Criminals publish data of 8.7m people after airports hack
Criminal hackers have published the personal data of nearly nine million people online after breaching Manchester Airports Group (MAG), which operates Manchester, London Stansted and East Midlands airports. The attackers had attempted to extort MAG, but the ransom was not paid, prompting them to release the stolen material for free on a website accessible via the ordinary internet rather than the dark web, making it unusually easy for other criminals and scammers to obtain. Affected customers are now being warned of possible follow-up scams and attacks using their data.
The leaked half-terabyte dataset includes contact details, vehicle registrations, postcodes, wi-fi login and car parking information, purchasing history and browsing device data, according to analysis by HaveIBeenPwned. Cyber-security expert Kevin Beaumont warned that the data reveals both past and planned future travel, meaning high-profile or wealthy individuals concerned about their movements being tracked may need to take precautions. MAG says it has contacted all those affected, including customers with upcoming bookings, and is working with authorities, though it maintains passenger safety at the airports themselves was not compromised. The hackers, whom the BBC is not naming, said they used the same method to breach MAG as other recent victims, exploiting weaknesses in how companies store digital network keys.
- Hackers leaked data of 8.7m people from three UK airports
- MAG refused/failed to pay ransom, so criminals published data free online
- Data includes contact details, vehicle details, travel history; scam risk high