Vulnerability Disclosure
A cyber–attack on Collins Aerospace, a key provider of airline check-in and boarding systems, caused major disruption across several European airports, beginning late on Friday 19th September 2025. The company’s MUSE software, widely used by airlines at major hubs including Heathrow, Brussels, Berlin, and Dublin, was affected, making the impact particularly widespread. No attribution has been made public, and the timeline of detection and disclosure remains under review.
Impact
The incident led to extensive flight delays and cancellations. Airports were forced to revert to manual check-in and boarding procedures, resulting in long queues and significant inconvenience for passengers. Brussels Airport reported over 70 cancelled flights across the weekend, while Heathrow deployed additional staff to manage queues. Some airlines implemented temporary workarounds to minimise disruption.
Intelligence Cut-Off Date (ICoD)
22nd September 2025
Technical Breakdown
The event has been described as a cyber related disruption, though no technical details have been publicly confirmed regarding the nature of the vulnerability or whether it involved a previously unknown exploit. Experts suspect the attack may have involved unauthorised access to the MUSE system via compromised credentials or unpatched vulnerabilities. Forensic investigations are ongoing. The aerospace services sector continues to operate on a substantial amount of ageing digital legacy infrastructure, which poses significant security and operational risks.
Threat Intelligence Assessment
The aviation sector’s reliance on centralised service providers leaves it exposed to systemic risks. Cyber-attacks targeting aviation have increased by 600% between 2024 and 2025, highlighting the urgent need for stronger security protocols and robust contingency planning. This incident serves as a warning to other critical sectors such as healthcare, energy, and logistics, where similar vulnerabilities exist.
Governments may respond with stricter cyber security regulations for vendors supporting national infrastructure, and increased investment in supply chain resilience. As of the time of writing, responsibility for the cyber-attack on Collins Aerospace has not been publicly attributed
Quorum Cyber’s Response
Our team is actively monitoring the situation surrounding this data breach. Our Threat Intelligence Hub is continually updated with the latest information and recommendations to ensure our clients remain protected against emerging threats.
Intelligence Terminology Yardstick












