Security

Ransomware attack on Collins Aerospace MUSE software disrupts European airports

A ransomware attack on Collins Aerospace's MUSE check-in platform forced Heathrow, Brussels, Berlin Brandenburg and Dublin to adopt manual boarding, with Brussels cancelling 140 flights on September 22.

T
By TechQuire Daily Staff TechQuire Daily Staff
September 21, 2026 / 7 min read

Late on Friday, September 19, 2026, a cyberattack struck Collins Aerospace's MUSE software, a check-in and boarding platform used by multiple airlines at airports across Europe. The disruption forced Heathrow Airport, Brussels Airport, Berlin Brandenburg Airport, and later Dublin Airport to abandon electronic check-in and boarding and revert to manual operations, with staff using pen and paper and handwriting boarding passes. The incident began when systems operated by Collins Aerospace, a subsidiary of RTX Corp., suffered what the company called a cyber-related disruption. MUSE, which stands for Multi-User System Environment, allows airlines to share check-in desks and boarding gate positions, making it a central piece of airport infrastructure.

Collins Aerospace is an American aviation and defense technology company owned by publicly traded RTX. Its MUSE software helps passengers check themselves in, print boarding passes and bag tags, and dispatch luggage from kiosks. The company has touted an optional integration with Amazon Web Services cloud infrastructure. Airports said the issue centered around a provider of check-in and boarding systems, not airlines or the airports themselves.

Initial reports on Saturday, September 20, described a limited but serious impact. By mid-morning, Brussels Airport spokesperson Ihsane Chioua Lekhli told broadcaster VTM that nine flights had been canceled, four were redirected to another airport, and 15 faced delays of an hour or more. Axel Schmidt, head of communications at Berlin Brandenburg Airport, said that by late morning the airport had no flights canceled due to the specific reason, but that could change. Berlin airport operators cut off connections to affected systems. Heathrow, Europe's busiest airport, said the disruption had been minimal with no flight cancellations directly linked to the problems afflicting Collins.

Collins Aerospace said it was actively working to resolve the issue and that the impact was limited to electronic customer check-in and baggage drop, which could be mitigated with manual check-in operations. The UK National Cyber Security Centre said it was working with Collins Aerospace and affected UK airports, alongside Department for Transport and law enforcement colleagues, to fully understand the impact. By Monday, September 22, the European Union Agency for Cybersecurity, known as ENISA, confirmed that a third-party ransomware attack was behind the disruption and that the type of ransomware had been identified while law enforcement investigated.

Key Facts

The operational toll mounted quickly. Reuters reported on September 22 that Brussels Airport canceled 25 departing flights the next day and 50 the day after, then scrapped 140 flights scheduled for September 22 because Collins Aerospace was not yet able to deliver a new secure version of the check-in system. Brussels officials said 85 percent of scheduled flights were still operated over the weekend, thanks to extra staffing and the use of self-bag drop and online check-in.

At Heathrow, the impact grew. BankInfoSecurity reported on September 20 that the incident led to at least 29 flight cancellations at Heathrow, Europe's busiest and the fourth most transited airport in the world, as well as disruption at Berlin Brandenburg and Brussels Airport. By late Saturday, Dublin Airport also reported service disruptions tied to the hack. British Transport Secretary Heidi Alexander said she was aware of an incident affecting airline check-in and boarding, impacting flights at Heathrow and other European airports.

By the fourth day of the outage, FlightRadar24 data painted a stark picture. GCN reported on September 22 that 90 percent of Heathrow flights were delayed with an average delay of 29 minutes; Brussels had 88 percent of flights delayed with an average delay of 43 minutes; Berlin Brandenburg had 94 percent of flights delayed with an average delay of one hour; and Dublin had 91 percent of flights delayed. Dublin Airport spokesperson Graeme McQueen told TechCrunch that there was no timeline at the current time for a fix to be implemented.

ENISA's confirmation on Monday, September 22, provided the clearest official attribution. Industrial Cyber reported on September 22 that ENISA said a third-party ransomware attack caused the disruptions, that the type of ransomware had been identified, and that law enforcement was investigating. The agency's statement did not name a culprit. The European Commission said air traffic control and aviation safety were unaffected, and investigators had found no sign of a large-scale or severe attack. Eurocontrol asked airlines to cancel half of Brussels flights for the Saturday to Sunday window.

