Desk live·
ForensicPost
Breaches/Method/File 25-0925

ENISA Confirmed European Airport Disruption as Ransomware Days Later

ENISA confirmed the European airport disruption as ransomware days after it began. In a multi-country incident with no single owner, the confirming authority is doing something structural.

Constructed geometry · not a chart of case data
Methods & StandardsThis file records how the desk works, not an incident
TargetCross-border incident classification
ActorUnattributed
D. Kennedy11 min readConfidence: high2 sources reviewed

The disruption at European airports filed at 25-0919 ran for several days amid delays and cancellations before ENISA, the EU cybersecurity agency, confirmed publicly that it was a ransomware attack.

That interval, and who closed it, is worth examining separately from the incident.

A Multi-Country Supplier Incident Has No Natural Spokesman

The affected airports were in different countries with different regulators. The supplier was a company in another jurisdiction with commercial reasons for caution. The airlines were affected parties, not investigators.

Absent an authority willing to characterise it, the public account of a cross-border incident is assembled from airport statements about queues — which describe the symptom and cannot name the cause.

Classification Changes What Other Parties Can Do

Confirming ransomware tells every other operator of the same platform what class of event they are exposed to. It tells insurers which policy terms engage. It moves the incident from "IT problem" into a category with established response playbooks.

It is the same function this desk credited in the severity-scale file at 26-0415: shared vocabulary is what lets a sector act on somebody else’s incident.

The Gap Is Where Speculation Lives

During the days before confirmation, research firms published candidate attributions naming several groups. None was established. That is what fills an information vacuum, and it is why the speed of authoritative classification matters more than its completeness.

A regulator that says "this is ransomware, we do not yet know by whom" on day two serves everybody better than a complete account on day thirty.

How we reported this

This is a standards file built on reporting of the incident cited, listed below. The argument about classification timing is ours and labelled as such. Corrections: corrections@forensicpost.com.

Sources
  1. From MUSE to manual: cyberattack analysis on European airport operationsCYFIRMA
  2. Cyberattack on Collins Aerospace disrupts European airportsAerotime
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary