Yazılar

Collins Aerospace Works to Restore Airline Software After Cyberattack

Collins Aerospace, a subsidiary of RTX, said on Wednesday it is working to restore its passenger processing software after a cyber intrusion disrupted airline operations across several European airports.

The company’s MUSE system—which supports passenger check-in, baggage handling, and boarding—was knocked offline on September 19 in what has been identified as a ransomware attack. The disruption caused widespread travel delays and cancellations.

British police confirmed on Wednesday that they had arrested a man in connection with the incident, though investigations remain ongoing.

Berlin airport, one of the affected hubs, said it was still struggling to fully restore its check-in and baggage systems and warned travelers to expect further delays and cancellations.

The Collins Aerospace hack is the latest in a string of cyberattacks in Europe that have triggered significant real-world consequences, underscoring the vulnerability of critical infrastructure to digital threats.

UK Police Arrest Man Over Cyberattack That Disrupted European Airports

British police have arrested a man in connection with a ransomware attack on Collins Aerospace, a unit of RTX, that disrupted check-in systems at several European airports and caused widespread travel chaos.

The National Crime Agency (NCA) said the suspect, a man in his 40s, was detained on Tuesday on suspicion of violating the Computer Misuse Act. He has since been released on conditional bail.

“Although this arrest is a positive step, the investigation into this incident is in its early stages and remains ongoing,” said NCA Deputy Director Paul Foster.

Authorities have not yet identified which criminal group was behind the hack. Unlike many ransomware gangs that typically publicize their attacks and leak stolen data on dark web sites, monitoring groups said no organization has yet claimed responsibility for the Collins Aerospace breach.

Ransomware attacks involve malicious software that encrypts a company’s data, with criminals demanding payment to unlock it. Such groups usually try to avoid targets likely to draw heavy law enforcement attention.

The Collins Aerospace hack is the latest in a series of cyberattacks in Europe that have triggered serious offline disruptions. Jaguar Land Rover, Britain’s largest carmaker and owned by Tata Motors, announced this week it would extend factory shutdowns until October 1 after a separate hack left operations paralyzed.

Berlin airport, one of several affected by the Collins Aerospace incident, warned it could take several more days before secure and fully functional systems are restored.

British police have arrested a man in connection with a ransomware attack on Collins Aerospace, a unit of RTX, that disrupted check-in systems at several European airports and caused widespread travel chaos.

The National Crime Agency (NCA) said the suspect, a man in his 40s, was detained on Tuesday on suspicion of violating the Computer Misuse Act. He has since been released on conditional bail.

“Although this arrest is a positive step, the investigation into this incident is in its early stages and remains ongoing,” said NCA Deputy Director Paul Foster.

Authorities have not yet identified which criminal group was behind the hack. Unlike many ransomware gangs that typically publicize their attacks and leak stolen data on dark web sites, monitoring groups said no organization has yet claimed responsibility for the Collins Aerospace breach.

Ransomware attacks involve malicious software that encrypts a company’s data, with criminals demanding payment to unlock it. Such groups usually try to avoid targets likely to draw heavy law enforcement attention.

The Collins Aerospace hack is the latest in a series of cyberattacks in Europe that have triggered serious offline disruptions. Jaguar Land Rover, Britain’s largest carmaker and owned by Tata Motors, announced this week it would extend factory shutdowns until October 1 after a separate hack left operations paralyzed.

Berlin airport, one of several affected by the Collins Aerospace incident, warned it could take several more days before secure and fully functional systems are restored.

Jaguar Land Rover extends cyberattack shutdown to four weeks, costing £50m per week

Jaguar Land Rover (JLR), Britain’s largest carmaker, said it will keep its factories closed until October 1 following a cyberattack earlier this month that has paralyzed operations and rippled across the automotive supply chain. The shutdown, now stretching to four weeks, is costing the Tata Motors-owned luxury carmaker about £50 million ($68 million) per week, according to the BBC.

JLR runs three UK factories producing around 1,000 vehicles a day, including the popular Range Rover and Defender models. The outage has forced many of its 33,000 employees to stay home, while smaller suppliers are also struggling to cope with the disruption.

Adding to the fallout, industry sources told The Insurer that JLR was left without direct cyber insurance coverage, having failed to finalize a deal brokered by Lockton before the attack. The company has declined to comment on its insurance position or on who may be behind the breach.

Government ministers, including Peter Kyle and Chris McDonald, visited JLR on Tuesday to discuss recovery plans. McDonald said the government’s top priorities are “helping Jaguar Land Rover get back up and running as soon as possible and the long-term health of the supply chain.”

The shutdown underscores the UK’s broader vulnerability to ransomware and cyberattacks, which have recently hit major retailers like Marks & Spencer and Co-op, and even disrupted airport check-in systems across Europe. Official figures show more than 40% of UK businesses reported some form of cyber breach in the past year.

S&P Global’s latest survey shows JLR’s stoppage is already weighing on UK manufacturing output. With JLR’s supply chain supporting over 104,000 jobs, the Unite union has warned of potential layoffs and urged government support to protect workers and suppliers.

JLR said it is working on a phased restart plan, though the investigation into the attack continues. “We have made this decision to give clarity for the coming week,” the company said, stressing its focus on minimizing disruption to staff and partners.