Vulnerability Disclosure

A cyberattack on Collins Aerospace, a key provider of airline check-in and boarding systems, caused major disruption across several European airports, beginning late on Friday 19th September 2025. The company’s MUSE software, widely used by airlines at major hubs including Heathrow, Brussels, Berlin, and Dublin, was affected, making the impact particularly widespread. No attribution has been made public, and the timeline of detection and disclosure remains under review. 

Impact

The incident led to extensive flight delays and cancellations. Airports were forced to revert to manual check-in and boarding procedures, resulting in long queues and significant inconvenience for passengers. Brussels Airport reported over 70 cancelled flights across the weekend, while Heathrow deployed additional staff to manage queues. Some airlines implemented temporary workarounds to minimise disruption. 

Intelligence Cut-Off Date (ICoD)

22nd September 2025 

Technical Breakdown

The event has been described as a cyber related disruption, though no technical details have been publicly confirmed regarding the nature of the vulnerability or whether it involved a previously unknown exploit. Experts suspect the attack may have involved unauthorised access to the MUSE system via compromised credentials or unpatched vulnerabilities. Forensic investigations are ongoing. The aerospace services sector continues to operate on a substantial amount of ageing digital legacy infrastructure, which poses significant security and operational risks. 

Threat Intelligence Assessment

The aviation sector’s reliance on centralised service providers leaves it exposed to systemic risks. Cyber-attacks targeting aviation have increased by 600% between 2024 and 2025, highlighting the urgent need for stronger security protocols and robust contingency planning. This incident serves as a warning to other critical sectors such as healthcare, energy, and logistics, where similar vulnerabilities exist.  

Governments may respond with stricter cyber security regulations for vendors supporting national infrastructure, and increased investment in supply chain resilience. As of the time of writing, responsibility for the cyber-attack on Collins Aerospace has not been publicly attributed 

Quorum Cyber’s Response

Our team is actively monitoring the situation surrounding this data breach. Our Threat Intelligence Hub is continually updated with the latest information and recommendations to ensure our clients remain protected against emerging threats. 

Intelligence Terminology Yardstick

Further Threat Intelligence from Quorum Cyber

Headquarters

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

FLORIDA, USA Office

501 E Kennedy Blvd.
STE 1400
Tampa FL 33602

Ontario, Canada Office

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

Contact Us
Address

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

501 E Kennedy Blvd
STE 1400
Tampa FL 33602

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

HEADQUARTERS
Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ



FLORIDA, USA OFFICE
501 E Kennedy Blvd.
STE 1400
Tampa FL 33602


ONTARIO, CANADA OFFICE
1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7


Legal

Privacy Preference Center

Skip to content