Heathrow Airport said work continues to resolve and recover from the outage of a Collins Aerospace airline system that impacted check-in, and it apologized to those who faced delays while noting that the vast majority of flights had continued to operate. The Associated Press reported on September 20 that many other European airports said their operations were unaffected, highlighting that the disruption was concentrated among a specific set of hubs.

Analysis

The bigger picture here is that a single vendor's software can become a choke point for an entire region's aviation network. Collins Aerospace's MUSE platform is used by multiple airlines to share check-in desks and boarding gate positions, so when it fails, the failure is not confined to one carrier or one terminal. Cody Barrow, CEO at EclecticIQ, wrote that the attack is a clear reminder of how fragile aviation operations can be when critical systems depend on a handful of third-party providers. By targeting a single vendor, attackers were able to disrupt airports across multiple countries, a textbook example of supply chain risk in action.

The response also reveals how much manual capacity still exists in a highly digitized industry. Airports reverted to pen and paper, handwriting boarding passes, pulling out laptops, and using self-bag drop and online check-in to keep passengers moving. Brussels said 85 percent of scheduled flights still operated over the weekend using extra staffing. That is a notable operational achievement, but it also underscores the cost: long queues, delays measured in hours, and cancellations that persisted for days.

Attribution remains unresolved. Experts said hackers, organized crime, or state-backed groups could be responsible, though no culprit has been identified. Meanwhile, the UK National Cyber Security Centre urged organizations to make use of its free guidance and tools to help reduce cyber attack chances. The incident has become a case study in third-party risk, but the absence of a named attacker leaves open questions about motive and persistence.

The commercial relationship between Collins Aerospace and major airports adds another layer. Heathrow in April inked a six-year renewal agreement with RTX to continue deploying MUSE software in all four passenger terminals. When Brussels Airport said Collins Aerospace was not yet able to deliver a new secure version of the check-in system, it signaled that recovery would not be a simple restart. The airport canceled 140 flights for September 22 as a direct result.

Why It Matters

The disruption affected millions of travelers across Europe's busiest hubs. Heathrow, Brussels, Berlin Brandenburg, and Dublin are major gateways, and the delays and cancellations rippled through connecting itineraries and airline schedules. FlightRadar24 data on the fourth day showed 90 percent of Heathrow flights delayed, 88 percent at Brussels, 94 percent at Berlin Brandenburg, and 91 percent at Dublin.

The incident also puts a spotlight on the European Union's cybersecurity response and the role of ENISA. The agency's confirmation that ransomware was the cause gave the public an official explanation after days of speculation. The European Commission said air traffic control and aviation safety were unaffected, and investigators found no sign of a large-scale or severe attack. Still, the operational disruption was severe enough to force Brussels to cancel nearly half its departures on September 22.

For the aviation sector, the event reinforces a lesson that regulators and operators have been slow to fully absorb. Critical services often depend on a small number of third-party providers, and those providers can become single points of failure. The UK National Cyber Security Centre's involvement, alongside the Department for Transport and law enforcement, shows that governments treat such incidents as national infrastructure concerns. The same pattern could apply to other shared platforms in travel, logistics, or payments.

Next Up

Recovery timelines remain uncertain. Dublin Airport's spokesperson, Graeme McQueen, told TechCrunch that there was no timeline at the current time for a fix to be implemented, while airlines continued to deploy manual workarounds. Brussels Airport warned of disrupted operations again on Monday, September 22, and advised passengers to check flight status before coming to the airport. Collins Aerospace said it was actively working to resolve the issue and restore full functionality to its customers as quickly as possible, but the company had not yet delivered a new secure version of the check-in system as of September 22.

Investigators are still working to identify the attackers. ENISA said the type of ransomware had been identified and law enforcement was investigating, but no culprit has been named. Experts said hackers, organized crime, or state-backed groups could be responsible. In the meantime, airports and airlines will continue to rely on manual check-in and backup systems, and the incident is likely to intensify scrutiny of how shared aviation software is secured, tested, and supported.

Tagged

Comments (0)

No comments yet. Be the first to share your thoughts.