Desk live·
ForensicPost
Ransomware/Aviation/File 25-0919

Collins Aerospace Ransomware Disrupted Heathrow, Brussels and Berlin

A ransomware attack on Collins Aerospace’s MUSE passenger-processing platform disrupted Heathrow, Brussels and Berlin from 19 September 2025. None of the airports was attacked.

Constructed geometry · not a chart of case data
TargetCollins Aerospace MUSE
ActorUnattributed
D. Kennedy13 min readConfidence: high3 sources reviewed

On 19 September 2025 major European airports including London Heathrow, Brussels and Berlin Brandenburg suffered severe disruption to check-in and boarding. The cause was an attack on MUSE, the common-use passenger-processing platform supplied by Collins Aerospace. ENISA subsequently confirmed it as ransomware.

Check-in, baggage handling and self-service kiosks were affected. Airlines reverted to manual procedures. Heathrow reported most flights operating by the morning of 21 September, with longer processing times persisting.

This Is The File The 2026 Disruption Should Be Read Against

This desk filed a strikingly similar event in April 2026 at 26-0406: aviation support software compromised, the same category of function degraded, the same set of hubs, the same manual fallback.

Two incidents in the same layer within seven months is the argument made at 26-0704 — that common-use platforms are a systemic single point of failure — arriving with the evidence attached rather than as a prediction.

A Supplier, Not A Target

None of the affected airports was attacked. Each had procured a shared platform that lets any airline operate from any desk, which is the arrangement that makes a modern terminal work at all.

The consequence is that a single supplier incident produced simultaneous degradation across several countries, several regulators and several national aviation authorities — with no single body positioned to coordinate the response.

What A Confirmed Classification Is Worth

ENISA confirming ransomware matters because it converts speculation into a category. No group formally claimed the attack, and research at the time offered several plausible candidates without settling on one.

We name none of them. A list of groups with the capability and the history is not attribution, and reproducing it would give a guess the appearance of a finding.

How we reported this

Compiled from public reporting and agency confirmation, listed below. No actor has been established; candidate lists circulating in research at the time are speculative and we do not reproduce them. Corrections: corrections@forensicpost.com.

Sources
  1. From MUSE to manual: cyberattack analysis on European airport operationsCYFIRMA
  2. Hundreds of flights delayed at Heathrow and other airports after apparent cyberattackTechCrunch
  3. Cyberattack on Collins Aerospace disrupts European airportsAerotime
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary