[Blog](/blog)

Show links

Resources

[Blog](/blog)

[Breaches](/breaches)

[eBooks, reports, & more](/resources)

[Events](/events)

[News](/news)

[Cybersecurity](/category/cybersecurity)

Show links

Categories

[Attack Surface Management](/category/attack-surface-management)

[Company News](/category/company-news)

[Compliance and Regulations](/category/compliance-and-regulations)

[Cybersecurity](/category/cybersecurity)

[Data Breaches](/category/data-breaches)

[DevOps](/category/devops)

[Human Cyber Risk](/category/human-cyber-risk)

[Risks and Vulnerabilities](/category/risks-and-vulnerabilities)

[Third-Party Risk Management](/category/third-party-risk-management)

[Vendor Risk Management](/category/vendor-risk-management)

[Grounded: The ARINC vMUSE Attack Disrupting Multiple Airports](/blog/the-arinc-vmuse-attack-disrupting-multiple-airports)

Publish date

September 20, 2026

{x} minute read

# Grounded: The ARINC vMUSE Attack Disrupting Multiple Airports

[Get a demo](/contact-sales)

[Free trial](/demo)

[Download the PDF guide](/resources/complete-guide-to-data-breaches)

[Free trial](/demo)

Written by

[Edward Kost](/team/edward-kost)

Senior Cybersecurity Writer

Edward is a cyber writer with a mechanical engineering background. His work has been referenced by academic institutions and government bodies.

Reviewed by

[Kaushik Sen](/team/kaushik-sen)

Chief Marketing Officer

Kaushik has a background in software engineering, enterprise solution architecture, and data analytics. He brings a unique, data-driven perspective to cybersecurity education.

Table of contents

eBook

A Complete Guide to Data Breaches

Free resource

### A Complete Guide to Data Breaches

Learn how to avoid a costly data breach with a comprehensive prevention strategy.

[Download now](/resources/complete-guide-to-data-breaches)

The line between the digital and physical worlds blurs completely when a cyber attack results in widespread, tangible disruption. For thousands of travelers, this became a harsh reality when major European airports were forced to delay flights due to a ransomware attack targeting a vendor in the supply chain.

To prevent a repeat catastrophic event, we must break down how the vendor's vulnerability was exploited and deepen our understanding of the often-overlooked risks lurking within complex technology supply chains.

## What we know

On Saturday, September 20, 2025,[ a cyber attack caused significant disruptions](https://www.cnbc.com/2025/09/21/what-we-know-about-the-cyberattack-that-hit-major-european-airports.html) at several major European airports. The European Union Agency for Cybersecurity (ENISA) [later confirmed](https://techcrunch.com/2025/09/22/eu-cyber-agency-confirms-ransomware-attack-causing-airport-disruptions/) that a ransomware attack caused the outage, which targeted the [ARINC vMUSE](https://www.rockwellcollins.com/~/media/Files/Unsecure/Services-And-Support/Information-Management/ARINC-Airports/Passenger-Processing-Systems/vMUSE/Airports_vMuse_Datasheet.ashx) system, a [passenger processing platform](https://www.collinsaerospace.com/what-we-do/industries/airports/passenger-processing-solutions/agent-assisted-check-in) by Rockwell-Collins.

With this system unavailable, airports were forced to switch to manual procedures. This workaround caused major delays for passengers and led to 217 flight cancellations across the key affected hubs as staff worked to get operations moving again and restore the system's functionality.

## A chain of vulnerabilities

While the full details of the intrusion are still under investigation, the technical cause of the breach points to a classic and preventable security failure: the exploitation of outdated, vulnerable, and internet-facing systems. The vMUSE platform connects airports via a proprietary Collins network called ARINC AviNet, which functions as a dedicated VPN. The simultaneous failure across multiple airports strongly suggests that this central network was the point of compromise.

Here is a list of the top ten airports using vMUSE:

                                                                                                                                                                                                                                                                                                                                       

| Airport                           | Location       |
| --------------------------------- | -------------- |
| London Heathrow                   | United Kingdom |
| Glasgow Airport                   | United Kingdom |
| Berlin Schönefeld                 | Germany        |
| Dublin Airport                    | Ireland        |
| Cork Airport                      | Ireland        |
| Cologne Bonn Airport              | Germany        |
| Mazatlán International Airport    | Mexico         |
| Zihuatanejo International Airport | Mexico         |
| Monterrey International Airport   | Mexico         |
| Velana International Airport      | Maldives       |

Security researchers examining the public-facing infrastructure of the ARINC network quickly identified multiple red flags, painting a picture of a digital environment ripe for compromise. Public scans revealed that the company's network was running a host of obsolete software, including:

* Microsoft's IIS 8.5 web server, which reached its official end-of-life in 2023.
* A version of the Glassfish application server dating back to 2014.
* An Oracle Communications Messaging Server that had not been updated since 2015.

> These legacy systems contain well-documented vulnerabilities that have long since been addressed in newer versions.

A significant cybersecurity oversight appears to be the use of outdated network hardware. Half of the company's Cisco ASA VPN appliances — devices that act as the gatekeepers for the network — were operating past their manufacturer's end-of-life date, meaning they no longer received security updates. 

A wide range of known vulnerabilities exists for these devices and their software. Coupled with the fact that they must be internet-facing to function, the use of Cisco ASAs creates a high-risk environment ripe for exploitation.

