Manchester Airports Group says no payment details taken and operations unaffected after hackers demand ransom.
A cyber attack on three major UK airports has exposed the personal data of approximately 8.7 million customers, the operator confirmed on Thursday, marking one of the largest data breaches in Britain in recent years.
Manchester Airports Group (MAG), which runs Manchester, London Stansted and East Midlands airports, said an unauthorised third party accessed customer information linked to in-airport Wi-Fi sign-ups as well as car park, lounge and fast-track bookings. The incident occurred over the weekend and was discovered on Tuesday.
The compromised data primarily consists of email addresses collected when passengers connected to free terminal Wi-Fi. A smaller portion includes phone numbers, vehicle registration numbers and postcodes associated with bookings. MAG stressed that the affected system did not hold bank or payment card details, and that “at no point has passenger safety or aviation security been compromised.” Airport operations continued without disruption.
Hackers Demand Ransom After UK Airport Data Breach:
Hackers demanded a ransom in exchange for the return and deletion of the stolen data. MAG refused to pay. The company has not disclosed the amount sought or publicly named the group responsible, though it has said it knows the attackers’ identity and is cooperating with relevant authorities and specialist cybersecurity advisers.
In a statement, MAG said: “A quantity of customer data has been obtained that relates to car park, lounge and Fast Track bookings and in-airport WIFI sign-ups at Manchester, Stansted and East Midlands airports. We immediately contained the risk and have been working with specialist advisors and taking appropriate steps to protect our customers and systems.”
The group, which handled around 66 million passengers last year across its three airports, has begun notifying affected customers. In emails, it urged people to remain vigilant against unexpected messages claiming to come from the airports, warning that MAG will never contact customers unsolicited to request payment or banking information.
UK Airports Cyberattack Exposes 8.7 Million Customer Records:
Security experts noted that the scale of the breach-even if much of the data is limited to email addresses-creates significant risk of phishing and social-engineering attacks. Criminals could craft convincing messages impersonating the airports or related travel services.
The incident comes amid a series of high-profile cyber attacks on British organisations in recent years, including retailers and manufacturers. Analysts say ransomware-style operations, in which data is stolen and a payment demanded to prevent its publication, remain a common tactic.
MAG said the vast majority of the 8.7 million affected records involve only email addresses. More detailed information was limited to customers who interacted with parking, lounge or fast-track services. Existing bookings remain valid and customer parking services are operating normally.
Authorities continue to investigate. Customers who used Wi-Fi or made bookings at the three airports have been advised to monitor their accounts carefully and treat any unexpected travel-related communications with caution.