The Register Home Page

back to article EU’s cyber agency blames ransomware as Euro airport check-in chaos continues

The EU's cybersecurity agency today confirmed that ransomware is the cause of continued disruption blighting major airports across Europe. Aside from the disturbance at various airports including London Heathrow, Berlin Brandenburg, and those in Brussels, Dublin, and Cork, very little is known about the specifics of the attack …

  1. elsergiovolador Silver badge

    Elephant

    The coverage keeps circling around which gang is behind it and which airport is delayed, but it tiptoes past the elephant in the room: IT is systematically underpaid and under-resourced. You don’t build resilience when the people keeping the lights on are treated like disposable overhead. The result isn’t surprising - it’s inevitable. Until the industry stops squeezing IT as a cost centre, these ‘shocks’ will just keep happening.

    See how much RTX pays for the roles...

    1. Lee D Silver badge

      Re: Elephant

      The problem is not even that.

      The problem is that a major critical utility like an airport shouldn't be running on general purpose operating systems running on commodity hardware connected to the wider Internet.

      At all. Ever. It never should have got that far at all.

      We've totally lost sight of what these systems need to be secure, and instead lobbed them at the cloud, managed by a bunch of people who can't understand anything that isn't fully remotely accessible with full admin rights on a GUI desktop.

      There shouldn't even BE an opportunity for a system like this to get ransomware, even if specifically targeted.

      1. Anonymous Coward
        Anonymous Coward

        Re: Elephant

        But isn't that the story of society in general? Everything runs on commodity hard and software these days.

        And it will get worse. I see RISC-V and even WASM taking over the role Intel has today.

        I've been proposing to asses the re-introduction of mainframes in critical infrastructure since our society has become very fragile due to the combination of internet and commodity hardware/software. Both China and Russia are making good use of this by stealing all of our secrets. Unless we invent an architecture that's inherently secure (which is attainable IMHO) we should consider going back to typewriters and paper for some processes.

      2. Anonymous Coward
        Anonymous Coward

        Re: Elephant

        I think both of you may be somewhat in agreement.

        That is, if there were proper systems folks involved early on, and then ongoing, with some say-so over implementation and support etc., the major critical utility wouldn't have got into that situation in the first place.

        Instead, it was most likely spec'd and procured by committee, influenced by politics and/or graft along the way, designed as a technicolor intergalactic extravaganza by grossly overpaid consultants, and built and staffed by lowest bidder. Then underfunded, understaffed, and neglected until it was time for blame and finger pointing.

  2. ChrisElvidge Silver badge

    As Dr Syntax said earlier

    https://forums.theregister.com/forum/all/2025/09/22/technology_problems_cause_aviation_delays/#c_5147175

    Collins aerospace = SPOF

  3. VicMortimer Silver badge

    Criminalize paying ransom

    Ransomware is NEVER going to get better until paying ransom is criminalized.

    When CEOs can go to prison for paying, ransomware will become unprofitable and go away.

    1. Aladdin Sane Silver badge

      Re: Criminalize paying ransom

      They'll just find a work around. You need to make it unprofitable by hunting down and absolutely hammering the perpetrators, which will require both cash and political capital.

      1. DS999 Silver badge

        Re: Criminalize paying ransom

        And when they're in Russia, or some other place out of the reach of international law?

        1. Anonymous Coward
          Anonymous Coward

          Re: Criminalize paying ransom

          Contract with the US military, they have tactical nuclear weapons.

          1. DS999 Silver badge
            Facepalm

            Re: Criminalize paying ransom

            Ah yes going to war with Russia over ransomware sounds like a MUCH better option than banning the payment of ransom!

            1. Aladdin Sane Silver badge
              Mushroom

              Re: Criminalize paying ransom

              Haven't you been paying attention? A nuclear apocalypse is coming soon to a country near you, so we might as well get something useful out of it.

      2. elsergiovolador Silver badge

        Re: Criminalize paying ransom

        You also need to ensure the solution would be brown envelope proof.

    2. Mixedbag

      Re: Criminalize paying ransom

      and then the ransomware groups will contract people to kidnap family members of the board.

      Thus turning it into Pay and goto jail or don't pay and bad things will happen to your friends and family

      1. DS999 Silver badge

        Re: Criminalize paying ransom

        Criminals could have been doing that since long before computer existed. If that was a thing, why is kidnapping family members of corporate elite mostly a Hollywood action movie trope with few actual instances?

