Thank you
Our team of industry domain experts combined with our guaranteed SLAs, our world class technology .
Get Immediate Help
A ransomware attack on Collins Aerospace’s MUSE check-in and boarding software started late Friday, 19 September 2025. Automated check-in and bag-drop systems went down across multiple European airports. Heathrow, Brussels, Berlin, and Dublin saw the brunt of delays and cancellations while many airlines switched to manual processing. Regulators say the root issue sits with a third-party vendor, not airport infrastructure. Early, conservative cost modelling points to low-eight-figure direct airline costs over the first 72 hours, not counting reputational and knock-on losses.
When it started. Evening of Friday, 19 September 2025. Disruption continued through the weekend and into Monday, 22 September.
Who was hit. Heathrow, Brussels, Berlin Brandenburg, and Dublin reported material impact. Heathrow said most flights operated but with manual processing in parts of the operation. Brussels cancelled dozens of flights and warned of continued disruption. Berlin faced queues during marathon weekend traffic. Dublin reported ongoing delays in Terminal 2.
Current status at time of writing. Collins said it is close to completing updates and restoring normal service. National cyber agencies, including the UK NCSC, are working with airports and Collins.
Saturday, 20 Sep: Heathrow warns of delays. Brussels and Berlin confirm manual processing. The NCSC coordinates with Collins and UK airports.
Sunday, 21 Sep: Brussels cancels ~50 of ~250–276 departures and asks airlines to reduce schedules for Monday. Heathrow reports widespread but mostly sub-hour delays. Dublin sees a second day of disruption in T2.
Monday, 22 Sep: Fourth day of disruption. Heathrow mostly running, still pockets of manual processing. Brussels continues to cancel flights. Collins says fixes are nearly complete.
Eurocontrol’s recommended tactical delay cost with network effect averages roughly €166 per minute at-gate across aircraft types. That figure already includes knock-on delays elsewhere in the network.
Using the Guardian’s Heathrow snapshot for Sunday alone: ~315 delayed flights (90% of 350) × 34 minutes ≈ 10,710 delay-minutes.
Multiply by €166/minute gives ≈ €1.8 million in direct airline delay cost for that Heathrow day, before passenger compensation, overtime, and extra handling.
2) Cancellation costs.
Eurocontrol’s on-the-day cancellation cost ranges roughly €16.6k–€25.7k for narrow-bodies and €85.6k–€123.9k for wide-bodies, with a system-wide average alternative of ~€20.9k per cancellation. Brussels reported dozens of cancellations on Sunday and further into Monday, so a day with, say, 50 cancellations could imply €1.0–€1.3 million on the conservative average, and far more if a material share were wide-bodies.
For delays ≥3 hours and cancellations, airlines may owe €250–€600 per passenger depending on distance and rerouting. Not every disrupted passenger qualifies, but for long-haul or missed connections the exposure climbs quickly.
Across Friday night to Monday and across the four most affected hubs, a low-eight-figure combined airline cost is plausible when you add delay minutes, cancellations, care and accommodation, rebookings, and compensation exposure. This is in line with Europe’s historically high delay economics where network effects amplify initial outages. Treat this as a preliminary range, pending airline disclosures and insurer reports.
A single vendor outage created correlated operational risk across airlines and airports. ENISA says the event was a ransomware attack, and Collins confirms MUSE was the affected system. This is textbook single point of failure in the passenger-processing chain.
Why the manual fallback hurts.
Manual check-in works, but it is slow. It increases at-gate delays, inflates turnaround times, and creates reactionary delays across the network. These are precisely the cost categories Eurocontrol prices highly in its delay models.
Regulator posture.
The European Commission monitored the situation. The UK’s NCSC engaged with Collins and airports. Expect deeper scrutiny of software supply-chain controls and service-level recovery obligations for critical aviation IT.
Don’t Let Cyber Attacks Ruin Your Business
Call
UK: +44 (0)20 3336 7200
KSA: +966 1351 81844
UAE: +971 454 01252
Contents
To keep up with innovation in IT & OT security, subscribe to our newsletter
Recent Posts
Cloud Security | 16/10/2025
Penetration Testing | 15/10/2025
Cybersecurity | 10/10/2025