
Heathrow Airport Cyber Attack – Complete Breakdown and Latest Updates
On Friday, 19 September 2025, a major cyber incident disrupted operations at London Heathrow and several other European airports. The attack targeted the Collins Aerospace MUSE system, a widely used platform for passenger check-in, boarding, and baggage processing. Travellers faced long queues, manual check-in procedures, flight delays, and cancellations.
What Happened at Heathrow Airport During the Cyber Attack?
Key Insights
- The attack targeted a single third-party airport software vendor (Collins Aerospace), not Heathrow’s core infrastructure, yet caused cascading delays across Europe.
- While the attack caused significant disruption, initial reports indicate it was not a data breach of passenger information.
- The rapid arrest suggests potential state-backed or high-profile criminal group involvement, though the investigation is ongoing.
- The incident highlights the vulnerability of centralized aviation infrastructure to supply-chain cyber risk.
Snapshot Facts
| Fact | Detail |
|---|---|
| Date of Attack | 19 September 2025 (Late Friday) |
| Attack Vector | Ransomware on Collins Aerospace MUSE |
| Primary Impact at Heathrow | Flight delays, cancellations, manual check-in |
| Affected European Airports | Multiple, including Brussels and Berlin Brandenburg |
| Arrest Made | Yes, by UK authorities (24 September 2025) |
| Official Confirmation | ENISA confirmed the event as a ransomware attack |
| Attribution | No group confirmed; investigation continues |
Why Was Heathrow Affected? The Role of the Collins Aerospace MUSE System
Heathrow was not directly hacked. The disruption originated from a ransomware attack on a third-party vendor, Collins Aerospace, which provides the MUSE passenger-processing platform. MUSE is a multi-user system used for check-in, boarding, and baggage workflows at numerous airports globally.
What is the Collins Aerospace MUSE System?
MUSE is a widely deployed check-in and baggage management system used by many airlines. Its compromise created a single-point-of-failure effect, impacting multiple airports simultaneously. Because it was a shared system, the attack caused cascading disruptions across several European hubs.
How Did the Cyber Attack Impact Airport Operations?
Airports were forced to revert to manual operations. This resulted in longer processing times for passengers, long queues, and knock-on disruption to flight schedules. Heathrow reported that the vast majority of flights were operating normally after the initial disruption, but some passengers still faced longer wait times. Brussels Airport reported about 60 flights cancelled and roughly 50% capacity reduction during the worst period. Berlin Brandenburg experienced average delays of about one hour per flight.
The disruption is widely described as a case of supply-chain cyber risk in aviation, where the compromise of one vendor affects many operators. The attack underscores the systemic risk inherent in shared aviation technology.
Which Airports Were Affected by the Cyber Attack?
The impact was felt across several major European airports. The most clearly documented cases include London Heathrow, Brussels Airport, and Berlin Brandenburg, with reports also indicating disruption in Dublin.
Was Gatwick Airport Affected by the Cyber Attack?
While Gatwick was not explicitly named in the most detailed reports as a primary impacted hub, the nature of the attack on a shared system meant that any airport using the Collins Aerospace MUSE platform could have been affected. The specific impact on Gatwick and Stansted remains unclear from the available sources.
Scope of Disruption
Brussels Airport provided one of the clearest quantified accounts, reporting around 60 flight cancellations and a 50% capacity reduction. Berlin Brandenburg reported average delays of about one hour per flight. Heathrow, while experiencing significant disruption, reported that the vast majority of flights operated normally after the initial impact.
What Is the Current Status and Latest Update on the Heathrow Cyber Attack?
By late September 2025, operations at most affected airports, including Heathrow, had been restored. The incident prompted a law enforcement response and a broader review of cybersecurity practices in the aviation sector.
Has an Arrest Been Made in the Heathrow Cyber Attack Case?
Yes. On 24 September 2025, British police arrested a man in his 40s on suspicion of offenses under the Computer Misuse Act in connection with the investigation. The arrested person was later released on conditional bail. The arrest signals significant progress in the investigation.
