Manchester Airports Group has suffered a major cyber attack in which data relating to around 8.7m customers has been accessed.
The group, which operates Manchester Airport, London Stansted and East Midlands Airport, said it became aware of the incident on Tuesday 25 August. The breach is believed to have occurred several days ago.
The affected information relates to car park, lounge and Fast Track bookings as well as in-airport WiFi sign-ups. Data accessed includes customers' email addresses, phone numbers, vehicle registrations and postcodes.
MAG said that neither it nor the affected system held customers’ bank or payment details. It also stressed that aviation security and airport operations had not been affected.
In a statement, Manchester Airports Group stated: "Manchester Airports group has been subject to a cyber security incident by an unauthorised third party. A quantity of customer data has been obtained that relates to car park, lounge and Fast Track bookings and in-airport WIFI sign-ups at Manchester, Stansted, and East Midlands airports. We immediately contained the risk and have been working with specialist advisors and taking appropriate steps to protect our customers and systems. We have informed and are working with the relevant authorities. At no point has passenger safety or aviation security been compromised.
"The incident has not resulted in any operational disruption. Airport operations remain unaffected and customer parking services continue to operate normally. Neither MAG nor the system accessed hold customers’ bank or payment details. The data that has been accessed includes customers’ email addresses, phone numbers, vehicle registrations and postcodes."
MAG said all upcoming bookings remained valid, although access to its online Manage My Booking service has been temporarily suspended.
The group added that it had restricted access to affected systems, engaged specialist cyber security experts and notified the relevant authorities. Affected customers are also understood to have been contacted directly.
Commenting on the incident, Daniel Wilcock, threat intelligence analyst at Talion Cyber Security, said: “This is a very significant breach that has impacted millions of people. Airports are widely regarded as critical national infrastructure and they are a prime target for threat actors and state-sponsored criminals."
Wilcock warned that scammers may use the event to launch further attacks: "This could be fake updates around the breach where customers are encouraged to click on links or divulge further information. Anyone impacted must be on guard for these types of attacks.”
MAG urged affected customers to remain vigilant for suspicious emails, texts and calls and warned that it will never unexpectedly request payment card details, banking information or passwords.
Printed Copy:
Would you also like to receive CIR Magazine in print?
Data Use:
We will also send you our free daily email newsletters and other relevant communications, which you can opt out of at any time. Thank you.









YOU MIGHT ALSO LIKE