Desk live·
ForensicPost
Nation-state/Aviation/File 26-0406

Cyber Incident Disrupted Check-in and Baggage at Major European Airports

A cyber incident affecting aviation support software disrupted check-in, boarding and baggage handling at major European airports between 4 and 6 April 2026. The airports were not individually attacked.

Constructed geometry · not a chart of case data
TargetEuropean airport passenger systems
ActorUnattributed
D. Kennedy12 min readConfidence: medium3 sources reviewed

Between 4 and 6 April 2026, a cyber incident affecting aviation support software disrupted passenger processing across multiple European hubs. Reporting describes check-in, boarding and baggage handling affected at airports including Heathrow, Brussels, Berlin and Dublin, with manual fallback operations during recovery.

None of those airports was individually compromised. They shared a supplier.

Common Platforms Are The Point Of The Platform

Airports do not each build their own check-in system. Shared passenger-processing platforms let any airline operate from any desk at any participating airport, which is what makes a modern hub work at all.

The efficiency is real and so is the coupling. A defect or compromise in that layer does not degrade one operator; it degrades passenger processing across every airport that adopted it, simultaneously, in several jurisdictions with different regulators.

Manual Fallback Worked, Expensively

Aviation retains manual procedures because it is a safety-regulated industry that has never been permitted to assume its systems will be available. Staff can check passengers in on paper, and during this incident they did.

The throughput is a fraction of the automated rate, which is why the visible outcome was queues, delays and cancellations rather than a halt. It is the same finding as the Minnesota water file in 26-0727: the fallback capability is what converted a systems failure into a bad day instead of a shutdown.

A Second Reason To Notice This One

Reporting connects the April disruption to a broader pattern including a 2025 incident affecting shared airport software. Two events touching the same layer within a year is a signal about the layer, not about the operators.

Graded medium. The disruption and affected functions are consistently reported; the specific mechanism, the supplier’s own account and any attribution are not established, and we are not inferring them.

How we reported this

Compiled from public reporting and industry analysis, listed below. No attribution has been established and we offer none. The list of affected airports is as reported and may be incomplete. Corrections: corrections@forensicpost.com.

Sources
  1. European airports and cyber resilience: latest wake-up callWorld Economic Forum
  2. Client alert: lessons learned from cyber attack disrupting European airportsAon
  3. Cyberattack triggers major April 2026 chaos at European airportsThe Traveler
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary