Since the night of Friday 19 September, passengers at several of Europe’s busiest airports have faced long queues and delays after the check-in system many airlines share there went down. The EU’s cybersecurity agency ENISA has now confirmed the cause: a ransomware incident at a third-party supplier, not at the airports themselves.
What happened
The system at the centre of this is MUSE, passenger processing software made by Collins Aerospace, a company owned by RTX. MUSE lets several airlines use the same check-in desks and boarding gates, so an airport does not need separate equipment for each carrier. That sharing is efficient on a normal day. When the software fails, it fails for everyone at once.
Heathrow in London, Brussels and Berlin were among the hubs hit. On Monday, ENISA told TechCrunch: “ENISA is aware of the ongoing disruption of airports’ operations, which were caused by third-party ransomware incident.”
Officials have not said which ransomware group or strain was involved. There are reports circulating with a name attached, but none has been officially confirmed, so I am leaving it out. The same goes for how the attackers got in: no official account has been published yet.
Who is affected
The people feeling this most are travellers checking in at the affected airports, especially those flying with airlines that rely on the shared desks rather than their own systems. Airline and airport staff are also under pressure while the shared system is unavailable.
The less visible group is every organisation that depends on one supplier for a critical, customer-facing service. What caught my attention here is that none of the airports appears to have been breached directly. They were hit because they all used the same product from the same vendor. In security terms that is concentration risk, and this weekend showed what it looks like in practice.
By the numbers
| Item | Detail as of 22 September 2025 |
|---|---|
| Disruption began | Night of Friday 19 September 2025 |
| Major hubs named | 3: Heathrow, Brussels, Berlin |
| Affected software | MUSE passenger processing |
| Software maker | Collins Aerospace, owned by RTX |
| Cause confirmed by ENISA | Third-party ransomware incident |
| Ransomware strain | Not officially confirmed |
What to do now
If you are flying from one of these airports in the next few days, check your airline’s app or website for the latest instructions before you leave home, allow extra time, and check in online where your airline offers it. That part is common sense.
For organisations, the more lasting lesson comes from the US Cybersecurity and Infrastructure Security Agency (CISA) and its #StopRansomware Guide. Its core recommendations map closely onto what went wrong here:
- Keep offline, encrypted backups and test restoration regularly. Recovery speed after ransomware depends on having clean copies the attackers could not reach, and on knowing that you can actually restore them.
- Segment your networks so that a compromise in one system cannot spread to others. A problem in one application should not become a problem everywhere.
- Maintain a manual fallback process for critical customer-facing operations, whether on paper or on offline equipment. If check-in software can fail across several countries at once, any business system can. Write your fallback down and practise it before you need it.
- Require multi-factor authentication for all remote and privileged access, and review third-party vendor access. Know which suppliers can reach your systems, what they can touch, and how quickly you could cut them off.
To those four I would add a planning question for any manager: list the outside services you could not operate a single day without, and ask each vendor what their own recovery plan looks like.
Why it matters
Airports were not careless here in any obvious way. They bought a widely used product to share infrastructure efficiently, and when that product was hit, several countries felt it at the same time. That is the uncomfortable trade-off of shared software: it lowers cost and raises the stakes of a single failure.
For smaller businesses the scale is different but the logic is the same. A booking platform, a payment provider or a cloud accounting tool can be your MUSE. In my view the honest response is not to avoid suppliers, which is impossible, but to know which ones matter most, keep a way to work without them for a while, and make sure your backups are yours.
The investigation is continuing, and I will update readers when Collins Aerospace or the authorities share more.
Sources
- TechCrunch, “EU cyber agency confirms ransomware attack causing airport disruptions”, 22 September 2025, https://techcrunch.com/2025/09/22/eu-cyber-agency-confirms-ransomware-attack-causing-airport-disruptions/
- CISA, “#StopRansomware Guide”, guidance page, accessed 22 September 2025, https://www.cisa.gov/stopransomware/ransomware-guide