Cyber Attack Hits Manchester Airport Group as Data of 8.7 Million Customers Accessed
Manchester Airport and two other major UK airports have been hit by a cyber attack in which personal information belonging to around 8.7 million customers was accessed.
Manchester Airports Group (MAG), which operates Manchester Airport, London Stansted and East Midlands Airport, confirmed that an unauthorised third party had gained access to customer information held on its systems.
The incident affects information connected with airport car parking, lounge bookings, Fast Track services and airport Wi-Fi registrations. The data accessed is reported to include customers’ email addresses, telephone numbers, vehicle registration numbers and postcodes.
Importantly, MAG said that banking and payment information was not compromised. The company has also stressed that passenger safety, aviation security and normal airport operations have not been affected. Flights and airport services are continuing to operate normally.
Attack Quickly Contained
MAG said it detected the incident and immediately took steps to contain the risk. The company has brought in specialist cybersecurity advisers and is working with relevant authorities as investigations continue.
As a precaution, some online customer services, including the Manage My Booking facility, have been temporarily suspended.
Reports today have also indicated that the attackers demanded a ransom. MAG has not paid the ransom, according to reports, while investigations continue into who was responsible for the attack.
Customers Warned About Scams
Although the stolen information does not reportedly include payment details or passport information, security experts are warning that the exposed data could be valuable to criminals.
Information such as an email address, telephone number, vehicle registration and details of an airport booking could be used to make highly convincing phishing emails, text messages and telephone scams.
Criminals could, for example, pretend to be Manchester Airport and claim that a parking reservation needs to be updated, a refund is available or a payment needs to be made.
Customers are therefore being urged not to click links in unexpected emails or text messages, and to be particularly cautious of communications referring to recent airport bookings.
Manchester Airport Operations Unaffected
Despite the scale of the breach, there is currently no indication that flight operations, baggage handling, airport security or air traffic systems have been affected.
MAG has said that the attack was restricted to customer information systems rather than the operational technology responsible for running the airports.
The incident nevertheless highlights the growing cybersecurity risks facing major transport organisations. Airports hold large quantities of customer information and rely on increasingly complex IT systems for everything from parking and Wi-Fi to passenger services.
The investigation into the breach is continuing, with MAG working alongside cybersecurity specialists and relevant authorities to establish exactly how the attackers gained access and what information was taken.
For affected customers, the immediate priority is to remain alert for phishing emails, scam text messages and suspicious telephone calls that appear to originate from Manchester Airport or another MAG service.
The company has apologised to customers and said it is taking steps to protect affected individuals and strengthen its systems following the attack.

I am one of the editors here at www.systemtek.co.uk I am a UK based technology professional, with an interest in computer security and telecoms.
