{"id":42360,"date":"2025-09-25T09:12:09","date_gmt":"2025-09-25T09:12:09","guid":{"rendered":"https:\/\/www.newsbeep.com\/ie\/42360\/"},"modified":"2025-09-25T09:12:09","modified_gmt":"2025-09-25T09:12:09","slug":"how-a-cyberattack-brought-dublin-airport-to-a-standstill-the-irish-times","status":"publish","type":"post","link":"https:\/\/www.newsbeep.com\/ie\/42360\/","title":{"rendered":"How a cyberattack brought Dublin Airport to a standstill \u2013 The Irish Times"},"content":{"rendered":"<p class=\"c-paragraph paywall \">In May 1940, the Maginot Line failed. France\u2019s series of defences were bypassed by the Wehrmacht through the Ardennes. That France hadn\u2019t factored in Germany\u2019s ability to bypass their defensive system is often derided.<\/p>\n<p class=\"c-paragraph paywall \">The thing is, in a manner of speaking, they did plan for it. There were communication exchanges along the line in order to quickly relay information to the rest of the French forces.<\/p>\n<p class=\"c-paragraph paywall \">What the French army didn\u2019t plan, granted amongst many other things, was sabotage. The Wehrmacht sabotaged the telephone lines so that their panzers (tanks) were already through the line before any reaction could happen.<\/p>\n<p class=\"c-paragraph paywall b-it-article-body__text--left\">Fast forward to the weekend just gone and airports across Europe, but most notably Terminal 2 in <a href=\"https:\/\/www.irishtimes.com\/tags\/dublin-airport\/\" target=\"_self\" rel=\"nofollow noopener\" title=\"https:\/\/www.irishtimes.com\/tags\/dublin-airport\/\">Dublin Airport<\/a>, stalled because of an issue most travellers didn\u2019t think of from a supplier they hadn\u2019t heard of.<\/p>\n<p class=\"c-paragraph paywall b-it-article-body__text--left\">The Muse check-in system developed by Collins Aerospace was the overlooked weak point in this instance. Passengers were frustrated by airport operator <a href=\"https:\/\/www.irishtimes.com\/tags\/daa\/\" target=\"_self\" rel=\"nofollow noopener\" title=\"https:\/\/www.irishtimes.com\/tags\/daa\/\">DAA<\/a> and <a href=\"https:\/\/www.irishtimes.com\/tags\/aer-lingus\/\" target=\"_self\" rel=\"nofollow noopener\" title=\"https:\/\/www.irishtimes.com\/tags\/aer-lingus\/\">Aer Lingus<\/a> when most of their ire really belong with a company they hadn\u2019t heard of which is trusted far beyond these shores.<\/p>\n<p class=\"c-paragraph paywall b-it-article-body__text--left\">Collins, which is a subsidiary of RTX (formerly Raytheon), was hit by a <a href=\"https:\/\/www.irishtimes.com\/tags\/cybersecurity\/\" target=\"_self\" rel=\"nofollow noopener\" title=\"https:\/\/www.irishtimes.com\/tags\/cybersecurity\/\">ransomware attack<\/a>. This led to check-in systems either going offline fully or slowing to an unusable crawl. This forced airlines, most notably Aer Lingus as the largest operator in Terminal 2, to go back to basics.<\/p>\n<p class=\"c-paragraph paywall b-it-article-body__text--left\">Bag tags were hand written, boarding passes were printed manually and everything slowed down considerably. The result was delays across the board as well as cancellations. The invisible plumbing that keeps air travel going only comes to the fore when something goes wrong.<\/p>\n<p class=\"c-paragraph b-it-article-body__interstitial-link\">[\u00a0<a aria-label=\"Open related story\" class=\"c-link\" href=\"https:\/\/www.irishtimes.com\/world\/europe\/2025\/09\/20\/cyberattack-disrupts-operations-at-heathrow-and-other-european-airports\/\" rel=\"noreferrer nofollow noopener\" target=\"_blank\">Dublin Airport continuing to manage fallout from cyberattackOpens in new window<\/a>\u00a0]<\/p>\n<p><img decoding=\"async\" data-chromatic=\"ignore\" alt=\"Dublin Airport was one of several airports across Europe to be impacted by the cyber attack. Photograph: Stephen Collins\/ Collins Photos\" class=\"c-image\" loading=\"lazy\" src=\"https:\/\/www.newsbeep.com\/ie\/wp-content\/uploads\/2025\/09\/JSIYWMPYCD3OXV5MRVLYAREC44.jpg\"   width=\"800\" height=\"533\"\/>Dublin Airport was one of several airports across Europe to be impacted by the cyber attack. Photograph: Stephen Collins\/ Collins Photos <\/p>\n<p class=\"c-paragraph paywall \">These are also the most likely points for such an incident to occur. If Visa or Mastercard suffered a severe cyberattack, you\u2019d understand that making payments would become difficult. <\/p>\n<p class=\"c-paragraph paywall \">It\u2019s the same for Collins Aerospace and airport management, when they were hit then every airport using their services along with the passengers going through it felt the pinch.<\/p>\n<p class=\"c-paragraph paywall \">The only difference is that you\u2019ve heard of Visa and Mastercard and thought Collins was a dictionary company. More often than not, the point of failure comes in a company with the importance but lack of public profile of Collins.