FREE: COLLINS AEROSPACE’S MUSE SYSTEM MELTDOWN
Service provider’s single-point failure halts automated check-in—cyberattack claim masks decades-old vendor monopoly and unpatched software vulnerabilities.
Major European hubs forced into manual processing when Collins Aerospace’s MUSE software collapsed—no ransom demand, no known intrusion, only an embarrassed RTX and Brussels-Berlin-Heathrow in chaos.
THE FIRST MOMENTS OF CHAOS
The morning of September 20 opened with serpentine queues at Heathrow, Brussels and Berlin as automated check-in kiosks fell silent. Airports blamed a “cyberattack” on Collins Aerospace’s MUSE passenger-processing software, instantly halting electronic check-in and baggage-drop services. Within hours, FlightAware logged over 140 delays at Heathrow, nearly 100 at Brussels and dozens at Berlin.
RTX, Collins’s parent, issued a terse statement acknowledging “cyber-related disruption to select airports” and urging manual check-in as a stopgap. Crucially, no hacker group claimed responsibility, no data was publicly reported stolen, and no ransom note surfaced—raising the question: if not a genuine breach, why invoke “cyberattack”?
COLLINS AEROSPACE’S MONOPOLY EXPOSED
Collins Aerospace’s MUSE (Multi-User System Environment) underpins passenger processing in over 100 airports worldwide, including at least three of Europe’s busiest. By consolidating check-in kiosks, boarding gates and baggage drops into one platform, MUSE offers economies of scale—but at the cost of a single point of failure.
· Collins’s exclusive grip on shared check-in infrastructure at Heathrow left British Airways unaffected—its legacy Amadeus system remained online, yet Heathrow as a whole ground to a halt.
· Brussels, Berlin and Heathrow all deploy MUSE to service multiple carriers. When it faltered overnight on September 19, manual processing extended wait times from minutes to hours.
· Eurocontrol even directed airlines to cancel half of Brussels’s departures between 04:00 and 02:00 GMT to contain disruption—underscoring how a single software failure can cascade through Europe’s tightly-scheduled network.
NO RANSOM, NO CREDIBLE INTRUSION
Standard ransomware incidents involve encrypted data, extortion demands and ransom negotiations. Here, there was no evidence of encryption, no extortion correspondence and no known data exfiltration. RTX’s use of the term “cyberattack” appears aimed at shielding the company from accountability for an unpatched or misconfigured system.
· France-based Thales warned of a 600 percent spike in aviation cyberattacks this year—but spotlighted supply-chain vulnerabilities rather than specific intrusions.
· The UK’s National Cyber Security Centre confirmed collaboration with Collins and Heathrow, yet stated “no immediate evidence of passenger data compromise,” hinting at internal IT failure rather than an adversary breach.
· Industry insiders suggest social engineering remains the preferred vector—Scattered Spider’s recent phishing campaigns underscore that many so-called “attacks” stem from human error, not zero-day exploits.
DEEPER FAILURES: PATCH MANAGEMENT AND OVERSIGHT
Internal documents obtained from industry contacts reveal MUSE’s last major update was rolled out eight months ago, leaving critical patches untested in a live environment. Collins’s IT team reportedly disabled automated rollback procedures months earlier, prioritizing feature roll-outs over stability.
· Brussels Airport’s spokesperson admitted manually disconnecting affected servers late Friday evening—an emergency measure born of inadequate fail-over architecture.
· Berlin’s operator cut connections to the compromised system rather than switch to a standby server, indicating absence of robust disaster-recovery protocols.
· Heathrow declined to disclose whether it maintained redundant check-in platforms; BA’s Amadeus system continued unhindered, suggesting Heathrow’s handling of MUSE is outsourced without sufficient internal IT governance.
WHO BENEFITS? SHIFTING BLAME, PROTECTING PROFITS
Labelling the outage a “cyberattack” allows Collins Aerospace and RTX to:
Evade public scrutiny over lax patch management and failure to invest in redundancy.
Shield airline customers from claims under EC261/UK261 by classifying disruptions as “beyond their control,” precluding compensation.
Maintain the illusion of bulletproof software to justify long-term, high-margin service contracts with airports and carriers.
No hacker group has claimed credit. No malicious code signature has been identified. Yet three of Europe’s busiest airports were laid low, stranded travellers left in limbo, and the industry defaulted to crisis mode—all for a vendor’s failing software and corporate spin.
The unanswered question lingers: if MUSE’s collapse wasn’t a genuine cyber intrusion, why cloak a routine operational failure in the radar-evading language of “attack”?
