A cyberattack affecting Manchester Airports Group (MAG) has exposed information belonging to approximately 8.7 million customers across three major UK airports.

 

 

The incident involves data associated with Manchester Airport, London Stansted Airport, and East Midlands Airport. Rather than disrupting flights or airport infrastructure, the attackers gained access to customer information collected through several digital services, including airport WiFi registrations.

Information connected to car parking, airport lounge, and Fast Track bookings was also compromised. The exposed records may contain email addresses, telephone numbers, postcodes, and vehicle registration numbers. MAG said the vast majority of affected customers had only their email addresses exposed. The company stressed that the compromised system did not contain bank or payment information.

MAG discovered the security incident on Tuesday and subsequently restricted access to affected systems. External cybersecurity specialists were brought in to assist with the investigation, while relevant authorities were notified. The company has not revealed how its systems were accessed or attributed the attack to a particular threat actor.

Airport operations have continued despite the breach. MAG said aviation security and passenger safety were unaffected, while existing customer bookings remain valid. However, the company temporarily disabled its online Manage My Bookings service as a precaution.

One notable aspect of the incident is the inclusion of airport WiFi information. This means the affected population is not necessarily limited to people who purchased parking, lounge access, or Fast Track services. Travelers who registered to use WiFi at the airports may also be among those whose information was accessed.

Although the exposed data does not include financial details, combining contact information with travel-related records could make subsequent scams more convincing. Someone possessing an email address, telephone number, vehicle registration, or information associated with an airport service could potentially construct phishing attempts that appear relevant to a passenger’s previous activity.

Affected customers have therefore been advised to treat unexpected communications carefully. MAG specifically warned about unsolicited emails, calls, and text messages and said it would not unexpectedly contact customers asking them to provide passwords, payment card numbers, or banking information.

The incident has also been reported to the UK’s Information Commissioner’s Office. Organizations covered by UK data protection rules are generally required to notify the regulator within 72 hours after becoming aware of a personal data breach when it is likely to pose a risk to individuals’ rights and freedoms.

Leave a Reply