Yazılar

Airport chaos underscores growing trend of high-profile ransomware attacks

A weekend ransomware attack that crippled airport check-in systems across Europe has drawn attention to a new trend in cybercrime: hackers are increasingly targeting high-profile companies and infrastructure for both larger payouts and reputational clout, cybersecurity experts said.

The European Union’s cybersecurity agency ENISA confirmed on Monday that the attack on Collins Aerospace, a unit of RTX, was ransomware-based. The hack disrupted check-in and baggage systems since Friday, grounding flights and stranding thousands of passengers. The attackers’ identity remains unknown, with no ransomware group yet claiming responsibility on dark web leak sites.

Rafe Pilling, Director of Threat Intelligence at Sophos, noted that while most ransomware attacks remain financially motivated, a subset of operations is now engineered for maximum disruption: “They are becoming more visible and more ambitious.”

The strategy is not new but appears to be escalating. In April, the group Scattered Spider was linked to an attack on retailer Marks & Spencer that halted online orders for weeks. Britain’s National Crime Agency also charged two teenagers last week over a 2024 attack on Transport for London, tied to the same group. The FBI estimates Scattered Spider has been involved in around 120 network intrusions and netted $115 million in ransom payments.

Experts warn the trend poses greater systemic risks. Martyn Thomas, Emeritus Professor of IT at Gresham College, said software vulnerabilities and weak security practices continue to fuel the crisis: “If criminals were to decide to cause serious injury or many deaths, the same attack strategies could be used on critical systems in healthcare or major infrastructure.”

Another driver, analysts say, is reputation within cybercriminal networks. Pulling off high-impact breaches boosts a hacker’s credibility and standing among peers, creating a cycle of increasingly bold attacks.

The incident highlights the growing urgency for stronger software security and corporate defenses as ransomware groups become more emboldened, aiming not only for profit but also prestige.

European airports face continued disruption after cyberattack on check-in systems

Some of Europe’s busiest airports — including London’s Heathrow, Berlin Brandenburg, and Brussels Airport — are still grappling with flight delays and cancellations after hackers targeted check-in and boarding software provider Collins Aerospace, owned by RTX.

The attack, which began on Friday, disabled Collins’ MUSE software, forcing airports to fall back on manual check-in operations. While Heathrow and Berlin reported easing disruption by Sunday, Brussels Airport said delays and cancellations would continue into Monday.

Brussels Airport asked airlines to cancel half of Monday’s flights to avoid severe queues and last-minute disruptions. On Sunday, 50 of 257 scheduled departures were canceled, following 25 cancellations the previous day.

Collins said it was in the “final stages” of restoring systems with a secure updated version of its software. However, Brussels Airport noted it had not yet received this update.

Passengers without online check-in or carry-on-only travel faced the worst queues. One traveler in Brussels described the experience:

“For me, it was business as usual. For those poor souls who didn’t do online check-in or have bags to check, they may be waiting a bit.”

Cirium data showed disruption levels varied: Heathrow had “low” delays, Berlin “moderate,” and Brussels “significant.”

The cyberattack is part of a wider wave of hacks disrupting European industries. Recent incidents included Jaguar Land Rover’s halted production and Marks & Spencer’s financial losses running into hundreds of millions of pounds. Regulators have launched investigations into the source of the latest breach.

Stellantis reports data breach at third-party provider for North America

Stellantis, the parent company of Chrysler, said on Sunday it had detected unauthorized access at a third-party service provider supporting its North American customer service operations.

The company confirmed that the breach exposed only basic contact information, with no financial or highly sensitive personal data compromised. Stellantis did not specify how many customers were affected.

“Upon discovery, we immediately activated our incident response protocols … and are directly informing affected customers,” Stellantis said, adding that authorities have been notified. The automaker urged customers to remain vigilant against phishing attempts.

The breach is the latest in a growing wave of cyberattacks targeting automakers. Earlier this month, Jaguar Land Rover was forced to shut factories until September 24 after a major cyber incident disrupted retail and production operations.

The rise in attacks reflects the increasing vulnerability of the automotive industry, as digital platforms and connected services become more integral to customer operations and vehicle support systems.