Manchester Airports Group hit by major cyber attack

Manchester Airports Group has suffered a major cyber attack in which data relating to around 8.7m customers has been accessed.

The group, which operates Manchester Airport, London Stansted and East Midlands Airport, said it became aware of the incident on Tuesday 25 August. The breach is believed to have occurred several days ago.

The affected information relates to car park, lounge and Fast Track bookings as well as in-airport WiFi sign-ups. Data accessed includes customers' email addresses, phone numbers, vehicle registrations and postcodes.

MAG said that neither it nor the affected system held customers’ bank or payment details. It also stressed that aviation security and airport operations had not been affected.

In a statement, Manchester Airports Group stated: "Manchester Airports group has been subject to a cyber security incident by an unauthorised third party. A quantity of customer data has been obtained that relates to car park, lounge and Fast Track bookings and in-airport WIFI sign-ups at Manchester, Stansted, and East Midlands airports. We immediately contained the risk and have been working with specialist advisors and taking appropriate steps to protect our customers and systems. We have informed and are working with the relevant authorities. At no point has passenger safety or aviation security been compromised.

"The incident has not resulted in any operational disruption. Airport operations remain unaffected and customer parking services continue to operate normally. Neither MAG nor the system accessed hold customers’ bank or payment details. The data that has been accessed includes customers’ email addresses, phone numbers, vehicle registrations and postcodes."

MAG said all upcoming bookings remained valid, although access to its online Manage My Booking service has been temporarily suspended.

The group added that it had restricted access to affected systems, engaged specialist cyber security experts and notified the relevant authorities. Affected customers are also understood to have been contacted directly.

Commenting on the incident, Daniel Wilcock, threat intelligence analyst at Talion Cyber Security, said: “This is a very significant breach that has impacted millions of people. Airports are widely regarded as critical national infrastructure and they are a prime target for threat actors and state-sponsored criminals."

Wilcock warned that scammers may use the event to launch further attacks: "This could be fake updates around the breach where customers are encouraged to click on links or divulge further information. Anyone impacted must be on guard for these types of attacks.”

MAG urged affected customers to remain vigilant for suspicious emails, texts and calls and warned that it will never unexpectedly request payment card details, banking information or passwords.



Share Story:

YOU MIGHT ALSO LIKE


Resilience Rooted in Reality
In this podcast, CIR speaks to CLDigital’s Tejas Katwala about why organisations must move beyond checklist compliance to build living, data driven resilience. He explains how rethinking governance, risk and compliance, breaking down silos and focusing on value streams can create sustainable, real time resilience that is rooted in the way businesses actually operate today.

Building cyber resilience in a complex threat landscape
Cyber threats are evolving faster than ever. This episode explores how organisations can strengthen defences, embed resilience, and navigate regulatory and human challenges in an increasingly complex digital environment.