Man arrested by NCA for airport outages caused by HardBit ransomware
A man has been arrested in connection with a ransomware attack that is causing flight delays across Europe, according to the UK’s National Crime Agency (NCA). The arrest took place in West Sussex, with the suspect being released on conditional bail. The NCA’s National Cyber Crime Unit is leading the investigation, emphasizing the persistent global threat of cybercrime and its impact on the UK.
Security experts have linked the attack on US firm Collins Aerospace to the HardBit ransomware variant, which has been described as basic without a portal. The disruption began on September 19, affecting airports over the weekend due to issues with the ARINC vMUSE software used for check-in desks and boarding gates by multiple airlines. Collins Aerospace confirmed ransomware on the systems supporting MUSE, despite operating outside the main enterprise network. Efforts to contain and respond to the incident have faced challenges, with devices being repeatedly infected, requiring the involvement of cybersecurity experts to assist with incident response.
The repercussions have been felt by airlines resorting to manual processes for check-ins and boarding, resulting in delays at airports like Heathrow, Brussels, and Berlin Brandenburg. Delay times varied, with most falling slightly as of Thursday morning, reflecting ongoing efforts to resolve the situation. EU security agency Enisa attributed the ransomware incident to a breach by a third-party supplier, sparking investigations with the help of internal and external cybersecurity experts, as well as notifications to law enforcement agencies and government authorities.
The incident highlights the disruptive and damaging nature of ransomware attacks, showcasing the importance of cybersecurity hygiene and prompt, effective incident response to mitigate their impact. The collaboration between law enforcement agencies, cybersecurity experts, and affected organizations is crucial in addressing and resolving such cyber threats. As cybercriminals continue to evolve their tactics, proactive measures and robust cybersecurity strategies are essential to safeguard critical infrastructure and systems against ransomware attacks. The incident serves as a reminder of the persistent cyber threats faced by organizations globally and the need for constant vigilance and preparedness to combat such malicious activities effectively.