Cyber Incident at Manchester Airports Group Affects 8.7 Million Customers

Manchester Airports Group (MAG), the operator of Manchester, London Stansted and East Midlands airports, has revealed that it was hit by a cyber security incident in which the data of about 8.7 million customers was accessed. The company said criminal hackers obtained customer contact details, vehicle registrations and postcodes over the weekend, though it stressed that passenger safety and aviation security were never compromised.

MAG said it became aware of the incident on Tuesday, August 25, and quickly moved to contain the breach and stop further unauthorised access. In a statement, the group said it had informed and was working with the relevant authorities. A spokesperson for MAG said: "We immediately contained the risk and have been working with specialist advisors and taking appropriate steps to protect our customers and systems."

The data accessed came from a system that did not hold customers' bank or payment details, according to the company. It is understood that the majority of the data was restricted to email addresses related to WiFi sign-ups in the airport terminals. More detailed information, including vehicle registrations, came from customers booking car-park spaces, arranging access to lounges, and booking fast-track services.

The affected airports are Manchester Airport, London Stansted and East Midlands Airport. MAG said airport operations remained unaffected by the incident and that customer parking services continued to operate normally.

Customer Notification and Advice

MAG has been emailing affected customers to inform them about the breach. The email, sent to customers, said: "Our investigation has identified that some of your personal information relating to airport car parking, lounge, Fast Track bookings and on-airport WIFI sign-ups has been accessed by an unauthorised third party. Neither MAG nor the system accessed hold customers' bank or payment details."

The email went on to reassure customers that MAG takes the security of customer information "extremely seriously" and said there was no action they needed to take. It urged customers to be "particularly cautious of unexpected emails, calls or text messages claiming to be from us," adding that MAG would never contact customers unexpectedly to ask for payment or banking information.

London Stansted Airport also emailed customers with similar advice, encouraging caution about unsolicited communications. MAG has urged customers to remain vigilant about suspicious emails, text messages or phone calls and to avoid opening attachments from unknown contacts.

The company apologised for any inconvenience or concern caused. MAG said it knew the identity of the hackers and had informed the relevant authorities.

Response and Investigation

MAG said it had been working with specialist cyber security advisors since discovering the breach. The company described the incident as a "cyber security incident by an unauthorised third party" and said it had taken immediate action to secure the affected system.

The company's statement emphasised that at no point had passenger safety or aviation security been compromised, and that the incident had not resulted in any operational disruption. The group said it would continue to work with authorities as part of its response to the incident.