How a cyberattack on a software product brought EU airports to a halt
Security incident at RTX subsidiary Collins Aerospace
Cybersecurity has made it into the daily press again, and airports too. Sound familiar? That could be due to the Crowdstrike case, which happened about a year ago.
Updated on Nov 3, 2025.
What happened?
At airports in Berlin, Brussels, Dublin, and London, passenger check-in had to be done manually in some cases (with pen and paper, I imagine it to look something like the picture above), which led to long waiting times, delays, and canceled flights over several days.
Unlike Crowdstrike, where a security solution managed to paralyze airports without any attackers, this time there was an attack, probably on September 19.
However, it was not a direct attack on the airports, but on the software provider Collins Aerospace — more specifically its cMUSE software. The Collins software ARING cMUSE is used for passenger processing — i.e., for processes such as check-in and baggage drop-off.
What kind of attack was it and how is Collins dealing with it?
There is almost no information about the nature of the attack and how the software company is dealing with it, except for the report of the incident by Collins’ publicly traded parent company RTX to the US Securities and Exchange Commission on September 19. The report also states that it was a ransomware attack — and, of course, that no financial impact on the publicly traded parent company RTX is expected.
There is no information from Collins Aerospace itself, a US company that provides technical solutions for commercial and military aerospace.
Some media articles refer to information from the EU cybersecurity agency ENISA, according to which the exact ransomware group is known to ENISA.
A German Tagesschau news report from September 24 states that Collins Aerospace “appears to be rebuilding the system after attempting to restart it on Monday.” The Wikipedia article on the incident states that on September 29, Collins began rolling out a “replacement system” at Brussels Airport. The reports do not indicate whether this replacement system comes from a backup or whether everything is being rebuilt from scratch.
How is the attack being interpreted by the media?
Many articles offer calming reassurances: aviation security was not compromised at any time, and the attack was not actually an attack on airports, which were only indirectly affected — collateral damage, so to speak.
At a time when Russian aircraft are constantly showing up in places where they don’t belong, these reassurances certainly make sense.
The air safety argument is credible; passenger handling is really far removed from software that could compromise air safety. But Collins also develops software solutions for cockpits, engines, and air traffic controllers, for example.
The collateral damage hypotheses remains exactly that: a hypothesis — at least if it is only based on what’s known publicly. Sure, it could have been a ransomware gang with purely economic interests, in which case an airline is just as much a random target as a gummy bear factory. But even if the goal was actually to paralyze air traffic, a software provider for airports would be a good choice from an attacker’s point of view.
A closer look at the product security incident
Regardless of whether the impact on airports was intentional or not, from an operator’s perspective, this remains a supply chain incident in which an attack on a software supplier has had an impact on the operator.
And in any case, it is a product security incident. If the CRA were already in force, Collins Aerospace would now have to report to ENISA, at least for a “severe incident,” and perhaps also for an “actively exploited vulnerability.”
In its official statement, RTX notably confirms explicitly a “product cybersecurity incident involving ransomware on systems that support its Multi-User System Environment (‘MUSE’) passenger processing software.”
According to the Collins website, cMUSE can be used in the cloud, on-premises, or in a hybrid configuration; however, there is no information on which model the affected airports have chosen.
The RTX report states that the MUSE systems are operated at the airports in their own networks, “outside the RTX Enterprise network.” That sounds like an on-premises installation.
The truly compelling question from a product security perspective remains unanswered: How did the ransomware get onto the “support systems” for the MUSE software for the Collins software installations at the four airports?
If we knew that, we would also know how much we need to worry about Collins Aerospace’s other products, which may be more interesting from an attacker’s point of view. After all, these carry out such minor functions as navigation, communication, radar, and targeting systems for military aircraft.
Update on November 3, 2025: Clumsy incident management?
The hacker group Everest has now commented on the incident. And apparently, the answer to the above question (how did ransomware at the parent company lead to the failure of on-premise product instances at airports?!) is much more mundane than expected.
But let’s start from the beginning.
In the communication vacuum on the part of Collins/RTX, the hacker group Everest, which claims to be behind the attack, has explained its actions.
The term “ransomware” is only accurate in a broad sense. Everest did not encrypt any data, but downloaded user data via an FTP access point with a weak password. Then the group demanded ransom from Collins by threatening to publish the data. Instead of paying the ransom, Collins apparently shut down the systems completely.
If this version is correct (a hacker group is not at the top of the list of trustworthy sources), the incident was — as is so often the case — rather trivial:
A weak password for FTP access enabled data theft, the attackers threatened to leak the data, and the blackmailed company took the systems offline — which did not prevent the data leak.
No fancy hack. No “sophisticated attacker.” No zero days needed. But also no good incident management on Collins’ part:
Leaving communication to the attackers, not preventing the impact on users, but making it worse. Because in addition to the data leak, there were also system failures.
So how did the ransomware get into the on-premise product instances? If the Everest Group’s reports are correct, the surprising answer is: it didn’t. Collins shut down the systems itself in response to Everest’s blackmail. Of course, this did not prevent the publication of user data that had already been leaked.
So the system failures were not directly caused by the attackers, as the ransomware message suggested, but rather by Collins Aerospace’s clumsy incident management.
This article was originally published as part of the monthly “Security Briefing for Hard Hats.” You can subscribe here.
