ARINC SelfServ vMUSE devices are down in airports in EU, they do self service check in. They’re connected to navAviNet aka ARINC Ground Network, managed by Collins Aerospace, who are owned by RTX.
An attacker got onto to the shared network.
Questa voce è stata modificata (2 settimane fa)
reshared this
Kevin Beaumont
in reply to Kevin Beaumont • • •Kevin Beaumont
in reply to Kevin Beaumont • • •Kevin Beaumont
in reply to Kevin Beaumont • • •Shodan dork if you wanna rubberneck:
org:"ARINC INCORPORATED"
6x AnyConnect VPN boxes offline
Kevin Beaumont
in reply to Kevin Beaumont • • •BBC good reporting on the ground impact
In theory it should be minimal but in practice airlines have automated many jobs so we’ll see.
bbc.co.uk/news/articles/c3drpg…
Heathrow cyber-attack: Delays possible after check-in system hit
Maia Davies (BBC News)G
in reply to Kevin Beaumont • • •Given how much airlines are pushing people towards self service check-in and as a result how few staff they have on check-in desks in some cases…
I’m not sure it will be quite such a minimal impact
PhreakByte
in reply to G • • •PhreakByte
in reply to PhreakByte • • •@cirriustech here are the “top ten” airports using vMUSE. See any you recognize in Europe as listed in current incident ;)
1. London Heathrow (LHR)
2. Glasgow Airport (GLA)
3. Berlin Schönefeld (SXF)
4. Dublin Airport (DUB)
5. Cork Airport (ORK)
6. Cologne Bonn Airport (CGN)
7. Mazatlán International Airport (Mexico)
8. Zihuatanejo International Airport (Mexico)
9. Monterrey International Airport (Mexico)
10. Velana International Airport (Maldiverne)
reshared this
Oblomov reshared this.
Kevin Beaumont
in reply to Kevin Beaumont • • •Kevin Beaumont
in reply to Kevin Beaumont • • •Oblomov reshared this.
Kevin Beaumont
in reply to Kevin Beaumont • • •If any journalists want a list of top impacted airports to check: infosec.exchange/@nieldk/11523…
BBC have Dublin and Cork added.
PhreakByte
2025-09-20 15:45:00
Kevin Beaumont
in reply to Kevin Beaumont • • •Kevin Beaumont
in reply to Kevin Beaumont • • •Kevin Beaumont
in reply to Kevin Beaumont • • •Kevin Beaumont
in reply to Kevin Beaumont • • •Kevin Beaumont
in reply to Kevin Beaumont • • •ARNIC are flying engineers out to airports to try to fix terminals.
Brussels airport, EBBR, have issued this NOTAM: “AD LTD DUE TO AN IT SYSTEM DISRUPTION. AIRLINES ARE TO CANCEL 50
PERCENT OF THEIR DEPARTING PASSENGER FLIGHTS IN THIS TIMEFRAME”
Oblomov reshared this.
Kevin Beaumont
in reply to Kevin Beaumont • • •The ARINC incident continues bbc.co.uk/news/articles/cwy888…
Also for anybody interested, ARINC is where the cyber incident is.
ARINC were basically the OG airport network provider, from 1929. ARNIC were sold to Carlyle Group (private equity) in 2007, who sold them to Rockwell Collins in 2013, who sold to United Technologies in 2018, who merged to form Collins Aerospace. Their network looks a mess of US corporate shenanigans… webmail doesn’t even require https yet 😅
Heathrow cyber-attack: Airports warn of second day of disruption
Maia Davies (BBC News)reshared this
Oblomov reshared this.
Kevin Beaumont
in reply to Kevin Beaumont • • •Worth noting that airplanes are incredibly safe and resilient after extensive regulation and open and transparent investigations of every air incident…
when you land on the ground, however, air travel is caught in the same cybersecurity bullshit every other industry is caught up in.
Oblomov reshared this.
Kevin Beaumont
in reply to Kevin Beaumont • • •European airport disruption continues after weekend cyber-attack
Tabby Wilson (BBC News)Kevin Beaumont
in reply to Kevin Beaumont • • •Kevin Beaumont
in reply to Kevin Beaumont • • •Kevin Beaumont
in reply to Kevin Beaumont • • •After ARINC restored domain controllers from backup, the threat actor got back in and started trashing more stuff. 🫡
The whole thing is a mess, they probably want to pause, take a breathe, and think about flushing out attacker before rebuilding things.
Kevin Beaumont
in reply to Kevin Beaumont • • •European airport disruption continues after weekend cyber-attack
Tabby Wilson (BBC News)Kevin Beaumont
in reply to Kevin Beaumont • • •Kevin Beaumont
in reply to Kevin Beaumont • • •Berlin Airport ran at 70% delays yesterday
dailyfinland.fi/europe/45344/L…
I’ve confirmed today that Heathrow, Berlin and Dublin all still have no Muse terminals restored. I haven’t checked other airports. It’s even more complicated because Muse both processes and stores biometrics of passengers.
"Before we reconnect our system, we must be 100% sure that there are no malware programmes left," the BER spokesman said.
Long delays at Berlin airport as authority confirms ransomware attack
dailyfinlandKevin Beaumont
in reply to Kevin Beaumont • • •Fuxle 🦊🏳️🌈 reshared this.
Kevin Beaumont
in reply to Kevin Beaumont • • •Kevin Beaumont
in reply to Kevin Beaumont • • •Kevin Beaumont
in reply to Kevin Beaumont • • •The Europe airlines ransomware situation is a variant of Hardbit ransomware, which doesn’t have a portal and is incredibly basic.
They’ve had to restart recovery again as the devices keep getting reinfected. I’ve never seen an incident like it. Somebody like the NCSC needs to go in and help them with IR.
