Manchester Airports Group has admitted that hackers accessed data from 8.7mn customers after a cyberattack on three UK airports.
According to the Financial Times, the outfit said email addresses, phone numbers, vehicle registrations and postcodes were taken from WiFi sign-ups and car park bookings.
The breach hit Manchester, London Stansted and East Midlands airports, making it one of the largest UK data spills in recent years. No bank or payment details were breached, which is something, although not much comfort if your details are now doing the rounds. MAG, which served 66mn passengers last year, said it had “immediately contained the risk” after spotting the hack on Tuesday.
“At no point has passenger safety or aviation security been compromised,” it added.
The attack on the UK’s largest airport group follows cyber hits on Marks and Spencer, Jaguar Land Rover and the Co-op. The shakiness of key UK infrastructure was highlighted again on Sunday, when suspected Iranian-linked hackers forced a small UK gas plant offline.
The customer data taken from MAG looks limited, but 8.7mn people is still a chunky haul. Sophos Counter Threat Unit director of threat intelligence Rafe Pilling said attacks on outfits like MAG were “most often ransomware attacks, where cyber criminals exfiltrate data and make financial demands not to publish it”.
“At this point the responsible group is likely trying to negotiate with MAG, and we would expect to see posting indicators of the data they have taken over coming days if a ransom is not paid,” he added.
Asked whether talks were happening, MAG told the FT that it had not paid a ransom and declined to say more.
The National Cyber Security Centre said it was “working with Manchester Airports Group in response to a cyber incident”.
GCHQ branch National Cyber Security Centre boss Richard Horne warned last year that companies needed to do more to defend themselves against cyber attacks.
In early 2023, retailer JD Sports said attackers had exposed data belonging to 10mn customers.
Two years earlier, the Electoral Commission, which oversees elections, suffered a major cyber incident that exposed data on 40mn voters. In 2020, retailer Dixons Carphone, now Currys, was fined £500,000 (€583,000) by the Information Commissioner’s Office.
The fine followed a breach that compromised personal data from more than 14mn customers. MAG said its operations were not disrupted by the incident, which at least spared passengers another layer of airport misery.
“Airport operations remain unaffected, and customer parking services continue to operate normally.”







