Breaking
Cyber CrimeDeveloping Story

UK Airport Group Data Breach Hits Pre-Holiday Travelers

MAG says customer data was stolen from its systems, warning of phishing risks ahead of peak travel.

··2 hours ago·3 min read
a group of people standing around a terminal
Photo by Albert Stoynov on Unsplash

As summer schedules reach their busiest point, the operator behind three of the UK's major airports has disclosed that an unauthorized party obtained customer data from its systems. Manchester Airports Group (MAG), which runs Manchester, London Stansted, and East Midlands airports, said it moved to contain the risk immediately after discovering the incident.

What Data Was Accessed

MAG stated that the accessed data included customers' email addresses, phone numbers, vehicle registration numbers, and postcodes. The company explicitly said that neither it nor the affected system held customers' bank or payment details. According to MAG, the data concerned car park bookings, lounge and Fast Track reservations, and in-airport Wi-Fi sign-ups.

The group said it has contacted affected customers directly, advising them to be alert for suspicious emails, text messages, and phone calls, and to avoid clicking links or opening unexpected attachments.

Breach During Peak Travel Period

Raghu Nandakumara, VP of industry strategy at Illumio, described the event as “a significant breach affecting a large number of customers ahead of one of the busiest travel periods of the year for UK airports.” He added that the exposed data could be used to make phishing and smishing attempts appear more convincing, given the travel-related context.

“For those affected, the exposed data increases the risk of targeted phishing and smishing attempts, where attackers can use legitimate travel-related information to make malicious communications appear convincing.”

— Raghu Nandakumara, VP of industry strategy at Illumio

Operations Unaffected

MAG emphasized that passenger safety and aviation security were not compromised, and that airport operations remained unaffected. The incident did not impact operational systems, and passengers have been told to continue traveling as normal.

The group said it had restricted access to affected systems, engaged specialist cybersecurity experts, and notified the relevant authorities. Its Data Protection team is overseeing the response.

Bookings Valid, Online Changes Suspended

MAG confirmed that all upcoming bookings remain valid and that customers do not need to take action regarding existing reservations. However, its online Manage My Booking service has been temporarily suspended as a precaution. Customers needing to amend bookings due within 72 hours have been directed to MAG's customer services team, which is open on weekdays between 9am and 5pm. The company warned that call wait times may be longer than expected.

Expert Advice on Mitigation

Commenting on the response, Nandakumara suggested that measures like segmentation could help restrict access to critical systems and sensitive data, reducing the risk that a single compromise becomes a wider incident. His remarks come as airports and travel operators increasingly face cyber threats that target customer data for follow-on attacks.

What This Means for Affected Customers

For those whose data was exposed, the immediate risk is an uptick in targeted phishing and smishing campaigns. Malicious actors often leverage legitimate-looking travel information—such as booking references or airport Wi-Fi sign-ups—to craft messages that appear genuine. Affected customers should be wary of unexpected communications referencing their travel plans, and should verify any requests for personal or financial information through official channels before responding.

This incident underscores the importance of robust access control and monitoring for systems that handle customer data, particularly at organizations that manage high volumes of personal information. While MAG has taken steps to contain the breach and notify victims, the full scale of the data exposure and its implications may not be known for some time. As the investigation continues, affected individuals are advised to monitor their accounts and remain vigilant for signs of misuse.

#cyber incident#data breach#mag#airport security#phishing#smishing

Sources

Iliyas

Founder & Editor, Xploitwire

This article was compiled from the sources listed above and checked against them for accuracy, under editorial policies set by Iliyas. Read our Editorial Policy →

← Back to all stories