<\/p>\n<p class=\"c-paragraph paywall \">It\u2019s also a matter that is being addressed, albeit with a lot of heavy lifting, by the European Union. The NIS2 directive and, to a lesser degree in cases like these, the Cyber Resilience Act (CRA) are squarely aimed at ensuring the organisations you have heard of, like DAA, are using third party companies that meet clear thresholds for cyber resilience.<\/p>\n<p class=\"c-paragraph paywall \">It extends security expectation across the supply chain, removing the excuse of the big brand blaming a third party supplier for the error. That big name, the one ostensibly providing the service like DAA and Aer Lingus were, is expected to have ensured its third party suppliers are fit for purpose.<\/p>\n<p class=\"c-paragraph paywall b-it-article-body__text--left\">NIS2 was meant to have been signed into law by all EU governments by October 17th, 2024. Ireland, like quite a number of other member states including France and Germany, is still running behind on transposing it into national law.<\/p>\n<p class=\"c-paragraph paywall b-it-article-body__text--left\">Had NIS2 been in place on time, then any company or organisation using Collins Aerospace\u2019s products would have been required to check that these products met certain cyber hygiene requirements and that the contracts therein met certain ongoing cybersecurity standards.<\/p>\n<p class=\"c-paragraph paywall \">There\u2019s a reasonable chance DAA already did this, despite not being required to, as it and others impacted alerted the relevant authorities quickly about the issue. That wasn\u2019t particularly difficult given how visible the fallout was. It can also be assumed that Collins\u2019 product met the required cyber hygiene standards.<\/p>\n<p class=\"c-paragraph b-it-article-body__interstitial-link\">[\u00a0<a aria-label=\"Open related story\" class=\"c-link\" href=\"https:\/\/www.irishtimes.com\/business\/economy\/2024\/12\/01\/area-14-dublin-airports-ghost-underground-station\/\" rel=\"noreferrer nofollow noopener\" target=\"_blank\">Area 14: Dublin Airport\u2019s ghost underground stationOpens in new window<\/a>\u00a0]<\/p>\n<p class=\"c-paragraph paywall \">Where the likes of NIS2 and the CRA, which is also still in the processing stage, would have definitely made a difference is in fallback measures. The level expected is high and this past weekend\u2019s disruptions would likely have been far less in such an instance.<\/p>\n<p class=\"c-paragraph paywall \">That\u2019s because of the penalties at play when it comes to not meeting NIS2 requirements, which can go as high as \u20ac10 million or 2 per cent of global turnover in some cases. It\u2019s the type of stick that puts manners of organisations.<\/p>\n<p class=\"c-paragraph paywall \">The incident at the weekend was for air travel passengers but the world we live and work in today is heavily reliant on invisible companies. That\u2019s not a bad thing. An awful lot of the work these companies do is incredibly boring despite being vital to basic day to day activities.<\/p>\n<p class=\"c-paragraph paywall \">Improving oversight on important boring work is the only way to reduce future incidents like what happened in Dublin last weekend.<\/p>\n<p class=\"c-paragraph paywall \">The French likely would still have been in a world of bother without their phone lines being sabotaged but it\u2019s still dreadful that they didn\u2019t account for such an attack back in 1940.<\/p>\n<p class=\"c-paragraph paywall \">By 2025, we should know better than to allow core pieces of infrastructure to be so vulnerable to attack.<\/p>\n","protected":false},"excerpt":{"rendered":"In May 1940, the Maginot Line failed. France\u2019s series of defences were bypassed by the Wehrmacht through the&hellip;\n","protected":false},"author":2,"featured_media":42361,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5],"tags":[601,72,3312,10725,11900,61,60],"class_list":["post-42360","post","type-post","status-publish","format-standard","has-post-thumbnail","category-business","tag-aer-lingus","tag-business","tag-cybersecurity","tag-daa","tag-dublin-airport","tag-ie","tag-ireland"],"_links":{"self":[{"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/posts\/42360","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/comments?post=42360"}],"version-history":[{"count":0,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/posts\/42360\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/media\/42361"}],"wp:attachment":[{"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/media?parent=42360"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/categories?post=42360"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.newsbeep.com\/ie\/wp-json\/wp\/v2\/tags?post=42360"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}