
Aer Lingus Dublin Airport Cyberattack: Key Facts
If you were trying to fly out of Dublin Airport on the weekend of September 20, the scene was anything but business as usual. A cyberattack knocked out the electronic check-in and baggage systems in Terminal 2, forcing airlines like Aer Lingus — the most affected carrier — to handle passengers with pen and paper, according to reports from BBC News (UK public broadcaster).
Date of attack: 20 September 2025 ·
Affected terminal: Terminal 2 at Dublin Airport ·
Flights cancelled (midday Sunday): 13 (BBC News) ·
Systems impacted: Check-in and baggage handling ·
Most affected airline: Aer Lingus
Quick snapshot
- Cyberattack occurred on 20 September 2025 (BBC News)
- Terminal 2 check-in and baggage systems were affected (RTÉ News (Irish state broadcaster))
- 13 flights cancelled by midday Sunday (BBC News)
- Aer Lingus was the most affected carrier (Aviation Awards Ireland)
- Who is responsible for the attack — no group has claimed credit (The Irish Times (Irish daily newspaper))
- Whether passenger data was exfiltrated (The Irish Times (Irish daily newspaper))
- Full extent of data compromise (The Irish Times (Irish daily newspaper))
- 20 Sept: Attack starts; systems go offline (BBC News)
- 21 Sept: 13 cancellations; IT specialists en route (Aviation Awards Ireland)
- 22 Sept: Operations gradually resume; minimal impact reported (The Economic Times)
- Systems being restored; investigation ongoing (BBC News)
- Passengers advised to check flight status online (BBC News)
- Possible compensation claims under EU law (BBC News)
Six key facts summarise the event:
| Category | Details |
|---|---|
| Date of attack | 20–21 September 2025 |
| Location | Dublin Airport, Terminal 2 |
| Cause | Cyberattack on check-in and baggage system (Collins Aerospace Muse software, Aviation Awards Ireland) |
| Impact | 13 cancellations, severe delays, passenger frustration |
| Current status | Gradual recovery, systems partially restored as of 22 Sept (Economic Times) |
| Attribution | Unknown |
Is Dublin Airport affected by the cyber-attack?
Yes — the cyberattack hit Dublin Airport’s Terminal 2 check-in and baggage systems, causing immediate disruption. RTÉ News (Irish state broadcaster) reported that electronic customer check-in and baggage drop were affected, though manual operations could mitigate some impact. The airport initially described it as a “minor impact” but as the day progressed, cancellations mounted.
Which terminals were impacted?
- Terminal 2 — all check-in kiosks and baggage handling (BBC News)
- Terminal 1 operations were not disrupted
Staff reportedly resorted to handwritten bag tags and manual boarding passes, according to The Irish Times.
The implication: a single software failure paralyzed an entire terminal, revealing the fragility of centralized airport IT.
What systems were taken offline?
- Check-in kiosks (RTÉ News)
- Baggage drop systems (RTÉ News)
- Shared boarding system — Muse software from Collins Aerospace (Aviation Awards Ireland)
The outage affected all airlines using the shared platform, with Aer Lingus bearing the brunt because it operates most of its flights from Terminal 2.
Dublin Airport’s reliance on a single third-party system (Collins Aerospace) meant one breach disrupted multiple airlines simultaneously. Passengers expecting seamless digital check-in had to revert to analog processes — a stark reminder of how fragile airport IT infrastructure can be.
Why have Aer Lingus cancelled so many flights?
The cyberattack knocked out the check-in system, forcing manual processing. Aer Lingus said it would be “significantly affected” on Sunday, with delays and cancellations expected (BBC News). By midday Sunday, 13 flights were cancelled — nine inbound and four outbound (BBC News).
Direct impact of the cyberattack on operations
- Baggage handling slowed drastically — manual tag writing and boarding pass printing (The Irish Times)
- Check-in queues stretched for hours
- Unable to process passengers efficiently, Aer Lingus cancelled flights to manage backlog
Aer Lingus’s communication and passenger handling
- Aer Lingus urged passengers to check in online and said updates would follow (BBC News)
- Passengers reported poor real-time information from the airline
- A dedicated travel updates page was activated
This isn’t Aer Lingus’s first IT-related disruption. In 2022, a cloud network issue forced the cancellation of 51 flights from Dublin (Reuters via Investing.com). That incident, though not a cyberattack, shows the airline’s vulnerability when centralised systems fail.
The pattern: Aer Lingus has repeatedly been caught without robust fallback procedures when its core systems go dark.
Which airports are affected by the cyber-attack?
The attack primarily targeted Dublin Airport’s Terminal 2, but the incident was part of a broader wave affecting several European airports (BBC News). Cork Airport also reported impact on shared check-in systems (RTÉ News).
Airports outside Ireland also hit in the same wave
- Similar disruptions reported at some UK and European airports (same Muse software) (Aviation Awards Ireland)
- No other Irish airports were affected beyond Dublin and Cork
European airports and cyber resilience
According to The Irish Times, the attack highlights that airport cybersecurity remains a weak spot across Europe. Many hubs share third-party platforms, creating single points of failure.
The pattern: One supplier, multiple airports, widespread vulnerability.
What this means: a single exploited weakness in a shared vendor can cascade across borders, grounding flights from Dublin to the UK.
Who is behind cyber attacks on airports?
No group has claimed responsibility for the Dublin Airport attack (BBC News). Airports are high-value targets for ransomware groups and state-sponsored actors because a few hours of downtime costs millions.
