NCA confirms arrest after airport cyber disruption
Disruption is easing across Europe following the ransomware incident
The UK’s National Crime Agency (NCA) has made an arrest over last week's cyber attack on several airports.
The agency said a man in his forties was arrested in West Sussex on suspicion of Computer Misuse Act offences, and released on conditional bail.
“Although this arrest is a positive step, the investigation into this incident is in its early stages and remains ongoing,” said Paul Foster, NCA deputy director and head of the NCA’s National Cyber Crime Unit.
30% off Keeper Security's Business Starter and Business plans
Keeper Security is trusted and valued by thousands of businesses and millions of employees. Why not join them and protect your most important assets while taking advantage of this special offer?
The cyber attack on software supplier Collins Aerospace led to major disruption for airlines flying out of London Heathrow, Brussels, and Berlin, with carriers forced to check passengers in manually.
The attack targeted Collins' ARINC cMUSE software, which allows airlines to share check-in desks and boarding gate positions rather than using their own dedicated infrastructure.
It's been confirmed that the incident was a ransomware attack, but so far little more is known. However, cybersecurity expert Kevin Beaumont said he had identified the ransomware used.
"The Europe airlines ransomware situation is a variant of Hardbit ransomware, which doesn’t have a portal and is incredibly basic," he wrote on Mastodon.
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
"They’ve had to restart recovery again as the devices keep getting reinfected. I’ve never seen an incident like it. Somebody like the NCSC needs to go in and help them with IR."
There's been a lot of speculation that the attack could have been carried out by a nation-state-affiliated group, with Russia having been tipped as the most likely suspect. That may now be in doubt, said Ryan McConechy, CTO at Barrier Networks.
"While details are still emerging, the NCA has confirmed that the suspect was arrested in the UK, which will likely come as a surprise to many," he said.
"While more information is likely to surface soon, the incident once again highlights that no organization is immune to cyber crime today. Whether attackers hit an organisation directly, or impact a large pool of organizations through a supply chain, cyber crime affects all businesses."
RTX, the parent company of Collins Aerospace, has confirmed in a filing with the US Securities and Exchange Commission (SEC) that the incident was a ransomware attack.
"The Company is diligently investigating the incident with the assistance of internal and external cybersecurity experts and has notified domestic and international law enforcement authorities and certain other government agencies," it said.
"The Company is also communicating with its customers and other stakeholders and providing technical support and guidance to affected airlines and airports."
RTX said it is investigating the incident with the help of internal and external cybersecurity experts, and that it's notified domestic and international law enforcement authorities and other government agencies.
Most flights are now operating normally, although some check-in desks are still processing passengers manually.
“Cyber crime is a persistent global threat that continues to cause significant disruption to the UK," said Foster. "Alongside our partners here and overseas, the NCA is committed to reducing that threat in order to protect the British public.”
Make sure to follow ITPro on Google News to keep tabs on all our latest news, analysis, and reviews.
MORE FROM ITPRO
- Cyber attacks are costing UK firms billions every year
- The top ransomware trends for businesses in 2025
- Financial impact of cyber attacks on UK retailers laid bare
Emma Woollacott is a freelance journalist writing for publications including the BBC, Private Eye, Forbes, Raconteur and specialist technology titles.
-
Ransomware negotiator sentenced for role in major cyber crime groupNews Deniss Zolotarjovs was a key player in a group associated with Conti
-
Threat actors ditch ‘spray and pray’ attacks in shift to targeted exploitationNews A dip in ransomware volumes points to a more targeted approach focused on vulnerability exploitation
-
Security leaders overconfident about ransomware recoveryNews Few manage to recover all their data, and many experience business disruption
-
German authorities want your help finding the hackers behind GandCrab and REvilNews Daniil Maksimovich Shchukin and Anatoly Sergeevitsch Kravchuk are believed to have made millions from ransomware as a service schemes
-
The rise of teen hackers ‘makes for a good headline’, but cyber crime activities peak later in lifeNews With family responsibilities and mortgages to pay, it's not teenagers dishing out malware or carrying out cyber extortion
-
Using AI to generate passwords is a terrible idea, experts warnNews Researchers have warned the use of AI-generated passwords puts users and businesses at risk
-
Researchers called on LastPass, Dashlane, and Bitwarden to up defenses after severe flaws put 60 million users at risk – here’s how each company respondedNews Analysts at ETH Zurich called for cryptographic standard improvements after a host of password managers were found lacking
-
‘They are able to move fast now’: AI is expanding attack surfaces – and hackers are looking to reap the same rewards as enterprises with the technologyNews Potent new malware strains, faster attack times, and the rise of shadow AI are causing havoc



