The Collins Aerospace cybersecurity lawsuit landscape, as of early 2026, is defined more by criminal investigations, regulatory inquiries, and a parent-company securities disclosure than by any civil complaint on a public docket. A September 2025 ransomware attack on the company’s MUSE passenger-processing software shut down automated check-in at several major European airports, prompted arrests in the United Kingdom, drew coordinated inquiries from authorities in Belgium, Germany, and the UK, and forced RTX Corporation to file a Form 8-K with the Securities and Exchange Commission. It also arrived during a period when the U.S. Department of Justice has been aggressively using the False Claims Act to pursue defense contractors, including RTX’s own Raytheon subsidiary, for cybersecurity failures.1Research file
What Happened to Collins Aerospace
Collins Aerospace, a subsidiary of RTX Corporation, operates the Multi-User System Environment, or MUSE, a passenger processing platform that handles electronic check-in, boarding pass and bag tag printing, and baggage dispatch for airlines and airports worldwide. The systems run on customer-specific airport networks rather than on RTX’s own enterprise infrastructure.
Anomalous activity was detected on the MUSE platform on the evening of September 19, 2025. By the early hours of Saturday, September 20, ransomware had begun encrypting core databases, crippling automated check-in at London Heathrow, Brussels Airport, Berlin Airport, and Dublin Airport. Staff switched to manual boarding, and Brussels Airport alone reported ten flight cancellations and average hour-long delays across all departures.
Collins initially described the event as a “cyber-related disruption.” The European Union’s cybersecurity agency, ENISA, confirmed on September 22, 2025, that it was a ransomware attack.
How the Attackers Got In
Security researchers have described the breach as a dual-incident event. The Everest ransomware group gained unauthorized access to a Collins Aerospace FTP server on September 10, 2025, using legacy credentials compromised in a 2022 infostealer infection. Everest exfiltrated data over roughly 24 hours before being detected and blocked on September 11, then contacted RTX on September 15 through a vulnerability reporting portal to demand a ransom.
Everest did not deploy the ransomware itself. A separate, still-unidentified threat actor used the HardBit ransomware variant to encrypt the MUSE systems the following week. Cybersecurity researchers Kevin Beaumont and Dominic Alvieri identified the HardBit strain and noted that HardBit operates as an affiliate program, meaning any actor with access could have deployed it. Everest has publicly stated that its group “does not use or distribute ransomware,” characterizing its own role as data theft rather than system sabotage.
A report from Heise noted that Collins Aerospace’s description of the incident as purely a ransomware attack may be misleading, because the MUSE shutdown appears to have been a late-stage emergency measure taken to regain control after data had already been stolen, rather than a direct result of the encryption event.
What Data Was Stolen
Everest claims to have exfiltrated more than 50 gigabytes of data from MUSE and ARINC systems. According to the group’s dark-web leak site, the stolen material includes approximately 1.5 million passenger records containing frequent flyer details, travel data, seat numbers, and passenger identifiers, along with more than 3,600 airline employee records with names, usernames, emails, and login metadata. The material allegedly also includes system documentation covering network topology, device identifiers, and application configurations.
The Dublin Airport Authority confirmed that boarding pass information was compromised. Screenshots published by Everest showed German-language account names, suggesting employee and traveler data from the DACH region was also taken. As of late October 2025, Everest had not released actual data samples but had posted a countdown timer on its Tor-based leak site to pressure RTX into paying.
Criminal Investigations and Arrests
The UK’s National Crime Agency arrested a man in his forties in West Sussex on September 24, 2025, on suspicion of offenses under the Computer Misuse Act. The arrest was supported by the South East Regional Organised Crime Unit. The suspect was released on conditional bail, and the NCA described its investigation at that stage as being in its early stages.
Authorities in Belgium, Germany, and the United Kingdom have opened or coordinated inquiries into the incident. ENISA confirmed the ransomware cause but does not itself investigate incidents or impose penalties. In the United States, RTX notified both the Cybersecurity and Infrastructure Security Agency and the Federal Aviation Administration, though neither had issued public findings or enforcement actions as of late 2025.
