UK Makes First Arrest in Massive Ransomware Attack That Crippled European Airports

# UK Arrests Suspect in Major Ransomware Attack Disrupting European Airports

The UK’s National Crime Agency (NCA) has made a significant arrest in connection with a ransomware attack that has caused widespread chaos across European airports. The cyberattack targeted critical passenger processing software, leading to flight delays and cancellations throughout the continent.

## The Arrest and Investigation

NCA officers arrested a man in his forties in West Sussex on suspicion of Computer Misuse Act offenses. The arrest followed an investigation into the cyberattack that compromised Collins Aerospace’s Multi-User System Environment (MUSE) passenger processing software.

“Although this arrest is a positive step, the investigation into this incident is in its early stages and remains ongoing,” said Paul Foster, head of the NCA’s National Cyber Crime Unit. The suspect has since been released on conditional bail as the investigation continues.

## Impact on Airport Operations

The ransomware attack, first detected on Friday, September 19, has severely disrupted operations at major European airports including:
– Heathrow Airport (London)
– Brussels Airport
– Cork and Dublin airports (Ireland)
– Berlin Brandenburg Airport
– Multiple other European hubs

The MUSE software enables multiple airlines to share check-in and gate resources at airports, including baggage handling systems. When compromised, this critical infrastructure caused a domino effect of flight delays and cancellations across the region.

## Corporate Response

RTX Corporation (formerly Raytheon Technologies), which owns Collins Aerospace, confirmed the attack in a filing with the Securities and Exchange Commission. The aerospace giant, employing over 186,000 people worldwide with revenues exceeding $80 billion, immediately activated its incident response plan.

“Upon detecting the incident, the Company activated its incident response plan and promptly took steps to assess, contain, respond to and remediate the incident,” RTX stated. The company is working with internal and external cybersecurity experts while providing technical support to affected airlines and airports.

Affected customers have shifted to backup or manual processes to maintain operations, though this has resulted in continued delays and cancellations.

## Technical Details

Cybersecurity experts suggest the attackers used either Hardbit or Loki ransomware variants. Both are considered “Ransomware-as-a-Service” programs, typically used in smaller-scale attacks, making their deployment in such a high-impact scenario unusual.

The MUSE airport systems operate independently from RTX’s main enterprise network, residing on customer-specific networks, which may have made them more vulnerable to targeted attacks.

## Ongoing Response

RTX has notified domestic and international law enforcement authorities and government agencies about the incident. The company continues to communicate with customers and stakeholders while working to restore full system functionality.

This incident highlights the critical vulnerability of airport infrastructure to cyberattacks and the far-reaching consequences when essential passenger processing systems are compromised. As the investigation continues, authorities are working to prevent similar attacks on critical transportation infrastructure.

Share This Article