# Ransomware disruption hits airport check-in systems across Europe
A cyberattack on a service provider disrupted check-in and boarding systems at several major European airports, causing delays and cancellations and forcing some airports to shift to manual procedures.
On 2025-09-20, the European Union's cybersecurity agency ENISA said the disruption was caused by a third-party ransomware incident, according to evidence source 7239. The agency said the type of ransomware had been identified and that law enforcement was involved in the investigation.
The disruption affected airports in Berlin, London, Brussels and Dublin. Brussels Airport said passengers should confirm travel plans before heading to the airport, and later asked airlines to cancel half of Sunday departures in order to avoid long queues and late cancellations. Heathrow, Berlin Brandenburg and Brussels were among the hardest hit, with cancellations and delays reported across the weekend.
The service provider, Collins Aerospace, confirmed that the problem affected its MUSE software in select airports. The company said the impact was limited to electronic customer check-in and baggage drop and could be mitigated with manual check-in operations. That distinction matters: the incident did not shut airports entirely, but it did break the systems most passengers depend on to move through terminals quickly.
Berlin airport was still dealing with the effects on Monday, including long waits at check-in. Dublin later reported a minor impact as well. Aviation data provider Cirium counted 29 arrivals and departures cancelled across Heathrow, Berlin and Brussels at the point reflected in the evidence.
The event highlights a familiar vulnerability in modern aviation. Airports do not all run identical software, but many depend on a small number of technology providers for common passenger systems. When one of those suppliers is hit, the disruption can spread across borders very quickly. The result is an operational problem that looks local at first and then becomes regional.
The timing was awkward for passengers and airports alike. Berlin was already dealing with heavy travel demand linked to the Berlin Marathon, while Brussels and Heathrow were warning of knock-on effects into the following day. Airports advised passengers to check with airlines before travelling, and some departures were shifted to manual processing to reduce further cancellations.
The incident also followed reports that the airport in St Petersburg had seen its website hacked a day earlier, underscoring how transportation infrastructure has become a recurring target in cyber incidents. Even where attackers do not fully disable systems, the knock-on effects can be immediate: longer queues, rescheduling, missed connections and extra pressure on airline staff.
Citations
- Source 7239: ENISA finding, airport impact, Collins Aerospace confirmation, cancellations and affected airports.



