Drooid Logo
Back to story perspectives

Full Breakdown

Arrest Made in Cyberattack Disrupting European Airports

9/24/2025, 7:54:08 PM

Overview of the Cyberattack

On September 19, 2025, a significant cyberattack targeted Collins Aerospace, a subsidiary of RTX Corporation, disrupting check-in and boarding systems at major European airports, including London Heathrow, Brussels, Berlin, and Dublin. The attack, attributed to ransomware, forced airports to revert to manual processing, leading to widespread flight delays and cancellations. The UK's National Crime Agency (NCA) reported that a man in his 40s was arrested in West Sussex on September 23 on suspicion of offenses under the Computer Misuse Act. He has since been released on conditional bail as the investigation continues.

Impact on Airport Operations

The cyberattack began late on Friday and persisted through the weekend, severely affecting operations at several airports. Brussels Airport experienced the most significant disruption, with nearly 140 flights canceled by Monday. Berlin and Heathrow also faced delays, with passengers reporting long queues and confusion as staff resorted to handwritten boarding passes and backup systems. Heathrow officials stated that while the majority of flights were operating normally by Tuesday, the situation remained fluid, and passengers were advised to check flight statuses before arriving.

Official Statements & Responses

Paul Foster, head of the NCA's National Cyber Crime Unit, described the arrest as a "positive step" but emphasized that the investigation is still in its early stages. He noted, "Cybercrime is a persistent global threat that continues to cause significant disruption to the UK." Collins Aerospace acknowledged the cyber-related disruption and is working closely with affected airports and law enforcement to restore functionality. The European Union Agency for Cybersecurity (ENISA) confirmed that ransomware was involved in the attack, highlighting the growing risks to critical infrastructure.

Criticism & Opposition

Experts have raised concerns about the increasing frequency and severity of cyberattacks on aviation infrastructure. Charlotte Wilson, head of enterprise at Check Point Software, remarked on the broader implications of such incidents, stating, "This disruption is part of a much bigger picture... Cyberattacks on critical infrastructure are fast becoming the new norm." The incident has prompted calls for enhanced cybersecurity measures across the aviation sector to protect against future attacks.

Conflicting Reports & Gaps

While the NCA has confirmed the arrest, details regarding the identity of the suspect and the specific criminal group behind the attack remain unclear. Some reports suggest that the attack could be linked to organized cybercrime or state-sponsored actors, but no definitive claims have been made. Additionally, the timeline for restoring full functionality to the affected systems has not been established, leaving airports and airlines to manage ongoing disruptions.

What's Next

As investigations continue, authorities are expected to enhance cybersecurity protocols across the aviation sector. Collins Aerospace is working to rebuild its compromised systems, and airports are implementing contingency plans to mitigate further disruptions. The situation remains dynamic, with updates anticipated as the investigation unfolds and recovery efforts progress.