UK National Crime Agency arrests suspect in airline cyberattack as consequences of Collins Aerospace ransomware attack persist

An individual was apprehended by the U.K. National Crime Agency (NCA) in West Sussex in connection with the ongoing investigation into the cybersecurity incident that affected Collins Aerospace. The incident led to widespread flight disruptions at major European airports such as Heathrow, Brussels, and Berlin, prompting authorities and the company to work towards restoring normal operations over the weekend.

The NCA, supported by the South East ROCU, conducted the arrest on suspicion of Computer Misuse Act offenses. The individual, a man in his forties, was released on conditional bail. Paul Foster, deputy director and head of the NCA’s National Cyber Crime Unit, emphasized that the cybercrime investigation is in its early stages and remains ongoing. He highlighted that cyber threats pose a persistent global challenge causing significant disruptions. The NCA is dedicated to reducing this threat to safeguard the British public.

RTX, the owner of Collins Aerospace, confirmed a ransomware cybersecurity incident involving the Multi-User System Environment (MUSE) passenger processing software that supports multiple airlines in sharing check-in and gate resources at airports. The incident prompted the activation of the company’s response plan to assess, contain, respond to, and remedy the situation. Collaboration with cybersecurity experts, internal investigations, and communication with law enforcement and government agencies were all part of the response effort.

As a result of the incident, affected airlines and airports had to resort to backup or manual procedures, resulting in flight delays and cancellations. However, RTX assured that the incident has not had a material impact on its financial status or business operations. Despite limited details disclosed by RTX, cybersecurity expert Kevin Beaumont identified the ransomware variant used as HardBit, which he described as basic. He noted the challenges faced in recovery efforts due to repeated reinfections.

Public information on HardBit revealed that it operates as a Ransomware-as-a-Service, encrypting files and demanding ransom payments. The ransomware strain evolved to version 4.0 by early 2024, incorporating additional security features. Organizations can protect themselves from HardBit attacks by implementing strategies such as maintaining offline backups, enhancing staff training on phishing, isolating networks, deploying advanced endpoint protection, and establishing a comprehensive incident response plan.

In addition to the incident involving Collins Aerospace, major airports like London’s Heathrow, Brussels, and Berlin experienced flight disruptions since Friday. Brussels Airport reported cancellations, while Berlin Brandenburg anticipated continued delays due to ongoing system issues. At Heathrow, the majority of flights operated normally, with the airport advising passengers to check flight statuses and arrive according to the recommended time frames.

Further research by CYFIRMA indicated that threat groups like Alixsec, Scattered Spider, and the Rhysida ransomware group could be potential actors based on their previous targeting behavior and capabilities. Alixsec’s declaration to target critical infrastructure sites, including transportation hubs like London Heathrow Airport, raises concerns about operational disruptions and underscores the importance of enhanced monitoring and defensive measures.