NCA confirms arrest after airport cyber disruption
Disruption is easing across Europe following the ransomware incident
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
You are now subscribed
Your newsletter sign-up was successful
The UK’s National Crime Agency (NCA) has made an arrest over last week's cyber attack on several airports.
The agency said a man in his forties was arrested in West Sussex on suspicion of Computer Misuse Act offences, and released on conditional bail.
“Although this arrest is a positive step, the investigation into this incident is in its early stages and remains ongoing,” said Paul Foster, NCA deputy director and head of the NCA’s National Cyber Crime Unit.
30% off Keeper Security's Business Starter and Business plans
Keeper Security is trusted and valued by thousands of businesses and millions of employees. Why not join them and protect your most important assets while taking advantage of this special offer?
The cyber attack on software supplier Collins Aerospace led to major disruption for airlines flying out of London Heathrow, Brussels, and Berlin, with carriers forced to check passengers in manually.
The attack targeted Collins' ARINC cMUSE software, which allows airlines to share check-in desks and boarding gate positions rather than using their own dedicated infrastructure.
It's been confirmed that the incident was a ransomware attack, but so far little more is known. However, cybersecurity expert Kevin Beaumont said he had identified the ransomware used.
"The Europe airlines ransomware situation is a variant of Hardbit ransomware, which doesn’t have a portal and is incredibly basic," he wrote on Mastodon.
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
"They’ve had to restart recovery again as the devices keep getting reinfected. I’ve never seen an incident like it. Somebody like the NCSC needs to go in and help them with IR."
There's been a lot of speculation that the attack could have been carried out by a nation-state-affiliated group, with Russia having been tipped as the most likely suspect. That may now be in doubt, said Ryan McConechy, CTO at Barrier Networks.
"While details are still emerging, the NCA has confirmed that the suspect was arrested in the UK, which will likely come as a surprise to many," he said.
"While more information is likely to surface soon, the incident once again highlights that no organization is immune to cyber crime today. Whether attackers hit an organisation directly, or impact a large pool of organizations through a supply chain, cyber crime affects all businesses."
RTX, the parent company of Collins Aerospace, has confirmed in a filing with the US Securities and Exchange Commission (SEC) that the incident was a ransomware attack.
"The Company is diligently investigating the incident with the assistance of internal and external cybersecurity experts and has notified domestic and international law enforcement authorities and certain other government agencies," it said.
"The Company is also communicating with its customers and other stakeholders and providing technical support and guidance to affected airlines and airports."
RTX said it is investigating the incident with the help of internal and external cybersecurity experts, and that it's notified domestic and international law enforcement authorities and other government agencies.
Most flights are now operating normally, although some check-in desks are still processing passengers manually.
“Cyber crime is a persistent global threat that continues to cause significant disruption to the UK," said Foster. "Alongside our partners here and overseas, the NCA is committed to reducing that threat in order to protect the British public.”
Make sure to follow ITPro on Google News to keep tabs on all our latest news, analysis, and reviews.
MORE FROM ITPRO
- Cyber attacks are costing UK firms billions every year
- The top ransomware trends for businesses in 2025
- Financial impact of cyber attacks on UK retailers laid bare
Emma Woollacott is a freelance journalist writing for publications including the BBC, Private Eye, Forbes, Raconteur and specialist technology titles.
-
Ransomware gangs are sharing virtual machines to wage cyber attacks on the cheap – but it could be their undoingNews Thousands of attacker servers all had the same autogenerated Windows hostnames, according to Sophos
-
Google issues warning over ShinyHunters-branded vishing campaignsNews Related groups are stealing data through voice phishing and fake credential harvesting websites
-
Notepad++ hackers remained undetected and pushed malicious updates for six months – here’s who’s responsible, how they did it, and how to check if you’ve been affectedNews Hackers remained undetected for months and distributed malicious updates to Notepad++ users after breaching the text editor software – here's how to check if you've been affected.
-
CISA’s interim chief uploaded sensitive documents to a public version of ChatGPT – security experts explain why you should never do thatNews The incident at CISA raises yet more concerns about the rise of ‘shadow AI’ and data protection risks
-
Former Google engineer convicted of economic espionage after stealing thousands of secret AI, supercomputing documentsNews Linwei Ding told Chinese investors he could build a world-class supercomputer
-
The FBI has seized the RAMP hacking forum, but will the takedown stick? History tells us otherwiseNews Billing itself as the “only place ransomware allowed", RAMP catered mainly for Russian-speaking cyber criminals
-
Everything we know so far about the Nike data breachNews Hackers behind the WorldLeaks ransomware group claim to have accessed sensitive corporate data
-
90% of companies are woefully unprepared for quantum security threats – analysts say they need to get a move onNews Quantum security threats are coming, but a Bain & Company survey shows systems aren't yet in place to prevent widespread chaos



