
Aviation & transport
Shared third-party platforms are a single point of failure for whole airports.
Check-in and departure control, booking, baggage, and ground systems lean heavily on shared third-party platforms and their software dependencies. When one common component fails, the disruption is immediate and public across every operator that uses it.
The software underneath
- Check-in and departure-control systems
- Booking, baggage, and ground-handling software
- Shared common-use passenger platforms
- Crew, flight-planning, and maintenance systems
The Collins Aerospace MUSE attack
September 2025Ransomware hit Collins Aerospace's MUSE common-use check-in and boarding platform, forcing a return to manual processing at hubs including London Heathrow, Brussels, and Berlin. More than 100 flights were disrupted, and check-in and baggage systems were offline for days. The EU cybersecurity agency ENISA confirmed it as a ransomware incident.
One shared third-party platform became the single point of failure for multiple major airports at once.
NIS2
Transport operators are essential entities under NIS2, with supply-chain security obligations covering their suppliers and software.
Know your components
Resolve and inventory the dependencies underneath the platforms you run, so a shared component's risk is visible.
Catch vulnerable and malicious code
Match against advisories and flag malicious behaviour across the tree.
Gate risky builds
Hold releases that carry an unaddressed critical finding until there is a fix.
Have you used Verifi in aviation & transport?
We are building our library of real-world results. Tell us how your team runs Verifi and we will help you write it up, or request a case study for your sector.