Cyber Security News

Hackers Steal Data of 8.7 Million Customers in Cyberattack on Three UK Airports

Cybercriminals have stolen the personal data of about 8.7 million customers following a cyberattack on systems used by Manchester Airports Group (MAG), which operates Manchester Airport, East Midlands Airport and London Stansted Airport.

The airport operator said the incident involved unauthorized access to customer information, including email addresses, postcodes and vehicle registration details. The attackers also demanded a ransom for the stolen data, but MAG said it refused to pay.

MAG stated that passenger safety, airport operations and aviation security were not affected by the breach. The compromised system did not contain customer bank account details or payment-card information, according to the group.

Most of the exposed data reportedly came from passengers who registered for WiFi services in airport terminals. The stolen information primarily included email addresses associated with WiFi sign-ups.

Hackers Steal Data From Three UK Airports

Additional customer records were accessed through services linked to airport travel, including car-park reservations, lounge bookings and fast-track access. These records may have contained more detailed information, such as vehicle registration numbers and postcodes.

The airport operator said it identified the incident on Tuesday and acted quickly to stop further unauthorized access. MAG said it contained the breach, engaged specialist cybersecurity advisors and began notifying customers whose data may have been affected.

“We immediately contained the risk and have been working with specialist advisors and taking appropriate steps to protect our customers and systems,” MAG said in a statement.

The company said it had informed the relevant authorities and was cooperating with them, while MAG told the BBC that it knows the identity of the threat actors involved but did not publicly name the hacking group or disclose the ransom amount demanded.

The UK Information Commissioner’s Office confirmed that it had received a breach notification from Manchester Airports Group and was assessing the information supplied by the company.

The regulator may determine whether MAG met its data-protection obligations and whether further action is required. The incident highlights the risks associated with customer-facing digital services, especially WiFi portals, parking platforms, and online booking systems.

While the compromised records did not include payment data, attackers can use email addresses, names, postcodes, and vehicle information to build convincing phishing and social engineering campaigns.

Affected customers may receive fake airport notifications, fraudulent baggage or flight alerts, malicious parking-payment messages, or scam calls claiming to offer compensation.

The combination of travel-related information and contact details can make such attacks appear legitimate. MAG has urged customers to remain alert for suspicious emails, text messages and phone calls.

Users should avoid opening unexpected attachments, clicking links in unsolicited messages or sharing personal information with unverified callers. Customers should independently visit official airport websites rather than following links in breach-related messages.

They should also enable multi-factor authentication on email accounts, use unique passwords, and monitor inboxes for phishing attempts that impersonate Manchester Airport, East Midlands Airport, London Stansted Airport, or customer-support teams.

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC

Abinaya

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Recent Posts

100+ Tech and Security Organizations Call for Global Cyber Defense Surge Against AI Attacks

More than 100 technology, cybersecurity, and financial-services organizations have joined OpenAI in an open letter…

2 hours ago

Hackers Abuse Active Directory SPN Misconfigurations for Stealthy Kerberoasting Attacks

Threat actors are increasingly abusing overlooked Active Directory service principal name (SPN) misconfigurations to launch…

3 hours ago

Critical cPanel Vulnerability Allows Attackers to Take Full Server Control

A newly disclosed vulnerability in cPanel and WHM, the widely used web hosting control panel…

4 hours ago

PaperCut NG/MF Vulnerability Actively Exploited in Attack – All Versions Impacted

PaperCut has confirmed that hackers are actively exploiting an unpatched vulnerability in its widely used…

12 hours ago

Cybercriminals Are Selling Corporate Executives’ Social Security Numbers for Just 25 Cents

Corporate executives' most sensitive identity data is being sold on dark web marketplaces for as…

13 hours ago

CISA Warns of Citrix NetScaler ADC and Gateway Vulnerability Exploited in Attacks

The U.S. Cybersecurity and Infrastructure Security Agency has added a critical Citrix NetScaler ADC and…

13 hours ago