When Europe’s Airports Stood Still: Ransomware Rears Ugly Head Yet Again—and Things Could Get Worse
Disruption at a Massive Scale Shows the Kind of Impact Ransomware Can Cause

Parts of Europe were thrown into disarray over the weekend after several major European airports were hit by severe disruptions caused by ransomware attacks. The cyberattacks disabled automated check-in and boarding systems, causing operational chaos at major hubs including London Heathrow in the UK, Brussels Airport in Belgium, Berlin Brandenburg Airport in Germany, and Dublin and Cork airports in Ireland.
The first signs of disruption were felt on Friday, 19 September 2025, with delays and cancellations continuing throughout the weekend. With automated systems rendered offline by the attacks, airport staff were forced to rely on manual procedures using laptops, iPads, and even handwritten boarding passes. This slowed passenger flow significantly and led to cancellations, particularly in Brussels and Berlin, while Heathrow experienced long queues and delayed departures.
The European Union Agency for Cybersecurity (ENISA) confirmed that ransomware was, indeed, the culprit behind the disruptions and that the affected vendor was US-based Collins Aerospace. Specifically, Collins’ Muse/ARINC cMUSE platform, which powers check-in and boarding infrastructure for multiple airlines and airports, was directly targeted, creating a ripple effect across Europe.
“The type of ransomware has been identified. Law enforcement is involved to investigate,” ENISA said in a statement to news agency Reuters.
Collins confirmed the attack as well, describing it as a “cyber-related disruption” but maintained it was “limited to electronic customer check-in and baggage drop and can be mitigated with manual check-in operations.”
Modern Face of Ransomware: From IT Systems to the Physical World
For cybersecurity expert and Keeper Security CEO and Co-Founder Darren Guccione, the attacks on Europe’s airports signal a paradigm shift in ransomware, one where the effects aren’t just confined to IT systems but are also felt in the real world.
“The confirmation that ransomware was behind the disruption of airport check-in systems reinforces how devastating these attacks can be to critical infrastructure,” he told Cybersecurity Asia. “What began as a single compromise cascaded into delayed flights, cancelled schedules and disruptions to peoples’ travel plans across Europe. This is the modern face of ransomware—no longer confined to IT systems but extending into the physical world, disrupting operations, economies and lives.”
Rafe Pilling, Director of Threat Intelligence at British cybersecurity firm Sophos, agrees that disruptive attacks are becoming more visible in Europe. However, he does not believe the frequency of such attacks is increasing.
“Disruptive attacks are becoming more visible in Europe, but visibility doesn’t necessarily equal frequency,” Pilling told Reuters. “Truly large-scale, disruptive attacks that spill into the physical world remain the exception rather than the rule.”
If the Europe airport attacks are, indeed, the exception as Pilling contends them to be, then these ones are certainly the disruptive kind—and the world has definitely taken notice. While there are no final numbers yet, initial reports estimate that over 100 flights combined were either delayed or cancelled completely as operations were disrupted and lives—travel plans, schedules, vacations—were affected by ransomware.

Things Could Get Worse
For Martyn Thomas, Emeritus Professor of IT at Gresham College in London, the airport snafu illustrates how impactful ransomware attacks can be. And yet he believes things could be worse—much worse, as in people getting badly hurt or even killed.
“It’s clear from the number of recent cyberattacks and their impact that this is a problem that will grow, possibly rapidly, until software developers get much better at writing secure software and company IT staff get much better at evaluating the security of software their company chooses to purchase or to use remotely,” said Thomas. “We have been lucky so far, as the motivation of cyber criminals has been disruption or financial gain. “If they were to decide to cause serious injury or many deaths, the same attack strategies could be used on critical systems in healthcare or major infrastructure.”
It is a chilling thought to say the least, but it is also very possible. Already, cybercriminals are becoming more audacious in choosing targets, going after big brands and critical infrastructure like Transport London and Europe’s airports over the weekend. In fact, according to cybersecurity company KnowBe4, attacks on critical infrastructure globally is surging, with 420 million recorded from January 2023 to January 2024 alone. This represents a 30% increase from 2022 and appears to be an alarming trend moving forward.
The numbers are a cause of concern, and any more escalation in motive could potentially be dangerous, just as Thomas claims.
What Can Be Done?
The million-dollar question now, obviously, is what can businesses do to better protect themselves against ransomware—or any cyberattack for that matter?
For Keeper’s Guccione, a good starting point would be to zone in on identity and access security.
Ransomware thrives on weak points in security, often exploiting trusted third-party advisors to maximise their reach. This is why industries that rely on complex digital ecosystems, like aviation, must place identity and access security at the centre of their defence strategy,” Guccione pointed out.
He added: “Defeating ransomware requires more than recovery. It requires eliminating implicit trust, enforcing strict privileged access controls and monitoring every session in real time. Modern, cloud-based privileged access management solutions that unify password, secrets and session management give organisations the visibility and control to identify threats early and contain attacks before they spread.”
Andrew Kay, Director of Systems Engineering, Asia Pacific and Japan, at Illumio, believes a shift in mindset is critical and advocates for organisations to think that breaches are inevitable. He also suggests a more proactive, adaptive cyber defence that focuses on containment where potential threats and weak points are tracked to and solutions are implemented before an attack ever occurs.
The post-breach world is here. Attackers have adapted. They exploit weaknesses, particularly human error. Their tactics are faster, more effective. They also target misconfigurations, unpatched systems, excessive permissions, and weak vulnerability management,” Kay wrote in an exclusive commentary for Cybersecurity Asia earlier this year. “Many organisations are becoming increasingly aware of these threats, leading to stronger and more proactive security strategies. However, attackers remain ahead, quickly adapting to new vulnerabilities. The challenge is staying one step ahead in a constantly evolving threat landscape.”
He further explaiend: “The defender’s most important tool going forward is containment, and it changes everything. It transforms cybersecurity’s binary focus—keeping attackers out—into a more nuanced strategy of cyber resilience. It is about stopping attackers in their tracks and strengthening your defences with every new attack.”
At the moment, that’s all organisations can do: strengthening their cyber defence against ransomware and other cyberattacks. There are a number of ways to do it, but the moral lesson is clear: Just do it, and do it now.
A Final Word
As Guccione pointed out, ransomware itself is not new, but its consequences are more visible than ever—and they appear to be getting worse. Attackers are targeting higher-profile systems as well, and the stakes are increasing, according to the Keeper Security CEO.
Organisations, therefore, must respond accordingly and “match this escalation” by building defences that “protect resilience and continuity while preserving the public’s trust in and reliance on essential services.”
Anything less than that and cybercriminals will be winning over and over again.



