Airport Chaos Highlights Rise in High-Profile Ransomware Attacks, Cyber Experts Say
A weekend hack crippled airport check-in systems across Europe, leaving thousands of passengers stranded and raising concerns about the increasing risk of high-profile ransomware attacks. The European Union's cybersecurity agency ENISA confirmed on Monday that the hack on Collins Aerospace, owned by RTX, was a ransomware attack.
Cybercriminals are taking greater risks by hitting high-profile targets to get bigger payoffs and boost their online reputational clout, cybersecurity experts said. The subset of attacks deliberately engineered for maximum disruption, often by Western-based groups, are becoming more visible and more ambitious.
"Broadly, the majority of ransomware activity is still geared towards extortion through data encryption and theft," said Rafe Pilling, Director of Threat Intelligence at Sophos, a British cybersecurity firm. "The subset of attacks deliberately engineered for maximum disruption, often by Western-based groups, are the outliers, but they are becoming more visible and more ambitious."
The hack on Collins Aerospace has affected dozens of flights since Friday, with passengers facing disruptions to check-in and baggage drop services.
Ransomware gangs routinely publicise attacks and leak stolen data on dark web “leak sites,” but websites that monitor those portals had not, as of Monday, detected any group claiming Collins Aerospace, or RTX, as a target. Ransomware is malicious software used by cybercriminals to encrypt a company's data and demand payment for its release.
Other groups, however, are becoming more brazen in the kind of targets they choose, cybersecurity experts said. In April, a group of hackers dubbed Scattered Spider was widely reported to be behind an attack that crippled British retailer Marks & Spencer, preventing one of the best-known names in British retailing from taking online orders for weeks.
Last Thursday, Britain's National Crime Agency charged two teenagers over a 2024 cyberattack on London's Transport for London, which it said caused "significant disruption and millions in losses". The NCA said investigators believed the TfL attack was carried out by members of Scattered Spider. The FBI has said Scattered Spider was involved with approximately 120 network intrusions, and has earned around $115 million in ransom payments.
"It's clear from the number of recent cyberattacks and their impact that this is a problem that will grow, possibly rapidly, until software developers get much better at writing secure software and company IT staff get much better at evaluating the security of software their company chooses to purchase or to use remotely," said Martyn Thomas, Emeritus Professor of IT at Gresham College, London. "We have been lucky so far, as the motivation of cyber criminals has been disruption or financial gain."
"If they were to decide to cause serious injury or many deaths, the same attack strategies could be used on critical systems in healthcare or major infrastructure," Thomas added.
Reputation and Online Clout
One potential factor adding to the rise in higher profile and more criminally risky ransomware targets is the pursuit of reputation within criminal circles: The bigger the target, the more online clout cybercriminals have with other hackers.
"A small but determined set of largely Western-based cybercriminals are honing their skills and becoming emboldened by their past success and the success of others," said Pilling at Sophos. "Their motivation isn't only financial though and pulling off a high-impact breach also brings social standing and credibility within their peer networks".
This new trend in high-profile ransomware attacks highlights the growing threat posed by cybercriminals, who are increasingly targeting high-risk organizations to boost their reputation and online clout. As cybersecurity experts warn, this is a problem that will only grow unless software developers and IT staff take steps to improve security measures.