Manchester Airports Group announced that attackers breached its systems and stole data related to registrations for Wi‑Fi networks and bookings for car parks, lounges, and the Fast Track service. The group said payment data and airport operations were not affected, while the number of people impacted remains undisclosed.
Manchester Airports Group (MAG) confirmed that its systems had been breached, resulting in the extraction of data belonging to customers of Manchester, London Stansted, and East Midlands airports. The stolen data includes information related to travelers’ registration on Wi‑Fi networks, as well as bookings for car parks, lounges, and the Fast Track service.
The group said the exposed data may include email addresses, phone numbers, vehicle registration numbers, and postcodes. It confirmed, however, that the attackers did not access customers’ payment data, and that the incident did not affect airport operations or car park services, which continued to operate normally.
Containment Measures and Affected Services
After discovering the intrusion, MAG said it restricted access to the affected systems, engaged external experts, and notified law enforcement agencies. It also temporarily suspended the online Manage My Booking service as a precaution and directed travelers to use the telephone line to manage their bookings.
The group did not disclose the number of people affected, although local media reported that the data of up to 8.9 million travelers may have been exposed, citing private statements from MAG. BleepingComputer was unable to verify this figure, so it cannot currently be considered a confirmed total for the incident. No ransomware or data-extortion group had claimed responsibility for the attack by the time the report was published.
Why Does This Matter?
The significance of the incident stems from the nature of the affected data, even though the attackers did not access payment information. Combining email addresses, phone numbers, vehicle details, and postal locations with travel or booking details could give attackers enough material to craft fraudulent messages that appear related to a flight, car park, or airport service. The source does not establish that the data was used in this way, but this explains why MAG warned customers about suspicious communications.
The airport advises potentially affected travelers to be cautious with links received by email or text message and not to provide card or bank account information or passwords in response to any request. MAG says it will not ask for this data. It also urged customers to reject and report attempts to obtain personal or financial information to the relevant authorities and to follow the recommendations of the UK National Cyber Security Centre after data breaches.
What Remains Unclear?
The attackers’ identity, the volume of stolen data, and the number of affected customers remain undisclosed. The fact that airport operations were not affected does not eliminate the need to monitor the investigation, particularly because the online booking management service was temporarily suspended and the group’s final assessment of the scope of access to the systems and data has not yet been published.