Manchester Airports Group data breach exposes 8.7 million customer records

Email addresses, phone numbers, and vehicle registrations stolen from car parking and Wi-Fi systems

edit
By LineZotpaper
Published
Updated
Read Time3 min
Sources2 outlets
Manchester Airports Group (MAG), the operator of three major UK airports, has disclosed a cyberattack that compromised the personal data of approximately 8.7 million customers, including email addresses, phone numbers, vehicle registration numbers, and postcodes. The breach affected data collected for car parking, lounge bookings, and public Wi-Fi services, though the company stated that no payment or passport information was stored on the compromised systems. MAG said it immediately contained the risk and has notified relevant authorities, while warning customers to remain vigilant against potential phishing attempts.

MAG, which runs Manchester Airport, London Stansted, and East Midlands Airport, confirmed the incident in a statement on Friday. The company, which recently celebrated a record 66 million passengers in a year, said it acted quickly to contain the breach and engaged external cybersecurity experts to assist with the investigation.

According to a spokesperson, the majority of affected customers—approximately 8.7 million—had only their email addresses compromised. However, some individuals also had their phone numbers, vehicle registrations, or postcodes stolen. The data was collected as part of the airports' car parking reservations, executive lounge bookings, fast-track security services, and public Wi-Fi sign-up processes.

MAG emphasised that at no point was passenger safety or aviation security compromised, and that none of its airports experienced operational disruption. As a precautionary measure, the group temporarily revoked access to its 'Manage My Booking' system. Customers needing to amend or cancel bookings within 72 hours were directed to contact customer services directly.

Affected customers have already been contacted by email. One reader of The Register criticised the handling, noting that receiving the breach notification after being charged £80 for five days of parking at Stansted 'added insult to injury'.

The company apologised for any inconvenience and reiterated that it takes the security of customer information 'extremely seriously'. It advised all customers to remain alert for unsolicited communications that might attempt to exploit the stolen data, though it stressed that visiting the airports remains safe.

The Register asked MAG for additional details on the nature of the attack, including whether ransomware was involved or which specific system was breached. A spokesperson declined to comment beyond the published statement.

Data breaches involving transport hubs are particularly concerning because the stolen information—such as vehicle registrations and email addresses—can be used in targeted phishing campaigns or for credential-stuffing attacks on other services. The Information Commissioner's Office (ICO) is likely to investigate whether MAG complied with data protection regulations under UK GDPR.

§

Analysis

Why This Matters

  • The breach exposes nearly 9 million UK travelers to potential phishing and identity fraud, especially those whose phone numbers and vehicle details were also taken.
  • Airports are critical infrastructure; this incident highlights vulnerabilities in ancillary systems (parking, Wi-Fi) that may not receive the same security focus as core aviation systems.
  • Given MAG's prominence and the scale of the breach, it could lead to significant regulatory fines under UK GDPR if the ICO finds negligence.

Background

MAG is one of the UK's largest airport operators, handling over 66 million passengers annually across its three airports. In recent years, the aviation industry has become a frequent target for cybercriminals, with notable breaches at airports including Heathrow (2018), Bristol (2020), and several European hubs. The MAG incident appears to be the largest UK airport data breach by victim count. The company had not disclosed any prior major cybersecurity incidents. The attack also comes amid a broader trend of ransomware and data-theft campaigns targeting travel and hospitality companies.

Key Perspectives

[MAG]: Stated it acted swiftly to contain the breach, notified authorities, and apologised to customers. It emphasised that safety and operations were unaffected and that no sensitive financial data was compromised. [Affected Customers]: Frustrated by the timing and inconvenience. Many rely on airports for travel and worry about increased spam and scam calls. The loss of vehicle registration data also raises concerns about physical tracking or vehicle-related fraud. [Security Experts]: Warn that email addresses and phone numbers are commonly used for phishing and social engineering. The combination with vehicle registrations could enable more convincing fake parking fine notices or toll charges. Experts urge MAG to provide identity protection services for affected individuals.

What to Watch

  • Whether a ransomware group or other threat actor claims responsibility and releases sample data to pressure MAG.
  • The ICO's investigation and any potential fine under UK GDPR, which can reach up to 4% of annual global turnover.
  • MAG's decision to offer credit monitoring or identity theft protection to the 8.7 million affected customers, and how quickly it restores the 'Manage My Booking' system.

Sources

newspaper

Zotpaper

Articles published under the Zotpaper byline are synthesized from multiple source publications by our AI editor and reviewed by our editorial process. Each story combines reporting from credible outlets to give readers a balanced, comprehensive view.