Cybercrooks jet off with Manchester Airports Group customer data
Manchester Airport Group (MAG), the UK-based operator of Manchester, Stansted, and East Midlands airports, has confirmed a cybersecurity incident in which an extortion group stole data belonging to approximately 8.7 million customers. The attack, which did not involve ransomware, is part of an ongoing investigation by MAG and relevant authorities.
In a statement, MAG disclosed that the vast majority of affected individuals—around 8.7 million—had only their email addresses compromised. These were primarily collected when customers signed up for the airports’ public Wi-Fi services. A smaller portion of the breached data came from customers who had made speculative inquiries, such as entering details while booking car parking or Fast Track services but not completing the transaction. A minority of the compromised data involved completed bookings.
The Information Commissioner’s Office (ICO) advised MAG not to disclose specific details about the ransom note or the extortion group’s identity, likely to prevent giving the attackers undesired publicity. While MAG did not pay the extortion demands, it noted that the group’s demands in this case were lower than what they typically seek. MAG emphasized that passenger safety and aviation security were never compromised during the incident.
The attackers breached one of MAG’s systems and then stole files from a database hosted by a third party. The company described the attack as a sophisticated hack, not the result of human error or negligence. Despite the breach, none of MAG’s airports experienced operational disruption, and the affected system did not store bank or payment details.
As a precaution, MAG temporarily suspended access to its Manage My Booking service. Customers who need to amend or cancel a booking within 72 hours of the announcement were advised to contact customer services directly. Affected customers have already been notified, including some who contacted The Register to share details of the incident.
MAG reassured customers that it takes data security seriously and apologized for any inconvenience caused. While the investigation continues, customers are urged to remain vigilant against potential phishing attempts. MAG also confirmed that visiting its airports remains safe despite the cyberattack.
The incident has drawn attention from customers, including one who expressed frustration over being charged £80 for parking at Stansted while also being informed of the data breach.
#Cybersecurity #DataBreach #ManchesterAirportGroup #AirportSecurity #CyberAttack #CustomerData #PhishingAwareness
Comments (0)
No comments yet — be the first to weigh in.
Related Coverage
Technology
Wireless Fat Tire Brakes: ESP32‑Powered ABS and Remote Control Demo
Tested on a fat‑tire bike, the ESP32‑controlled wireless brakes add ABS, remote‑control, and a braking‑equalizer, showing the future of electronic mountain‑bike braking.
Technology
Wikipedia on a Cheap Yellow Display
A hobbyist has adapted the Cheap Yellow Display (CYD), a budget-friendly microcontroller board, to serve as an offline Wikipedia reader by running a customized...
Technology
Compact PCB Vise Uses Up That Leftover Filament
A 3D-printed PCB vise created by a maker known online as Chefkoch offers enthusiasts a practical way to repurpose leftover filament spools while gaining a usefu...
Technology
Apple Health App Revamp with AI Coach Set for September 2024 Release
Apple’s upcoming Health app overhaul, dubbed Project Mulberry, will add an AI health coach, blood‑sugar tracking and camera‑based workout guidance—likely launching in September 2024.
Most Read
Autumn Hill Sentenced to 50 Years in Prison for Anti-ICE Protest: A Case of Political Persecution?
Hull City Secure 1-0 Away Win at Coventry, Maintain Perfect Premier League Start
DSM-6 to Integrate Biology in Mental Health Diagnosis for First Time
Russian Drone Strike on Kiev Ammo Depot Kills 37, Sparks Evacuations