On 19 September 2025 major European airports including London Heathrow, Brussels and Berlin Brandenburg suffered severe disruption to check-in and boarding. The cause was an attack on MUSE, the common-use passenger-processing platform supplied by Collins Aerospace. ENISA subsequently confirmed it as ransomware.
Check-in, baggage handling and self-service kiosks were affected. Airlines reverted to manual procedures. Heathrow reported most flights operating by the morning of 21 September, with longer processing times persisting.
This Is The File The 2026 Disruption Should Be Read Against
This desk filed a strikingly similar event in April 2026 at 26-0406: aviation support software compromised, the same category of function degraded, the same set of hubs, the same manual fallback.
Two incidents in the same layer within seven months is the argument made at 26-0704 — that common-use platforms are a systemic single point of failure — arriving with the evidence attached rather than as a prediction.
A Supplier, Not A Target
None of the affected airports was attacked. Each had procured a shared platform that lets any airline operate from any desk, which is the arrangement that makes a modern terminal work at all.
The consequence is that a single supplier incident produced simultaneous degradation across several countries, several regulators and several national aviation authorities — with no single body positioned to coordinate the response.
What A Confirmed Classification Is Worth
ENISA confirming ransomware matters because it converts speculation into a category. No group formally claimed the attack, and research at the time offered several plausible candidates without settling on one.
We name none of them. A list of groups with the capability and the history is not attribution, and reproducing it would give a guess the appearance of a finding.
Compiled from public reporting and agency confirmation, listed below. No actor has been established; candidate lists circulating in research at the time are speculative and we do not reproduce them. Corrections: corrections@forensicpost.com.