Manchester Airports Group cyber incident exposes data of 8.7m customers

Manchester Airports Group (MAG) has confirmed that a cyber security incident affecting its three airports resulted in customer data relating to around 8.7m people being accessed.

image: Shutterstock

The incident affected Manchester, London Stansted and East Midlands airports, with information associated with car park, lounge and Fast Track bookings and airport Wi-Fi registrations obtained by an unauthorised third party. Airport systems supporting passenger and aircraft operations were not disrupted.

MAG said the compromised information included customers’ email addresses, phone numbers, vehicle registration numbers and postcodes. It said neither the group nor the affected system held customers’ bank or payment details.

MAG said it became aware of the incident after identifying suspicious activity and had “immediately contained the risk”. It is working with specialist cyber security advisers and relevant authorities, including the UK’s National Cyber Security Centre (NCSC).

“At no point has passenger safety or aviation security been compromised,” MAG said, adding that the incident had not resulted in operational disruption and that airport operations and customer parking services remained unaffected.

The NCSC confirmed that it was working with MAG in response to the incident. The breach comes amid a period of heightened cyber security concerns across UK businesses and critical infrastructure, following a series of high-profile attacks on major organisations.

While the incident did not affect airport operations, the scale of the data breach highlights the challenge of protecting the extensive customer and commercial information generated by increasingly digital airport services.

The majority of the affected data is understood to relate to Wi-Fi registrations, with additional information coming from services including parking, lounge and Fast Track bookings. MAG has warned customers to be particularly cautious about unsolicited emails, calls or text messages that could use the compromised information in phishing or other fraud attempts.

The Financial Times reported that MAG had not paid a ransom and that the company declined to comment on whether negotiations with those responsible were taking place.

Previous
Previous

CAA selects three projects to advance hydrogen aviation safety and infrastructure

Next
Next

UK start-up develops hydrogen-based synthetic fuel designed to replicate Jet A-1