Cybercrooks jet off with Manchester Airports Group customer data
Manchester Airport Group (MAG), the UK-based operator of Manchester, Stansted, and East Midlands airports, has confirmed a cybersecurity incident in which an extortion group stole data belonging to approximately 8.7 million customers. The attack, which did not involve ransomware, is part of an ongoing investigation by MAG and relevant authorities.
In a statement, MAG disclosed that the vast majority of affected individuals—around 8.7 million—had only their email addresses compromised. These were primarily collected when customers signed up for the airports’ public Wi-Fi services. A smaller portion of the breached data came from customers who had made speculative inquiries, such as entering details while booking car parking or Fast Track services but not completing the transaction. A minority of the compromised data involved completed bookings.
The Information Commissioner’s Office (ICO) advised MAG not to disclose specific details about the ransom note or the extortion group’s identity, likely to prevent giving the attackers undesired publicity. While MAG did not pay the extortion demands, it noted that the group’s demands in this case were lower than what they typically seek. MAG emphasized that passenger safety and aviation security were never compromised during the incident.
The attackers breached one of MAG’s systems and then stole files from a database hosted by a third party. The company described the attack as a sophisticated hack, not the result of human error or negligence. Despite the breach, none of MAG’s airports experienced operational disruption, and the affected system did not store bank or payment details.
As a precaution, MAG temporarily suspended access to its Manage My Booking service. Customers who need to amend or cancel a booking within 72 hours of the announcement were advised to contact customer services directly. Affected customers have already been notified, including some who contacted The Register to share details of the incident.
MAG reassured customers that it takes data security seriously and apologized for any inconvenience caused. While the investigation continues, customers are urged to remain vigilant against potential phishing attempts. MAG also confirmed that visiting its airports remains safe despite the cyberattack.
The incident has drawn attention from customers, including one who expressed frustration over being charged £80 for parking at Stansted while also being informed of the data breach.
#Cybersecurity #DataBreach #ManchesterAirportGroup #AirportSecurity #CyberAttack #CustomerData #PhishingAwareness
Comments (0)
No comments yet — be the first to weigh in.
Energy biz SSE smacked around in court by a guy and AI
An Oxford doctoral student has defeated British energy provider SSE Energy Supply in court after utilizing artificial intelligence models to build his legal def...
Berkeley Humanoid Lite: Affordable Open-Source Robot with DIY Actuators
Explore the Berkeley Humanoid Lite, a budget-friendly open-source robot featuring 3D-printed actuators under $5,000 USD. Learn how its modular design benefits DIY projects.
Woodstove Safety Monitor: Oru System Alerts Users to Temperature Fluctuations
Discover how the Oru woodstove assistant helps prevent dangerous chimney fires by monitoring exhaust gas temperatures and alerting users to temperature changes.
NES CD Add-On Revives 1980s Gaming with Optical Storage
Explore how a DIY project integrates a CD drive with the NES using an RP2350B microcontroller and Everdrive N8 Pro for expanded storage and audio playback.
Mumbai’s Vile Parle Cypher is giving unheard rappers a voice
Enrich and Ultimo impress
Karnataka CM Signals Review of 5% Park Land Amendment Bill in Assembly