        1. elsergiovolador Silver badge

          Re: Criminalize paying ransom

          - You've got my son Timmy? Oh thank god. This ungrateful rug rat.

          - Sir, the ransom is 10 million dollars!

          - Nah mate, keep it.

          - But Sir, it is your son!

          - It's Timmy, he ruined my life! Keep the bastard!

          - We don't want him.

          - Right. See?

          1. Anonymous Coward
            Anonymous Coward

            Re: Criminalize paying ransom

            The correct response in line 3 is

            "you'll have to pay me more than that to take my son back!"

        2. Anonymous Coward
          Anonymous Coward

          Re: Criminalize paying ransom

          There used to be a trend of "tiger kidnapping" in Dublin (not corporate elite, just bank officers), transfer x amount for the safe release of your family. They'd break into the home before work then drop the guy to his office with a time limit to transfer funds.

    3. elsergiovolador Silver badge

      Re: Criminalize paying ransom

      Criminalise neglecting IT...

    4. Lee D Silver badge

      Re: Criminalize paying ransom

      Paying ransom is prima facie money laundering.

      Ask your auditors.

      You're paying a unidentified 3rd party huge sums of money in order to appease a crime, with no record of the transaction's destination.

      There is no way to distinguish "we were attacked and paid a ransom" from "hey, brother, I have a plan... you pretend to attack my company, I'll pay you the ransom via an anonymous payment method, then we split the proceeds 50-50 when the dust settles".

      I bring this up regularly when my employers talk about potential responses to ransomware. Paying them is money laundering. Because I can't tell if I'm paying that money illicitly to the CEO's brother, or some guy in Russia. Any audited account should be all over that with flashing red alarm signals going off at the very mention of such.

      It's already criminalised. We're just not enforcing that law. Another law isn't going to help.

  4. Frank Leonhardt

    Aircraft operate in clouds, but this is what you get for putting software there.

    cMUSE (Actually stands for common-use Multi-User System Environment) is a cloud based system running on AWS, doing away with on-site infrastructure as a selling point.

    As with anything cloud based (SaaS), there's a single point where it can be hit. This is how they've hit multiple airlines in one go. Anyone considering a move to the cloud really needs to think seriously about how stupid the concept of a "virtual air-gap" really is, and if your security decision maker still thinks it's a great idea, get someone else.

    Incidentally, their competition (SITA's BagManager, although it only tracks luggage) - is also cloud-based. cMUSE can optionally be run on-prem but I strongly suspect the airlines that got whacked in parallel are using the AWS version. Don't you?

    'sfunny how the BBC doesn't mention this stuff.

    1. elsergiovolador Silver badge

      Re: Aircraft operate in clouds, but this is what you get for putting software there.

      Imagine a more orange version of Krasnov, where he has a fit and signs a decree for AWS to stop services to unfriendly countries. Everything gets grounded and then leaders will have to come begging on their knees for oranger emperor to turn the services back on.

      1. Frank Leonhardt

        Re: Aircraft operate in clouds, but this is what you get for putting software there.

        Leaving the political personalities out of it, this is an excellent point. The west is worried about China flipping a switch and turning our webcams and iPhones against us, but government interference with a cloud service provider can do a lot of damage. But they're not dumb enough to fall for it.

        China's largest cloud provider is Alibaba Cloud, followed by Huawei and Tencent (mostly gaming) and Baidu. Microsoft Azure China only as around 4%, AWS slightly less.

        Russia is dominated by Yandex, VK Cloud, Selectel, MTS and Croc. Sanctions have all-but killed AWS and Azure in Russia, when previously they'd have held a third between them. Microsoft (in compliance with US and EU sanctions, did cut off Russia in Q1 this year but by halting sales in 2022 signalled that customers there needed to think of other providers so they had plenty of warning.

        AWS stopped selling but still provides services to non-sanctioned customers. Given the SWIFT ban cited by Microsoft as a reason to pull out, one wonders how they're paying their AWS bill. Laundering through Amazon Marketplace perhaps :-)

  5. Anonymous Coward
    Anonymous Coward

    Apparently there's been an issue with reinfection of servers and terminals at Heathrow which seems to be hampering Collins' ability to fix the problem. They're anticipating several more days of reliance on contingency procedures as there's no definite resolution date.

    Anon for reasons.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon

Other stories you might like