Europe’s largest airports dealing with fallout from major cyberattack

Europe’s largest airports dealing with fallout from major cyberattack

Europe’s busiest airports are reeling from a major cyberattack that rippled through Heathrow, Brussels, Berlin and beyond.

Experts say the incident is a textbook supply chain attack that has exposed the fragility of aviation’s digital ecosystem.

The disruption has sparked urgent warnings that cybersecurity in aviation must be treated as a board-level risk, on par with physical safety.

Industry experts have reacted to the news:

David Mound, Head of Research and Community at Shinobi Security, said: “The aviation industry runs on an intricate web of legacy systems and providers, making it an inevitable target – but inevitability shouldn’t mean acceptance. Cybersecurity is not just an IT issue; it’s a critical business risk with global ripple effects. One breach has disrupted tens of thousands of passengers – if that doesn’t put cybersecurity on the boardroom agenda, nothing will.”

Tom Kidwell, a former British Army and UK Government intelligence specialist, and Co-founder of Ecliptic Dynamics, said: “The attack over the weekend was another stark reminder of the dangers Europe’s most critical organisations face. While details at this moment in time are scarce, we know from experience the most common ways attackers breach these types of organisations.

“Phishing campaigns, which despite being the most basic are also the most effective, have long been the favourite technique used by attackers. However, recent attacks on M&S, Co-op, and JLR are suspected to have been carried out using social engineering; a devastating vector which uses the identities of real or fake employees to trick other staff into compromising their own organisations, lowering defences or sharing critically sensitive information.

“The reality is that, in 2025, the world is not on the most steady heading. Active conflict zones in Europe, the Middle East, Asia and Africa are causing global diplomatic tensions. And while many are concerned about physical attacks on the UK and Western Europe, there is a much higher probability of damaging cyberattacks being aimed this way, likely by Russia or other malicious states.

“This attack is another wake up call that the risk of our CNI (critical national infrastructure) being targeted by malicious actors is growing, and without fresh approach to managing that risk, breaches will continue to occur.”

Jamie Akhtar, CEO and Co-founder at CyberSmart, said: “To reduce risk from this kind of disruption, organisations need more than perimeter defences. That means rigorous assessment of supplier resilience, redundancy and fallback options, continuous monitoring of dependencies, and clear communication protocols during incidents. Ultimately, the weakest link is often someone else’s system but the consequences are felt by everyone.”

ThreatSpike CEO, Adam Blake, said: “I’m deeply concerned but not surprised by the scale of the cyberattack on European airports. The cybersecurity industry has shown a colossal failure in protecting businesses where it matters. Businesses are pouring vast sums of money into advanced security tools and bolt-on solutions, but it’s just fragmenting security posture, creating overlapping controls and gaps for adversaries to exploit. 

“The cybersecurity model is clearly broken. Cybersecurity vendors have a responsibility to try a lot harder in educating businesses on where their gaps are, because it’s clear that they don’t know. There’s a global obsession with adopting a checklist of tools and that’s just not a viable solution. Cybersecurity needs to be treated a lot more holistically, as a strategic priority built on end-to-end visibility, consistent monitoring and response, and proactive threat detection. Where organisations stitch together a patchwork of vendors, vulnerabilities will inevitably emerge.”

Cody Barrow, CEO, EclecticIQ, said: “The aviation sector has invested heavily in safety, but cybersecurity resilience hasn’t kept pace. Operators and regulators need to ensure that essential systems can continue to function even when vendors are compromised. That means building redundancy, running realistic contingency exercises, and ensuring threat intelligence flows quickly between partners. 

“We should expect incidents like this to become more frequent, and the sector must treat cyber-resilience with the same urgency as physical safety.”

Browse our latest issue

Intelligent CIO Europe

View Magazine Archive