Cyberattack on European airports: How hackers target 'fragile Jenga tower of code'

Airports' security systems have to be fully protected, because even one entry way could prove disastrous
- PUBLISHED: Tue 23 Sept 2025, 7:39 AM UPDATED: Thu 25 Sept 2025, 2:03 PM
A cybersecurity researcher and analyst said that the likelihood of system disruptions at airports is growing, driven by an increase in digitalisation of airport operations, among other reasons.
This comes after several European airports were hit with cyberattacks, causing flight delays and cancellations. On Saturday and Sunday, Heathrow Airport and Brussels Airport’s check-in systems, provided by American aviation and defence technology company Collins Aerospace, were disrupted, affecting several airlines, including the Abu Dhabi-based carrier Etihad.
Although the attackers have not yet been identified, the BBC reported that “malicious software was used to scramble automatic check-in systems.”
Stay up to date with the latest news. Follow KT on WhatsApp Channels.
Maher Yamout, lead security researcher at META Kasperskylab, told Khaleej Times, that the likelihood of these kinds of attacks “is growing.”
“Increasing digitalisation of airport operations, reliance on shared service providers, and the complex interconnectivities expand the attack surface, which in turn gives cybercriminals more opportunities.”
Weakest link
“Attackers often look for the weakest link, which is frequently third-party suppliers or interconnected IT systems rather than the airport’s core network itself,” said Yamout. In cybersecurity and information security, the weakest link usually refers to humans, who are naturally prone to mistakes.
Airports' security systems have to be fully protected, because even one entry way could prove disastrous, leaving behind an entrance for malicious hackers to exploit vulnerabilities. Additionally, when multiple airports rely on the same check-in systems, one single weakness can cause a major disruption quickly, Bart Salaets, EMEA Field CTO at F5 said. “In critical sectors like this, downtime is expensive, so attackers know they have leverage,” he added.
Jenga tower of code
“Our critical IT infrastructure is often a fragile Jenga tower of third-party code and suppliers,” Gavin Millard, Vice President of Product at Tenable, told Khaleej Times. “When you pull the wrong brick, widespread systemic chaos can follow.”
Millard said that if the airport system disruptions were a result of cyber-attacks, then it was likely an unpatched vulnerability, a misconfiguration, or an authentication weakness that allowed it to happen.
“Attackers need only one way in, while defenders must cover every angle. But this doesn't have to be the case,” he said. He mentioned that British Airways was less affected due to a robust backup system, noting how its resilient systems were due to proactive planning.
“We must move beyond firefighting and focus on fireproofing by identifying single points of failure, prioritising the exposures that matter most, and having strong response plans in place," he added.
The aftermath
Although the attack is still fresh, the aviation sector will have to focus on improving its resilience, Rafe Pilling, director of threat intelligence at Sophos, said. Airports usually use third-party providers like baggage and check-in systems and airlines. Although they are critical to the smooth running of airports and flights, Pilling said they can “provide conduits for cyber-attacks into other systems as well as disrupt operations when they are themselves subjected to an attack.”
Salaets, the CTO for F5, added that “the aviation industry needs to focus on resilience, from better vendor risk management to building in redundancy, so one cyber-attack can’t bring everything to a standstill."




