Cyber attack on UK’s largest airport group exposes data of 8.7mn customers
Data relating to 8.7mn customers was accessed following a cyber attack last weekend on three major UK airports, in one of the biggest breaches in the country in recent years.
Manchester Airports Group on Thursday said customers’ email addresses, phone numbers, vehicle registrations and postcodes had been taken following WiFi sign-ups and car park bookings at Manchester, London Stansted and East Midlands airports. No bank or payment details were breached.
MAG, which last year served 66mn passengers, said it had “immediately contained the risk” after becoming aware of the hack on Tuesday. “At no point has passenger safety or aviation security been compromised,” it added.
The hack on the UK’s largest airport group follows several large-scale cyber attacks on UK companies, including Marks and Spencer, Jaguar Land Rover and the Co-op Group.
The vulnerability of key UK infrastructure was also highlighted by Sunday’s revelation that hackers thought to be affiliated with the Iranian regime had forced a small UK gas plant to go offline.
While the accessed customer information appeared restricted, the size of the MAG data breach involving 8.7mn customers is one of the biggest in recent years.
Rafe Pilling, director of threat intelligence at Sophos Counter Threat Unit, said attacks of the kind on MAG were “most often ransomware attacks, where cyber criminals exfiltrate data and make financial demands not to publish it”.
“At this point the responsible group is likely trying to negotiate with MAG and we would expect to see posting indicators of the data they have taken over coming days if a ransom is not paid,” he added.
Asked if negotiations were taking place, MAG told the FT that it had not paid a ransom and declined to comment further.
The National Cyber Security Centre said it was “working with Manchester Airports Group in response to a cyber incident”.
Richard Horne, head of the branch of signals intelligence agency GCHQ, warned last year that companies needed to do more to guard against cyber attacks.
In early 2023, retailer JD Sports said it had fallen victim to a cyber attack that exposed the data of 10mn customers.
Two years earlier, the Electoral Commission, the elections regulator, suffered a major cyber incident in which the data of 40mn voters was accessed.
In 2020, retailer Dixons Carphone, now known as Currys, was fined £500,000 by the Information Commissioner’s Office, the data watchdog, over a breach that compromised the personal data of more than 14mn consumers.
MAG said no operations were disrupted by the incident, adding: “Airport operations remain unaffected and customer parking services continue to operate normally.”