Common threat actors and motivations
- Ransomware gangs seeking payouts
- State-sponsored groups aiming to disrupt travel or gather intelligence
- Hacktivists protesting airport policies
Lack of attribution in this specific case
Investigations are ongoing, but attribution often takes weeks or months. The Collins Aerospace system may have been exploited via a known vulnerability (Aviation Awards Ireland).
The lack of a clear culprit makes it harder to assess whether this was a targeted attack on Aer Lingus or collateral damage from a broader strike.
What is the latest update on the Aer Lingus Dublin Airport cyberattack?
As of 22 September 2025, operations are gradually resuming (Economic Times). The airport said it hoped for a full fix that day and manual processes remained in place. Aer Lingus continues to advise passengers to check flight status online.
Current status of flights and systems
- Check-in systems partially restored
- Baggage handling still running at reduced capacity
- IT specialists from the US arrived to support recovery (Aviation Awards Ireland)
Official statements from the airport and Aer Lingus
- Dublin Airport: “minimal impact” on Monday (Economic Times)
- Aer Lingus: “significantly affected” on Sunday (BBC News)
- Both advised passengers to confirm travel before heading to the airport
The catch: while the airport downplayed the impact, the 13 cancellations and hours-long queues tell a different story for stranded passengers.
Timeline of the Aer Lingus Dublin Airport cyberattack
- 20 September 2025 (Saturday): Cyberattack hits Dublin Airport Terminal 2; check-in and baggage systems go offline (BBC News)
- 20 September 2025 (evening): Aer Lingus cancels multiple flights; passengers stranded (BBC News)
- 21 September 2025 (Sunday): Disruption continues; 13 flights cancelled by midday; airport works on recovery (BBC News)
- 22 September 2025 (Monday): Operations gradually resume; official statements released; investigation ongoing (Economic Times)
What should passengers do if their flight is cancelled?
Under EU Regulation 261/2004, passengers whose flights are cancelled are entitled to care (meals, accommodation) and either rebooking or a refund. Aer Lingus has set up a dedicated support page for affected travelers (BBC News).
Rights under EU Regulation 261/2004
- Right to re-routing or full refund
- Right to care (meals, two phone calls, hotel if overnight)
- Right to compensation (€250-€600) depending on distance, unless extraordinary circumstances
Cyberattacks may be considered extraordinary circumstances, but a claim for care still stands. Passengers should keep all receipts and documentation.
How to rebook or claim compensation
- Use Aer Lingus website or app to rebook
- Contact customer service (be prepared for long wait times)
- Submit a claim via the airline’s compensation page
The 2-hour rule for tarmac delays applies only to US flights, not EU regulations.
For passengers stuck at the airport, check your travel insurance—some policies cover cyber-related disruptions. The airport authority says it’s reviewing cybersecurity protocols to prevent a repeat.
What we know vs. what remains unclear
Confirmed facts
- Cyberattack occurred on 20 September 2025 at Dublin Airport Terminal 2
- Check-in and baggage systems were knocked out
- 13 flights were cancelled by midday Sunday
- Aer Lingus was the most affected carrier
- Manual processes were used for check-in and boarding
What’s unclear
- Who is responsible for the attack
- Whether passenger data was exfiltrated
- When all systems will be fully restored
- Full extent of data compromise
Voices from the incident
“The incident caused only a ‘minor impact’ at first, with some airlines using manual check-in processes.”
— Dublin Airport spokesperson, via BBC News
“We will be significantly affected on Sunday, with delays and cancellations expected.”
— Aer Lingus statement, via BBC News
“The outcome was delays across the board, as well as cancellations.”
— The Irish Times
“This demonstrates how a single supplier failure can cascade across multiple airports.”
— Cybersecurity expert, quoted by Aviation Awards Ireland
The cyberattack exposed a fragile reliance on shared third-party IT systems at major European airports. For Aer Lingus passengers, the immediate cost was cancelled flights and lost time. The airport authority now faces a clear choice: invest in resilient backup systems and real-time passenger communication, or risk a repeat that erodes travel confidence even further.
Related reading: **What Is a DDoS Attack?** · **Air Canada Strike Flight Attendants**
ibtimes.co.uk, breached.company, instagram.com, youtube.com, travelextra.ie
Frequently asked questions
How long will the disruption last?
As of 22 September 2025, systems are gradually being restored. The airport hopes for a full fix soon but has not given a specific timeline (Economic Times).
Can I claim compensation for a cancelled flight?
Under EU Regulation 261/2004, you may be entitled to care and rebooking or a refund. Compensation (€250-€600) may apply unless the airline claims extraordinary circumstances, but you should file a claim regardless.
Is my personal data safe?
It is not yet confirmed whether passenger data was compromised. The Irish Times reports that data exfiltration is under investigation (The Irish Times).
What systems were affected?
Electronic check-in kiosks, baggage drop systems, and boarding systems that rely on Collins Aerospace’s Muse software (Aviation Awards Ireland).
Are other Irish airports affected?
Cork Airport experienced some impact, but no other Irish airports were reported affected (RTÉ News).
How can I get a refund or rebook?
Check your flight status on the Aer Lingus website. Use their online portal to rebook or request a refund. You can also call customer service (BBC News).
What is the cause of the cyberattack?
Investigations are ongoing. No group has claimed responsibility, and the exact method is unknown (BBC News).
Will there be more cancellations?
As systems come back online, further cancellations should be limited. Check the airline’s website for real-time updates.