Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Ransomware

European Airport Disruptions Caused by Ransomware Attack

Collins Aerospace is reportedly having difficulties recovering from the ransomware attack.

Collins Aerospace ransomware attack hits airports

The cybersecurity incident impacting Collins Aerospace, which led to disruptions at several major airports across Europe, was the result of a ransomware attack, according to the EU cybersecurity agency ENISA. 

ENISA said the type of ransomware involved in the attack has been identified and law enforcement is conducting an investigation, but the agency did not share further information.

The cyberattack hit services provided by US-based Collins Aerospace, which is owned by RTX (formerly Raytheon). Collins Aerospace is one of the world’s largest suppliers of aerospace and defense solutions. The company was recently awarded a NATO contract for electromagnetic warfare solutions. 

Collins technology is used at airports to enable passengers to check in, print boarding passes and luggage tags, and dispatch their bags. The cyberattack has impacted check-in and boarding systems at major airports, forcing them to turn to manual processes. This resulted in delays and flights being cancelled.  

The incident has impacted airports in the UK, Germany, Belgium, and Ireland, including London’s Heathrow, Brussels Airport, and Berlin Brandenburg.

While Heathrow said a vast majority of its flights continued to operate and delays were not significant, Brussels Airport experienced substantial disruptions, reportedly asking airlines to cancel nearly 140 flights on Monday.

Advertisement. Scroll to continue reading.

The UK’s National Cyber Security Centre issued a statement over the weekend to inform the public that it’s working with the country’s Department of Transport to investigate the incident.

An internal memo from London’s Heathrow airport, obtained by the BBC, revealed that over a thousand computers may have been corrupted and remote restoration is not possible. In addition, according to the memo, Collins found that the hackers had still been inside its network after it rebuilt and relaunched systems. 

Cybersecurity expert Kevin Beaumont has been monitoring the incident and believes the attack hit ARINC communications and information processing services, specifically SelfServ vMUSE systems. 

The researcher pointed out that dozens of ARINC-related systems appear to be exposed to the internet, and some of them seem to be lacking important security mechanisms. 

Beaumont also noted that the incident led to users of the ARINC system at airports being unable to log into their accounts. 

Collins previously said it was in the final stages of completing the software updates required to bring systems back online, but it’s unclear if that was before or after it discovered that hackers had still been inside its systems.

It’s unclear who is behind the attack, but DataBreaches suggested there is a possibility that it may be connected to the ShinyHunters cybercrime group, whose partner, the Scattered Spider gang, is known to have targeted the aviation industry

Scattered Spider and ShinyHunters announced their retirement recently, but the industry is skeptical of their claims and evidence suggests that they continue carrying out attacks. 

Related: Jaguar Land Rover Admits Data Breach Caused by Recent Cyberattack

Related: Air France, KLM Say Hackers Accessed Customer Data

Related: Cyberattack On Russian Airline Aeroflot Causes the Cancellation of More Than 100 Flights

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we break down why email-layer defenses alone can't keep pace with the modern phishing ecosystem, how agentic AI is changing the capacity equation for security teams, and more.

Register

This year's summit will help organizations learn how to utilize tools, controls, and design models needed to properly secure cloud environments. Interact with leading solution providers and other end users facing similar challenges in securing a variety of cloud deployments.

Register

People on the Move

Mark Carter has been appointed Chief Information Security Officer at Socure.

Spektrum Labs has named Mark Cravotta Chief Operating Officer.

Philip Martin has joined Uber as Chief Information Security Officer.

More People On The Move

Expert Insights

Four decades of incident response experience suggest that exploits are often the symptom, not the root cause, of today’s cybersecurity failures.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.