RTX’s SEC Disclosure
RTX filed a Form 8-K with the SEC on September 19, 2025, the same day the anomalous activity was detected. The filing disclosed a “ransomware incident affecting its Multi-User System Environment (‘MUSE’) passenger processing software” and noted the affected systems operated outside RTX’s enterprise network on customer-specific networks.
RTX stated the incident “has not had a material impact and is not reasonably expected to have a material impact, on the Company’s financial condition, business operations or results of operations.” The filing acknowledged that potential future costs related to remediation, legal risks, and regulatory inquiries remained subject to the ongoing investigation. No specific dollar figures for remediation or customer compensation have been publicly disclosed.
Why No Civil Complaint Has Been Filed Publicly in Europe
European law places strict limits on disclosing investigative details related to critical-infrastructure operators. Under the NIS2 Directive and the General Data Protection Regulation, no official reports or sanctions related to the Collins Aerospace incident had been released as of early 2026. Passengers and employees whose data was exposed may eventually bring claims under GDPR provisions, but the regulatory pipeline has not produced public findings that private plaintiffs would typically build on.
Related Enforcement Against RTX and the Defense Industrial Base
The Collins Aerospace attack arrived in a period of sharply escalating legal consequences for defense contractors that fail to meet cybersecurity standards. The Department of Justice has been using the False Claims Act to treat cybersecurity noncompliance as fraud against the government, and RTX’s own corporate family has already been on the receiving end.
On April 4, 2025, the DOJ announced an $8.4 million settlement with Raytheon Company, RTX Corporation, and Nightwing Group LLC to resolve allegations that Raytheon’s cybersecurity subsidiary had failed to implement required security controls on internal development systems used for unclassified Department of Defense work. The case, brought as a whistleblower action by a former Raytheon director of engineering, alleged that noncompliant systems were used on 29 DoD contracts and subcontracts between 2015 and 2021, in violation of DFARS and FAR cybersecurity requirements. The whistleblower received $1.512 million from the settlement. No formal determination of liability was made.
In March 2026, defense subcontractor MORSECORP Inc. agreed to pay $4.6 million to settle False Claims Act allegations that it had failed to meet NIST SP 800-171 cybersecurity requirements from 2018 through 2023, used a noncompliant third-party email provider, and reported inaccurate compliance scores to the DoD.
Both settlements fall under the DOJ’s Civil Cyber-Fraud Initiative, which treats misrepresentation of a company’s security posture as potential grounds for treble damages and per-claim penalties that can reach $28,000. The December 2024 rollout of the Cybersecurity Maturity Model Certification program, which shifts the defense industrial base from self-attestation to independent third-party verification, is expected to generate additional enforcement. Under the CMMC rules that took effect November 10, 2025, certification is now a condition of contract award, and companies must maintain compliance scores in the DoD’s Supplier Performance Risk System.
For RTX, the two tracks converge. The Raytheon settlement addressed legacy cybersecurity failures on the government contracting side. The Collins Aerospace ransomware attack exposed vulnerabilities on the commercial aviation side. Together they show how a single defense conglomerate can face legal and operational risk across its portfolio when cybersecurity controls fall short.
Pending Legislation That Could Change the Rules
The attack has become a backdrop for new legislation. The United Kingdom’s Cyber Security and Resilience Bill, which would update the Network and Information Systems Regulations 2018, had its Second Reading in the House of Commons on January 6, 2026. The bill would empower authorities to designate “critical suppliers” to essential services, and parliamentary debate specifically cited air traffic control as the kind of single-point-of-failure the legislation aims to address. Collins Aerospace was not named in the debate, but the bill’s supply-chain provisions appear tailored to the type of third-party software dependency that made the MUSE attack so disruptive.
In the United States, mandatory incident reporting requirements under the Cyber Incident Reporting for Critical Infrastructure Act, known as CIRCIA, are not yet in force. Final rules have been delayed until spring 2026.