Spanish
VisaVerge official logo in Light white color VisaVerge official logo in Light white color
  • Home
  • Airlines
  • H1B
  • Immigration
    • Knowledge
    • Questions
    • Documentation
  • News
  • Visa
    • Canada
    • F1Visa
    • Passport
    • Green Card
    • H1B
    • OPT
    • PERM
    • Travel
    • Travel Requirements
    • Visa Requirements
  • USCIS
  • Questions
    • Australia Immigration
    • Green Card
    • H1B
    • Immigration
    • Passport
    • PERM
    • UK Immigration
    • USCIS
    • Legal
    • India
    • NRI
  • Guides
    • Taxes
    • Legal
  • Tools
    • H-1B Maxout Calculator Online
    • REAL ID Requirements Checker tool
    • ROTH IRA Calculator Online
    • TSA Acceptable ID Checker Online Tool
    • H-1B Registration Checklist
    • Schengen Short-Stay Visa Calculator
    • H-1B Cost Calculator Online
    • USA Merit Based Points Calculator – Proposed
    • Canada Express Entry Points Calculator
    • New Zealand’s Skilled Migrant Points Calculator
    • Resources Hub
    • Visa Photo Requirements Checker Online
    • I-94 Expiration Calculator Online
    • CSPA Age-Out Calculator Online
    • OPT Timeline Calculator Online
    • B1/B2 Tourist Visa Stay Calculator online
  • Schengen
VisaVergeVisaVerge
Search
Follow US
  • Home
  • Airlines
  • H1B
  • Immigration
  • News
  • Visa
  • USCIS
  • Questions
  • Guides
  • Tools
  • Schengen
© 2025 VisaVerge Network. All Rights Reserved.
News

EU Agency Confirms Ransomware Attack Behind Major Airport Disruptions

A ransomware attack on Collins Aerospace’s MUSE software disrupted European airports from September 19–21, 2025, forcing manual processing, causing hundreds of cancellations, and prompting ENISA-led coordination and likely regulatory reviews of third-party risk.

Last updated: September 22, 2025 9:30 am
SHARE
VisaVerge.com
📋
Key takeaways
ENISA confirmed a ransomware attack on MUSE (ARINC cMUSe) disrupted European airports between September 19–21, 2025.
Hundreds of flights were delayed or canceled at hubs including Heathrow, Brussels, Berlin Brandenburg, Dublin, and Cork.
Collins Aerospace (RTX) deployed updates and prioritized restoring busiest airports; law enforcement continues the investigation.

(LONDON) The EU Agency for Cybersecurity confirmed a major ransomware attack that disrupted airport operations across Europe between September 19 and 21, 2025, after a compromise of Collins Aerospace’s MUSE (ARINC cMUSe) software used for passenger processing. ENISA said on September 22 that the attack was ransomware-based and tied to a third-party vendor, with the specific strain identified but kept confidential while law enforcement continues its work. The impact was felt at some of the continent’s busiest hubs, including London Heathrow, Brussels, Berlin Brandenburg, Dublin, and Cork, where hundreds of flights were delayed or canceled and thousands of travelers were left in long lines.

Immediate operational impact

With automated check-in, baggage handling, and boarding systems down, airports fell back to manual methods. Staff handwrote boarding passes and baggage tags and checked passengers in using laptops and iPads.

EU Agency Confirms Ransomware Attack Behind Major Airport Disruptions
EU Agency Confirms Ransomware Attack Behind Major Airport Disruptions
  • At Brussels, nearly 140 outgoing flights were canceled in a single day as crews struggled to keep planes moving.
  • At Berlin Brandenburg on September 22, several departure lanes still posted delays of more than an hour while systems were being restored.

Collins Aerospace, part of RTX, acknowledged the cyber-related disruption and said it was in the final stages of bringing affected sites back online, prioritizing the busiest airports.

How the attack spread and why it was so disruptive

According to ENISA, the attack exploited the MUSE (ARINC cMUSe) software — the shared system that allows multiple airlines to use the same check-in and boarding infrastructure. This common-use model helps airports run more efficiently on normal days, but it also created a single point of failure that spread pain quickly when the system went down.

⚠️ Important
Relying on a single third-party system can cause widespread delays. Always plan for potential manual processing and longer queues when traveling through hubs using shared infrastructure.

Experts warned this incident shows how digital interdependence can turn a software outage into a real-world disruption, with passengers stranded, crews out of position, and flight schedules in tatters.

“A shared digital backbone can speed travel on good days, yet expose a broad set of airports to the same failure at once.”