Kevin Beaumont
in reply to Kevin Beaumont • • •Look at Dublin airport, reporters starting to realise it never actually got fixed 😅
thejournal.ie/dublin-airport-i…
No timeline for fix to issues slowing operations at Dublin Airport's Terminal 2, says DAA
TheJournal.ieKevin Beaumont
in reply to Kevin Beaumont • • •Kevin Beaumont
in reply to Kevin Beaumont • • •Flight delays today:
Heathrow 78%
Brussels 79%
Dublin 68%
Berlin 86%
All are vMuse. London City isn't on vMuse, they're at 35% as a point of comparison.
Kevin Beaumont
in reply to Kevin Beaumont • • •Kevin Beaumont
in reply to Kevin Beaumont • • •Man arrested in connection with cyber-attack on airports
Imran Rahman-Jones (BBC News)Kevin Beaumont
in reply to Kevin Beaumont • • •reshared this
Andrea Dell’Amico reshared this.
Ben Tasker
in reply to Kevin Beaumont • • •According to Ben Tasker, manager of Ben Tasker's bank account, sending me $1000 can prevent cyber-attacks
^ basically the same thing but with different names
Kevin Beaumont
in reply to Kevin Beaumont • • •NPR and PBS have somehow managed to run a completely bollocks article linking the EU airport thing to AI - the article itself written by an AI cybersecurity vendor. wgcu.org/science-tech/2025-09-…
It's completely false. The payloads used in this one are detected by free Defender AV with a decade old static AV detections. This is not some cyber mega attack by a ransomware group: it's extremely poor security hygiene.
Detection expert says hackers likely used AI to penetrate airport system
Undetectable.ai/Special to WGCU (WGCU)reshared this
gelato_al_pollo, Dizzy, Ricardo Martín, e_es, myrmepropagandist e GhostOnTheHalfShell reshared this.
Kevin Beaumont
in reply to Kevin Beaumont • • •rtx-20250919
www.sec.govKevin Beaumont
in reply to Kevin Beaumont • • •If your board is concerned about the EU ransomware thing - there is no need to be concerned. It is not a wider issue.
It wouldn't surprise me if the person arrested turns out to be an employee trying to do incident response or some such (I'm not saying they're guilty, at all).
It's an extremely unusual incident and essentially involves lax cybersecurity and confused response.
Kevin Beaumont
in reply to Kevin Beaumont • • •ARINC/Collins have been unable to restore the systems in Brussels airport so they are ripping out and replacing everything.
lesoir.be/700923/article/2025-…
HT @0xThiebaut
There’s a bit more info here: aviation24.be/airports/brussel…
They will keep cancelling 10% of flights each day for the foreseeable future.
Cyberattaque à Brussels Airport : un nouveau système déployé ce lundi avec l’espoir d’un retour à la normale
Par Belga (Le Soir)Kevin Beaumont
in reply to Kevin Beaumont • • •Flight delays today:
Heathrow 90%
Brussels 89%
Dublin 84%
Berlin 86%
All are vMuse. London City isn't on vMuse, they're at 33% as a point of comparison.
Kevin Beaumont
in reply to Kevin Beaumont • • •In terms of recovery:
- Heathrow going nowhere, manual workarounds to issue bag tags and boarding passes, airlines have been told to maintain continency measures until w/c October 6th
- Brussels Airport are manual workarounds to issue bag tags and boarding passes, and are ripping out all their vMuse terminals and Muse IT infrastructure and replacing them
- Dublin making progress to starting restoration
- Berlin manual workarounds to issue bag tags and boarding passes
Kevin Beaumont
in reply to Kevin Beaumont • • •A bit more on Berlin: heise.de/en/news/Cyberattack-o…
travelandtourworld.com/news/ar…
Cyberattack on airports: Problems continue at BER and one arrest
Malte Kirchner (heise online)Kevin Beaumont
in reply to Kevin Beaumont • • •Kevin Beaumont
in reply to Kevin Beaumont • • •Aer Lingus have got their check in terminals working again at Dublin Airport
ittn.ie/travel-news/aer-lingus…
Caribtours Agent Dinner – Dublin
Geoff Percival (ITTN)Kevin Beaumont
in reply to Kevin Beaumont • • •Flight delays today:
Heathrow 95%
Brussels 94%
Dublin 76%
Berlin 80%
All are vMuse. London City isn't on vMuse, they're at 33% as a point of comparison.
Kevin Beaumont
in reply to Kevin Beaumont • • •If you're traveling via Heathrow, Brussels, Dublin or Berlin airport this weekend - flights are running fine but average 90% delays still.
Check in online (rather than at the airport). If you need to baggage drop add about ~30 mins to your usual schedule.
Expectation is this will last for about another week or two due to the ongoing issues at ARINC/Collins/RTX.
The exceptions are British Airways and Aer Lingus, who are okay now and extra staffed too.
Kevin Beaumont
in reply to Kevin Beaumont • • •Kevin Beaumont
in reply to Kevin Beaumont • • •yahoo.com/news/articles/berlin…
Yahoo fait partie de la famille de marques Yahoo.
www.yahoo.comKevin Beaumont
in reply to Kevin Beaumont • • •Flight delays today:
Heathrow 81%
Brussels 81%
Dublin 73%
Berlin 77%
Kevin Beaumont
in reply to Kevin Beaumont • • •I'm probably going to stop tracking this one for now, basically the impacted airports are mostly okay to travel through, check in online basically.
Airports did a really good at being resilient, by falling back to paper and/or using online check in.
Collins, less so.
Kevin Beaumont
in reply to Kevin Beaumont • • •Kevin Beaumont
in reply to Kevin Beaumont • • •EaSi123
in reply to Kevin Beaumont • • •