Cyber-attack exposes data of 8.7 million MAG customers

← Back to the feed

Cyber-attack exposes data of 8.7 million MAG customers

Developing story first seen 2 hours ago

The Guardian · 2 hours ago

New reporting confirms that hackers accessed the personal data of about 8.7 million customers of Manchester Airports Group (MAG), which operates Manchester, London Stansted and East Midlands airports. MAG says the breach did not affect airport operations, passenger safety or aviation security, but the exposed information could increase customers’ risk of phishing or other scams.

The affected system covered car park, lounge and fast-track bookings and airport Wi-Fi sign-ups, exposing email addresses, telephone numbers, postcodes and vehicle registration numbers. MAG says no bank or payment details were stored on the system, that it contained the incident immediately, and that it has informed relevant authorities; parking services remain operational.

  • Hackers accessed data linked to 8.7 million airport customers.
  • Safety, security and airport operations were unaffected.
  • Customers are urged to watch for phishing attempts.

New here? Start with this

Manchester Airports Group, known as MAG, runs three major UK airports: Manchester, London Stansted and East Midlands. Alongside flights, it provides services such as airport parking, lounge access, fast-track security bookings and Wi-Fi registration.

A cyber-attack is an unauthorised attempt to access computer systems or information. Personal details such as email addresses, phone numbers, postcodes and vehicle registration numbers can be useful to criminals trying to make scam messages appear convincing.

Phishing is a type of fraud in which criminals send messages that seem to come from a trusted company, often to obtain passwords or other sensitive information. Airport operators hold customer data for many everyday travel services, so breaches can affect people even when airport flights, safety systems and payment details are not involved.

Both sides, in good faith

The strongest fair case each way — we don't pick a winner.

The case for

MAG’s response can be viewed as proportionate to the nature of the incident: it contained the breach, says operational and safety-critical systems were unaffected, and the compromised system held no bank or payment details. Supporters would argue that prompt containment, regulatory notification and clear advice about phishing risk are the practical priorities, particularly when parking and airport services must continue for travellers.

The case against

Critics would argue that the scale of the exposure makes this a serious failure of data stewardship, even without payment information. Email addresses, phone numbers, postcodes and vehicle registrations can help criminals craft convincing scams or link records across datasets, so customers may face lasting risks. They would say MAG should provide fuller transparency about how access was gained, how long data was exposed, and what concrete support and security improvements it will offer affected people.

More coverage

Business Companies Cybersecurity Software Technology UK World

Read the full article at the source →

Originally published by The Guardian as “UK airports operator hit by cyber-attack and customer data accessed”.