What is the Latest Update on the Heathrow Cyber Attack?
As of the latest available reports, the immediate operational disruption has passed. Airports have returned to normal digital operations. The investigation into the full scope and attribution of the attack is ongoing. The attacker’s identity and the exact ransomware strain have not been publicly confirmed.
Heathrow reported that the vast majority of flights were operating normally after the initial disruption. Systems were back online within approximately 48 hours of the attack on 19 September 2025.
Timeline of the Heathrow Cyber Attack
- 19 September 2025 (Late Friday): Ransomware attack initiated on Collins Aerospace MUSE software.
- 20 September 2025 (Saturday): Widespread delays reported at Heathrow and other European airports. News outlets report the disruption.
- 20-21 September 2025 (Weekend): Airports use backup systems. Operations gradually recover.
- 24 September 2025: UK police arrest a man in his 40s in connection with the attack.
What Is Known and What Remains Unclear About the Attack?
| Established Information | Information That Remains Unclear |
|---|---|
| Attack occurred on 19 September 2025. | The exact identity of the attacker group. |
| It targeted Collins Aerospace MUSE software. | Whether passenger data was exfiltrated (initial reports say no). |
| It caused delays at Heathrow and other European airports. | The full list of all affected airports globally. |
| A suspect has been arrested in the UK. | The exact ransomware strain used. |
What Does This Attack Mean for Aviation Cybersecurity?
This incident highlights the vulnerability of centralized aviation infrastructure. A single software vendor being compromised can paralyze multiple major international hubs simultaneously. This attack differs from a direct breach of an airport’s network, which makes the response and attribution more complex. The speed of the arrest is notable and may indicate pre-existing intelligence or a less sophisticated attacker. The event serves as a significant case study in supply-chain cyber risk.
Official Sources and Statements
Several official statements and analyses have emerged regarding the incident. Heathrow warned passengers of potential disruptions, citing a “cyber security incident.” ENISA, the European Union Agency for Cybersecurity, confirmed the event was a ransomware attack. RTX, Collins Aerospace’s parent company, stated that the disruption affected electronic customer check-in and baggage drop and could be mitigated with manual procedures.
“Heathrow warned passengers of potential disruptions, citing a ‘cyber security incident’.”
— BBC, industrialcyber.co
“The attack was a ransomware incident impacting the Collins Aerospace MUSE check-in and boarding software.”
— Micromindercs.com
Summary: What Should Travelers and Observers Take Away?
The Heathrow cyber attack was a significant ransomware incident that disrupted travel for thousands of passengers across Europe. While the immediate operational impact has been resolved, the investigation continues. The event serves as a stark reminder of the systemic risks posed by third-party software dependencies in critical national infrastructure. For a detailed technical analysis of the attack vector, read From MUSE to Manual: Cyberattack Analysis on European Airport Operations.
Frequently Asked Questions
Aviation security overview provides additional context on industry-wide protections. For further reading on the Heathrow incident and its implications, see our analysis of airport cyber disruptions.
Is Heathrow Airport operating normally now?
Yes, operations were restored within approximately 48 hours after the attack on 19 September 2025.
Was my personal data stolen in the Heathrow cyber attack?
Initial reports indicate this was a ransomware attack disrupting check-in systems, not a data breach. Passengers should monitor official statements for updates.
What is the Collins Aerospace MUSE system?
MUSE is a multi-user airport passenger-processing platform used for check-in, boarding, and baggage-related workflows at numerous airports.
Should I be worried about flying through Heathrow now?
No. The affected systems have been restored and security is operational for all flights.
Who is responsible for the Heathrow cyber attack?
No group or individual has been definitively confirmed as responsible. An arrest has been made, but the investigation is ongoing.
How many flights were cancelled at Heathrow?
The exact number is not fully consolidated, but reports indicate around 20 flights were cancelled at Heathrow during the disruption.