Investigation and response

Law enforcement agencies are investigating, and authorities have not named the ransomware strain or any suspected group. ENISA said it is supporting the response and coordinating with national authorities.

  • Collins Aerospace reported it was deploying updates and working directly with airport IT teams.
  • Restoration was underway by September 22, with some hubs nearing full functionality while others still warned passengers to plan extra time.

A senior analyst at cybersecurity firm Sophos, Rafe Pilling, noted that while big ransomware cases are more visible today, truly large-scale events that affect physical operations remain rare — though that is little comfort to affected travelers and staff.

Passenger experience and practical advice

As airports worked through backlogs, the scene often resembled air travel from decades ago: long queues, paper documents, and manual checks at the counter. Staff tried to keep things moving, but the sudden shift to manual fallback meant slower passenger processing and more last-minute gate changes.

For passengers, the immediate effects were simple and frustrating: delays, cancellations, and confusion about when systems would come back. Airport social media feeds and public address systems urged travelers to arrive early, expect long lines, and keep digital boarding passes ready when possible. Even tech-savvy passengers found that apps and kiosks could not help when the core back-end services were down.

💡 Tip
Have a portable backup of essential travel documents and a printed copy of your itinerary in case apps and kiosks fail at the airport.

Practical steps passengers can take:
1. Keep government-issued ID and any travel letters within reach for manual verification.
2. Take photos of checked baggage tags and paper boarding passes before heading to security.
3. Use airline apps for real-time gate and schedule changes, but be prepared for gaps if back-end systems are down.
4. If canceled, ask the airline about rebooking options and request written confirmation at the counter.

Policy context and regulatory implications

The ransomware attack spotlights the policy side of airport tech. Third-party risk is now central to aviation resilience.

  • Contracts with vendors are likely to be reviewed to include clear cybersecurity clauses, real-time monitoring duties, and faster incident reporting.
  • Resilience plans will likely commit airports to maintain and regularly test manual fallback so staff can switch modes without chaos.
  • ENISA’s role as coordinator underscores the importance of a shared response framework. For official updates and technical guidance, travelers and industry professionals can consult ENISA.

Experts expect regulators to examine whether current rules are strong enough for systems that serve many airlines at once. Possible policy actions include better segmentation so a single compromised application cannot bring down check-in across multiple terminals, and joint drills simulating cyber outages, including communication dry runs.

What airports and airlines are doing next

While the investigation continues, airport operators are focusing on three main areas:

📝 Note
If you’re affected, request written confirmation of rebooking and keep it; it helps when lining up a new schedule amid system outages.
  • Strengthening monitoring of third-party vendors tied to passenger processing tools like MUSE (ARINC cMUSe).
  • Building more redundancy so that a digital failure does not escalate into mass cancellations.
  • Improving public communications, including simple, timely guidance during manual processing periods.

Cybersecurity specialists emphasize limiting the blast radius when a compromise occurs. That means segmenting systems, testing manual procedures regularly, and agreeing on recovery priorities across large hubs. Collins Aerospace’s phased restoration — prioritizing the busiest airports — reflects such triage.

Key takeaways

  • The compromise of a widely used third-party system can produce continent-wide disruption.
  • Manual fallbacks prevented a total standstill but revealed vulnerabilities in contingency preparedness.
  • Regulatory scrutiny and contractual changes are likely, focusing on third-party risk and resilience testing.
  • For travelers: check with your airline before leaving home, build in extra time, carry paper copies of key documents, and follow airport advisories until systems are fully restored.

ENISA’s confirmation and the ongoing law enforcement work show that authorities are treating the incident as a serious threat to critical infrastructure. The sector faces tough questions on vendor oversight, service-level cybersecurity obligations, and how often airports should validate manual backups to avoid similar chaos in future.

VisaVerge.com
Learn Today
ENISA → European Union Agency for Cybersecurity, coordinates cybersecurity response and guidance across EU member states.
Ransomware → Malicious software that encrypts or locks systems or data, often demanding payment to restore access.
MUSE (ARINC cMUSe) → Common-use passenger processing software allowing multiple airlines to share check-in and boarding infrastructure.
Collins Aerospace → Aerospace and avionics company (part of RTX) that provides passenger processing systems including MUSE.
Shared digital backbone → A central system or platform used by multiple organizations that can become a single point of failure if compromised.
Manual fallback → Non-digital procedures—like handwritten boarding passes and manual passport checks—used when automated systems fail.
Third-party risk → The potential for vendors or suppliers to introduce vulnerabilities that affect an organization’s security or operations.

