, AI Hacking Tools, DDR5 Bit-Flips, npm Worm & More

Next Post

Future of CVE Program in limbo as CISA, board members debate path forward

Related Posts

WrtHug Exploits Six ASUS WRT Flaws to Hijack Tens of Thousands of EoL Routers Worldwide

A newly discovered campaign has compromised tens of thousands of outdated or end-of-life (EoL) ASUS routers worldwide, predominantly in Taiwan, the U.S., and Russia, to rope them into a massive network. The router hijacking activity has been codenamed Operation WrtHug by SecurityScorecard's STRIKE team. Southeast Asia and European countries are some of the other regions where infections have
Read More

Analysing ClickFix: 3 Reasons Why Copy/Paste Attacks Are Driving Security Breaches

ClickFix, FileFix, fake CAPTCHA — whatever you call it, attacks where users interact with malicious scripts in their web browser are a fast-growing source of security breaches.  ClickFix attacks prompt the user to solve some kind of problem or challenge in the browser — most commonly a CAPTCHA, but also things like fixing an error on a webpage.  The name is a little misleading, though
Read More

North Korean Hackers Lure Defense Engineers With Fake Jobs to Steal Drone Secrets

Threat actors with ties to North Korea have been attributed to a new wave of attacks targeting European companies active in the defense industry as part of a long-running campaign known as Operation Dream Job. "Some of these [companies] are heavily involved in the unmanned aerial vehicle (UAV) sector, suggesting that the operation may be linked to North Korea's current efforts to scale up its
Read More