
by Lacey Pfalz
Last updated: 9:00 AM ET, Mon September 22, 2025
The European Union Agency for Cybersecurity (ENISA) has reported that the multiple European airports that got hacked this weekend held boarding and check-in software for ransom.
According to the BBC, the hacks, which caused flight delays and cancellations in Berlin, Brussels and London Heathrow all targeted a Collins Aerospace check-in and boarding software called Muse, which hackers disrupted and scrambled, holding it for ransom in exchange for bitcoin.
The agency does not yet know which cybercriminal group was behind the attack, which began Friday, though French aerospace company Thales noted that cyberattacks in aviation have increased 600 percent from 2024.
"The type of ransomware has been identified. Law enforcement is involved to investigate," the agency told Reuters.
Every airport impacted reported using manual workarounds to continue boarding and checking in passengers, though delays were the most common reported issue.
London Heathrow, a major international hub, put out a notice on its website that “Work continues to resolve and recover from an outage of a Collins Aerospace airline system that impacted check-in. We apologise to those who have faced delays, but by working together with airlines, the vast majority of flights have continued to operate.”
“We encourage passengers to check the status of their flight before travelling to Heathrow and to arrive no earlier than three hours for long-haul flights and two hours for short-haul.”
Travelers transiting or flying through any of the impacted airports are encouraged to remain in contact with their airline for updates and to head to the airport earlier than usual to allow for extra delays.
Collins Aerospace, meanwhile, refers to the hack at a “cyber incident,” and issued a statement on Monday that it was completing a software update. An internal memo seen by the BBC and sent to London Heathrow staff says that Collins Aerospace had rebuilt and relaunched Muse only to later realize the hackers were still inside. The same memo says over a thousand computers might have to be fixed in person, rather than remotely.
This year, cybercriminal group Scattered Spider was blamed for several different hacks at specific airlines in North America, including Hawaiian Airlines and WestJet. The FBI has warned of an increase in potential cyber threats towards aviation, since holding operations ransom would greatly impact thousands of people.
Topics From This Article to Explore