Cyberattacks with such large-scale impacts usually require extensive preparation, and this event may have been set in motion as early as 2023. Though not confirmed by Collins Aerospace, the ransomware group BianLian [claimed to have breached Collins Aerospace in 2023](https://www.govinfosecurity.com/ransomware-behind-collins-aerospace-hack-enisa-says-a-29498), stealing around 20 gigabytes of data. 

If true, this event could have armed the attackers with the [data leaks they needed](https://www.upguard.com/product/breach-risk) to successfully execute this larger-scale attack.

## The core lesson: A failure of supply-chain security

Ultimately, the chaos that unfolded across Europe's airports was not just the result of a single company's security lapse but a catastrophic failure of supply-chain security. The incident is a textbook example of the ripple effects of an interconnected digital ecosystem, where a vulnerability in one vendor can trigger a cascade of disruptions for countless dependent organizations. 

> The reliance of multiple international airports and airlines on a single, compromised system creates a single point of failure that attackers could exploit with devastating effect.

Adding a critical layer to this failure, the European Union Agency for Cybersecurity (ENISA) revealed that the attackers' initial entry point was not Collins Aerospace, but one of its own third-party providers.

This oversight highlights a fundamental weakness in modern enterprise security: [most organizations are blind to the security risks of their vendor network.](https://www.upguard.com/product/vendorrisk)

This detail transforms the event from a direct vendor compromise into a multi-layered supply-chain attack, highlighting how deep and opaque these digital dependencies can be. It underscores a fundamental weakness in modern enterprise security: organizations are often blind to the risks inherited from their vendors' vendors.

To prevent future incidents of this scale, organizations must adopt a more rigorous and proactive approach to cyber risk posture management. 

Key recommendations include:

* **Demand complete transparency from vendors:** The most critical lesson from this event is that organizations must have deep visibility into their vendors' technology stacks and internal security policies. It is no longer sufficient to accept a vendor's assurances of security. Businesses must demand answers to specific, granular questions, like:

  * What software and hardware are you using? 
  * What are your patching schedules and update policies? 
  * How do you manage end-of-life equipment? T

> Proper supply chain security assumes a vendor's systems are likely attack vectors, and that begins with complete awareness of their digital footprint.

* **Implement robust legacy system management:** Critical systems that rely on older components or cannot be easily updated present a significant risk. These systems must be properly inventoried, continuously monitored, and protected with strong compensating controls to reduce their attack surface and isolate them from potential threats.
* **Elevate cybersecurity to a core business Function:** The level of investment and executive oversight in cybersecurity must directly correspond to the criticality of the systems being protected. Security cannot be treated as a simple back-office IT function; it is a fundamental business risk. Rectifying this organizational mindset is the first and most important step in building true resilience.

The aviation industry, and indeed all sectors relying on complex technology partners, must now move swiftly to implement these principles to build a more defensible Third-Party Risk Management foundation.

eBook

A Complete Guide to Data Breaches

Free resource

### A Complete Guide to Data Breaches

Learn how to avoid a costly data breach with a comprehensive prevention strategy.

[Download now](/resources/complete-guide-to-data-breaches)

## Related posts

Learn more about the latest issues in cybersecurity.

Cybersecurity

#### [Left Unsupervised: 10 Times Access Outlived Its Authorization](/blog/10-times-access-outlived-authorization)

Access granted once shouldn’t mean access forever. Read more on how unmonitored access caused 10 of these real-life breaches and what they taught us.

[](/team/revashni-moodley)

[Revashni Moodley](#)

August 25, 2026

Cybersecurity

#### [Surviving a LockBit Ransomware Attack: The ROI of Visibility](/blog/surviving-a-lockbit-ransomware-attack)

Read how veteran CISO Nick Gicinto saved his alma mater from a LockBit ransomware attack by discarding the standard playbook.

[](/team/nicholas-sollitto)

[Nicholas Sollitto](#)

June 1, 2026

Cybersecurity

#### [Top 10 Security Events of 2025](/blog/top-security-events-of-2025)

Recap the ten most impactful events that reshaped the cybersecurity industry this year and the critical lessons each had to teach us. Read more here.

[](/team/revashni-moodley)

[Revashni Moodley](#)

January 7, 2026

Cybersecurity

#### [Risk Automations: The Shift From Catch-Up to Command](/blog/risk-automations-shift-catch-up-to-command)

Connect intelligence to system execution with Risk Automations, your new resolution layer for risk. Reduce remediation from hours to seconds - read more.

[](/team/revashni-moodley)

[Revashni Moodley](#)

December 1, 2025

Cybersecurity

#### [Shai-Hulud's True Lesson for CISOs: A Crisis of Communication](/blog/shai-hulud-lesson-for-cisos)

Shai-Hulud was driven by a communication crisis between security and engineering. Get a CISO's perspective on how to finally bridge this gap.

[](/team/phil-ross)

[Phil Ross](#)

September 3, 2026

Cybersecurity

#### [UpGuard’s Updated Cyber Risk Ratings](/blog/cyber-risk-ratings-2024)

Discover UpGuard's updates to its cyber risk ratings, including enhanced risk categorization and an improved scoring algorithm.

[](/team/nicholas-sollitto)

[Nicholas Sollitto](#)

July 4, 2025

[All posts](/blog)

Experience superior visibility and a simpler approach to cyber risk management

[Get a demo](/contact-sales)

[Free trial](/demo)
