The disruption at European airports filed at 25-0919 ran for several days amid delays and cancellations before ENISA, the EU cybersecurity agency, confirmed publicly that it was a ransomware attack.
That interval, and who closed it, is worth examining separately from the incident.
A Multi-Country Supplier Incident Has No Natural Spokesman
The affected airports were in different countries with different regulators. The supplier was a company in another jurisdiction with commercial reasons for caution. The airlines were affected parties, not investigators.
Absent an authority willing to characterise it, the public account of a cross-border incident is assembled from airport statements about queues — which describe the symptom and cannot name the cause.
Classification Changes What Other Parties Can Do
Confirming ransomware tells every other operator of the same platform what class of event they are exposed to. It tells insurers which policy terms engage. It moves the incident from "IT problem" into a category with established response playbooks.
It is the same function this desk credited in the severity-scale file at 26-0415: shared vocabulary is what lets a sector act on somebody else’s incident.
The Gap Is Where Speculation Lives
During the days before confirmation, research firms published candidate attributions naming several groups. None was established. That is what fills an information vacuum, and it is why the speed of authoritative classification matters more than its completeness.
A regulator that says "this is ransomware, we do not yet know by whom" on day two serves everybody better than a complete account on day thirty.
This is a standards file built on reporting of the incident cited, listed below. The argument about classification timing is ours and labelled as such. Corrections: corrections@forensicpost.com.