The MUSE Breach: Stolen Credentials and a Three-Year Wait
In 2022, a Collins Aerospace employee’s device was infected with Redline, an infostealer malware. The attacker harvested credentials for an FTP server operated by ARINC. Those credentials were legacy defaults: username AIS customer, password muse insecure. The attackers waited three years. In September 2025, they used the same credentials to access the MUSE backend. They exfiltrated 1.5 million passenger records, 3,637 airline employee records, and more than 50 GB of network and application topology files.
The Ransomware Wave: Five Airports Go Dark
On September 19, 2025, Collins Aerospace reported a cyber-related disruption to aviation authorities. That same day, five major European airports (Berlin, Heathrow, and others) began experiencing check-in and baggage system outages. They switched to manual operations. Passengers faced delays and cancellations. The disruptions lasted until September 29. A variant of Heartbeat ransomware was deployed on Collins systems. Delhi airport, using an on-premise MUSE version, was not affected.
Supply Chain Attack on Critical Infrastructure
Attackers targeted Collins Aerospace, a trusted vendor, to reach multiple airports. The attack path: Redline infection, credential harvesting, FTP access, MUSE backend compromise, data exfiltration. A second phase deployed ransomware. The aviation sector is classified as critical infrastructure under US and EU regulations. RTX, the parent company, never notified authorities. The speaker calls this a supply chain attack where trust is exploited.
Geopolitical Timing: Russia, NATO, and the Attack
On September 9-10, 2025, Russia launched a drone attack on Ukraine. Twenty to twenty-five drones crossed into Poland. NATO launched Operation Eastern Century on September 12. On September 16, NATO contractor ARYx announced a new electromagnetic warfare command system. On September 19, the day of the ransomware attack, three Russian MiG-31 fighter jets entered Estonian airspace. The Sun newspaper drew correlations during the attack, but no other outlet confirmed afterward. The speaker presents the timeline as facts, not conclusions.
Notable Quotes
username was AIS customer and the password was muse insecure. Konstantinos Fouzas · ▶ Watch (14:45)
RTX never tried to notify the authorities for that incident. Konstantinos Fouzas · ▶ Watch (17:01)
Everest is considered a Russian-speaking cybercriminal organization Konstantinos Fouzas · ▶ Watch (18:33)
three Russian MiG-31 fighter jets entered the Estonian airspace. Konstantinos Fouzas · ▶ Watch (30:48)
the conclusions, as always, should be yours. Konstantinos Fouzas · ▶ Watch (34:08)
Key Takeaways
- A 2022 Redline infection enabled the 2025 MUSE breach through reused default credentials.
- Five European airports were disrupted for ten days by Heartbeat ransomware.
- Supply chain attacks on critical infrastructure can coincide with geopolitical military operations.
About the Speaker(s)
Konstantinos Fouzas Last year’s bio was a massive hit, so … I’ll change it for no reason! Let’s see what this fella has to offer… Konstantinos is a guy who made the jump from the army to - let’s just say – a less stressful life. Eleven years in the Hellenic Armed Forces, with a general specialization in IT and the latest years in cybersecurity, gave him the ticket to his current occupation in Performance Technologies S.A., as a Senior Security Engineer. Offensively oriented, he deals with penetration tests and security assessments both in IT and OT environments, while simultaneously consulting them on security topics. Moreover, he loves sharing knowledge, so he also teaches cybersecurity courses in New York College. Finally, he tries to get his PhD in Cyberwarfare (not so succesfuly until now!).