-
-
by
News PRO

A woman uses a smartphone as travellers queue to check in at Heathrow Airport Terminal 4, following a disruption to check-in and boarding systems caused by a cyberattack which has affected several major European airports, resulting in flight delays and cancellations, in Greater London, Britain, September 20, 2025. REUTERS/Isabel… Purchase Licensing Rights , opens new tab Read more
LONDON, Sept 22 (Reuters) – Cybercriminals are taking greater risks by hitting high-profile targets to get bigger payoffs and boost their online reputational clout, cybersecurity experts said, after a weekend hack crippled airport check-in systems across Europe and stranded thousands of passengers.
The European Union’s cybersecurity agency ENISA confirmed on Monday that the hack on Collins Aerospace, owned by RTX (RTX.N) , opens new tab, was a ransomware attack, but did not say where the attack originated from. The outage, which hit check-in and baggage drop services, has affected dozens of flights since Friday.
“Broadly, the majority of ransomware activity is still geared towards extortion through data encryption and theft,” said Rafe Pilling, Director of Threat Intelligence at Sophos, a British cybersecurity firm.
“The subset of attacks deliberately engineered for maximum disruption, often by Western-based groups, are the outliers, but they are becoming more visible and more ambitious,” he added.
It was not clear which group was behind the hack. Ransomware gangs routinely publicise attacks and leak stolen data on dark web โleak sites,โ but websites that monitor those portals had not, as of Monday, detected any group claiming Collins Aerospace, or RTX, as a target.
Ransomware is malicious software used by cybercriminals to encrypt a companyโs data and demand payment for its release. They typically operate in the shadows, and many try to avoid targets which might earn them unwanted attention from law enforcement agencies.
Other groups, however, are becoming more brazen in the kind of targets they choose, cybersecurity experts said.
In April, a group of hackers dubbed Scattered Spider was widely reported to be behind an attack that crippled British retailer Marks & Spencer (MKS.L) , opens new tab, preventing one of the best-known names in British retailing from taking online orders for weeks.
Last Thursday, Britain’s National Crime Agency charged two teenagers over a 2024 cyberattack on London’s Transport for London, which it said caused “significant disruption and millions in losses”.
The NCA said investigators believed the TfL attack was carried out by members of Scattered Spider.
The FBI has said , opens new tab Scattered Spider was involved with approximately 120 network intrusions, and has earned around $115 million in ransom payments.
“Itโs clear from the number of recent cyberattacks and their impact that this is a problem that will grow, possibly rapidly, until software developers get much better at writing secure software and company IT staff get much better at evaluating the security of software their company choses to purchase or to use remotely,” said Martyn Thomas, Emeritus Professor of IT at Gresham College, London.
โWe have been lucky so far, as the motivation of cyber criminals has been disruption or financial gain,” Thomas said. “If they were to decide to cause serious injury or many deaths, the same attack strategies could be used on critical systems in healthcare or major infrastructure.”
One potential factor adding to the rise in higher profile and more criminally risky ransomware targets is the pursuit of reputation within criminal circles: The bigger the target, the more online clout cybercriminals have with other hackers.
“A small but determined set of largely Western-based cybercriminals are honing their skills and becoming emboldened by their past success and the success of others,” said Pilling at Sophos.
“Their motivation isn’t only financial though and pulling off a high-impact breach also brings social standing and credibility within their peer networks”.
Reporting by James Pearson in London. Editing by Jane Merriman
Our Standards: The Thomson Reuters Trust Principles. , opens new tab
Suggested Topics:
Reports on hacks, leaks and digital espionage in Europe. Ten years at Reuters with previous postings in Hanoi as Bureau Chief and Seoul as Korea Correspondent. Author of ‘North Korea Confidential’, a book about daily life in North Korea.
Read Next / Editor’s Picks
Site Index
About Reuters
Stay Informed
Information you can trust
Reuters, the news and media division of Thomson Reuters, is the worldโs largest multimedia news provider, reaching billions of people worldwide every day. Reuters provides business, financial, national and international news to professionals via desktop terminals, the world’s media organizations, industry events and directly to consumers.
Related
Discover more from The Who Dat Daily
Subscribe to get the latest posts sent to your email.


OUTLAW CHEMICAL FREE SOAPS AND NATURAL BODY PRODUCTS!




New Orleans Saints News
Saints News:Injury Report, Moore & Shough Presser + Cap Moves
Tulane College Sports
Tulane vs. South Alabama Preview: Green Wave Seek Week 2 Rebound
New Orleans Saints News
Saints Free $10.3M! Ruiz & Godchaux Restructures Explained | PODCAST
Sports News & More
Why Jared Goff Is Underrated and Dangerous
New Orleans Saints News
Saints Add 12 Players to Practice Squad as New Orleans Continues Roster Moves
New Orleans Saints News
Saints Looking for WR Help: Four Receivers Work Out Before Lions Opener
New Orleans Saints News
Saints Trade for Zamir White as RB Injuries Mount
New Orleans Pelicans News
Pelicans Sign Bennedict Mathurin to 2-Year, $16M Deal