This Article in a Nutshell

A major ransomware attack between September 19–21, 2025, compromised Collins Aerospace’s MUSE (ARINC cMUSe) passenger-processing software, disrupting automated check-in, baggage handling and boarding across multiple European airports, including Heathrow, Brussels, Berlin Brandenburg, Dublin and Cork. The outage forced airports to revert to manual processes, causing long queues, hundreds of cancellations and thousands of passengers affected. ENISA confirmed the ransomware nature on September 22 and is coordinating with national authorities while law enforcement investigates. Collins Aerospace deployed updates and prioritized restoration at busiest hubs. The incident highlights risks from shared third-party systems, prompting likely regulatory reviews, stronger vendor cybersecurity clauses, improved redundancy and regular testing of manual fallbacks.

— VisaVerge.com
Share This Article
Facebook Pinterest Whatsapp Whatsapp Reddit Email Copy Link Print
What do you think?
Happy0
Sad0
Angry0
Embarrass0
Surprise0
Jim Grey
ByJim Grey
Senior Editor
Follow:
Jim Grey serves as the Senior Editor at VisaVerge.com, where his expertise in editorial strategy and content management shines. With a keen eye for detail and a profound understanding of the immigration and travel sectors, Jim plays a pivotal role in refining and enhancing the website's content. His guidance ensures that each piece is informative, engaging, and aligns with the highest journalistic standards.
Subscribe
Login
Notify of
guest

guest

0 Comments
Inline Feedbacks
View all comments

Verging Today

September 2025 Visa Bulletin Predictions: Family and Employment Trends
Immigration

September 2025 Visa Bulletin Predictions: Family and Employment Trends

Trending Today

September 2025 Visa Bulletin Predictions: Family and Employment Trends
Immigration

September 2025 Visa Bulletin Predictions: Family and Employment Trends

Allegiant Exits Airport After Four Years Amid 2025 Network Shift
Airlines

Allegiant Exits Airport After Four Years Amid 2025 Network Shift

Breaking Down the Latest ICE Immigration Arrest Data and Trends
Immigration

Breaking Down the Latest ICE Immigration Arrest Data and Trends

New Spain airport strikes to disrupt easyJet and BA in August
Airlines

New Spain airport strikes to disrupt easyJet and BA in August

Understanding the September 2025 Visa Bulletin: A Guide to U.S. Immigration Policies
USCIS

Understanding the September 2025 Visa Bulletin: A Guide to U.S. Immigration Policies

New U.S. Registration Rule for Canadian Visitors Staying 30+ Days
Canada

New U.S. Registration Rule for Canadian Visitors Staying 30+ Days

How long it takes to get your REAL ID card in the mail from the DMV
Airlines

How long it takes to get your REAL ID card in the mail from the DMV

United Issues Flight-Change Waiver Ahead of Air Canada Attendant Strike
Airlines

United Issues Flight-Change Waiver Ahead of Air Canada Attendant Strike

You Might Also Like

Over 400 Flights Canceled at Hartsfield Due to Severe Storm
News

Over 400 Flights Canceled at Hartsfield Due to Severe Storm

By Robert Pyne
Azorra Flips Script on A220-300 ‘Breakup’ Plan
News

Azorra Flips Script on A220-300 ‘Breakup’ Plan

By Robert Pyne
Immigration Agents Allegedly Fire at Truck, Shattering Car Window
Immigration

Immigration Agents Allegedly Fire at Truck, Shattering Car Window

By Shashank Singh
Regula Collaborates to Install ID Scanners in European Airports
News

Regula Collaborates to Install ID Scanners in European Airports

By Visa Verge
Show More
VisaVerge official logo in Light white color VisaVerge official logo in Light white color
Facebook Twitter Youtube Rss Instagram Android

About US


At VisaVerge, we understand that the journey of immigration and travel is more than just a process; it’s a deeply personal experience that shapes futures and fulfills dreams. Our mission is to demystify the intricacies of immigration laws, visa procedures, and travel information, making them accessible and understandable for everyone.

Trending
  • Canada
  • F1Visa
  • Guides
  • Legal
  • NRI
  • Questions
  • Situations
  • USCIS
Useful Links
  • History
  • Holidays 2025
  • LinkInBio
  • My Feed
  • My Saves
  • My Interests
  • Resources Hub
  • Contact USCIS
VisaVerge

2025 © VisaVerge. All Rights Reserved.

  • About US
  • Community Guidelines
  • Contact US
  • Cookie Policy
  • Disclaimer
  • Ethics Statement
  • Privacy Policy
  • Terms and Conditions
wpDiscuz
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?