A sophisticated cyber attack on Collins Aerospace disrupted operations at major European airports on Friday night, affecting check-in and boarding systems and forcing thousands of passengers into chaos as airlines reverted to manual processes.

The attack heavily impacted Heathrow, Brussels, and Berlin airports, causing numerous flight delays and cancellations when hackers targeted the company’s Multi-User System Environment (Muse) software, which allows airlines to share check-in desks and boarding gates across multiple carriers.

Collins Aerospace acknowledged “a cyber-related disruption” to its Muse software at “select airports” but emphasized that manual check-in operations could still be used. However, the transition to paper-based systems created widespread operational challenges that extended into Saturday.

The timing of the attack highlights the aviation industry’s vulnerability to digital threats. The European Aviation Safety Agency estimated a monthly average of 1,000 airport cyberattacks in 2020, with a 600% increase in aviation cyberattacks reported between 2024 and 2025, demonstrating escalating risks to critical infrastructure.

Brussels Airport initially reported “a large impact” on its flight schedule, including cancellations, while Berlin’s Brandenburg Airport experienced extended waiting times. Dublin and Cork airports confirmed minor disruptions as airlines implemented manual check-in and boarding procedures.

When Muse was knocked offline, airlines across three countries simultaneously lost the ability to process passengers electronically, with staff resorting to hand-written baggage tags and phone-based boarding lists, recreating an era of travel long thought obsolete.

The National Cyber Security Centre confirmed it was working with Collins Aerospace, affected United Kingdom (UK) airports, and law enforcement agencies to understand the full impact. The European Commission monitored the situation but stressed there was no evidence of a “widespread or severe” attack.

Passengers described hours-long queues, confusion at gates, and cancelled connections. Travelers reported staff manually tagging luggage and checking passengers over the phone, while others sat on aircraft for extended periods without information about delays or cancellations.

Flight tracker FlightAware recorded hundreds of delayed flights across affected airports. Eurocontrol, Europe’s air traffic regulator, requested airlines to reduce half their flight schedules at Brussels Airport until Monday to ease operational pressure.

The incident recalls last year’s Crowdstrike software failure that grounded flights worldwide, underscoring how interconnected digital systems create cascading vulnerabilities across the aviation sector. According to Boeing research, ransomware incidents alone surged by 600 percent in 2023, with threat actors increasingly targeting critical infrastructure for financial gain.

While some UK politicians suggested Russian involvement, cybersecurity experts cautioned against premature attribution. Criminal ransomware gangs, often operating from Russia or Eastern Europe, remain the most likely culprits given their established pattern of targeting critical infrastructure for financial extortion.

The aviation industry remains a key target for cyberattacks in 2025, with its role as critical infrastructure making it a prime focus for threat actors who exploit the heavy reliance on digital systems for operations.

The Collins Aerospace attack demonstrates how single points of failure in shared aviation infrastructure can create continent-wide disruptions. Muse software’s widespread adoption across European airports meant that one successful cyber intrusion simultaneously disabled passenger processing capabilities across multiple countries.

Industry observers suggest the attack could accelerate calls for airports and airlines to invest more heavily in cyber resilience and redundant systems. The manual fallback procedures, while functional, proved insufficient to handle normal passenger volumes during peak travel periods.

Recent analysis shows that breaches caused by hacking or information leakage increased from 4% in 2010 to 81% in 2024 in global systems, highlighting the evolving threat landscape facing aviation infrastructure operators worldwide.

Security experts emphasize that aviation’s digital transformation, while improving efficiency and passenger experience, has expanded attack surfaces for cybercriminals. The Muse system attack represents a sophisticated understanding of aviation operations, targeting software that enables resource sharing across carriers.

Collins Aerospace has not disclosed the origin of the hack, and investigations continue across multiple jurisdictions. The company’s parent organization RTX faces growing scrutiny over cybersecurity protocols for aviation infrastructure software used across international airports.

The disruption underscores broader questions about critical infrastructure protection in an increasingly connected world, where cyber attacks on single service providers can create international incidents affecting thousands of travelers and multiple national economies simultaneously.