UK Airport Group Data Breach Hits Pre-Holiday Travelers
MAG says customer data was stolen from its systems, warning of phishing risks ahead of peak travel.
As summer schedules reach their busiest point, the operator behind three of the UK's major airports has disclosed that an unauthorized party obtained customer data from its systems. Manchester Airports Group (MAG), which runs Manchester, London Stansted, and East Midlands airports, said it moved to contain the risk immediately after discovering the incident.
What Data Was Accessed
MAG stated that the accessed data included customers' email addresses, phone numbers, vehicle registration numbers, and postcodes. The company explicitly said that neither it nor the affected system held customers' bank or payment details. According to MAG, the data concerned car park bookings, lounge and Fast Track reservations, and in-airport Wi-Fi sign-ups.
The group said it has contacted affected customers directly, advising them to be alert for suspicious emails, text messages, and phone calls, and to avoid clicking links or opening unexpected attachments.
Breach During Peak Travel Period
Raghu Nandakumara, VP of industry strategy at Illumio, described the event as “a significant breach affecting a large number of customers ahead of one of the busiest travel periods of the year for UK airports.” He added that the exposed data could be used to make phishing and smishing attempts appear more convincing, given the travel-related context.
“For those affected, the exposed data increases the risk of targeted phishing and smishing attempts, where attackers can use legitimate travel-related information to make malicious communications appear convincing.”
— Raghu Nandakumara, VP of industry strategy at Illumio
Operations Unaffected
MAG emphasized that passenger safety and aviation security were not compromised, and that airport operations remained unaffected. The incident did not impact operational systems, and passengers have been told to continue traveling as normal.
The group said it had restricted access to affected systems, engaged specialist cybersecurity experts, and notified the relevant authorities. Its Data Protection team is overseeing the response.
Bookings Valid, Online Changes Suspended
MAG confirmed that all upcoming bookings remain valid and that customers do not need to take action regarding existing reservations. However, its online Manage My Booking service has been temporarily suspended as a precaution. Customers needing to amend bookings due within 72 hours have been directed to MAG's customer services team, which is open on weekdays between 9am and 5pm. The company warned that call wait times may be longer than expected.
Expert Advice on Mitigation
Commenting on the response, Nandakumara suggested that measures like segmentation could help restrict access to critical systems and sensitive data, reducing the risk that a single compromise becomes a wider incident. His remarks come as airports and travel operators increasingly face cyber threats that target customer data for follow-on attacks.
What This Means for Affected Customers
For those whose data was exposed, the immediate risk is an uptick in targeted phishing and smishing campaigns. Malicious actors often leverage legitimate-looking travel information—such as booking references or airport Wi-Fi sign-ups—to craft messages that appear genuine. Affected customers should be wary of unexpected communications referencing their travel plans, and should verify any requests for personal or financial information through official channels before responding.
This incident underscores the importance of robust access control and monitoring for systems that handle customer data, particularly at organizations that manage high volumes of personal information. While MAG has taken steps to contain the breach and notify victims, the full scale of the data exposure and its implications may not be known for some time. As the investigation continues, affected individuals are advised to monitor their accounts and remain vigilant for signs of misuse.
Sources
- Infosecurity Magazine Original source
Continue Reading
CRPx0's big claims and where they lead
CRPx0's victim count rose from under 10 to 48 organizations since June, but experts urge caution over unverified claims.
NemoClaw Flaw Opens Local AI Agents to Browser-Based Attacks
A single website visit can hijack NemoClaw's local Ollama model server via DNS rebinding, according to new research.
Tortoiseshell Expands Toolset With Backdoor, SSH Tunnel
Iran-linked Tortoiseshell adds reverse SSH tunneling and a C++ backdoor, with new infrastructure hinting at wider targeting.