You are viewing 1 of your 2 free articles
Manchester Airports Group (MAG) has confirmed that around 8.7 million customers have been affected by a cyber security incident across its three UK airports.
An unauthorised third party obtained customer data relating to car park, lounge and Fast Track bookings, as well as in-airport Wi-Fi sign-ups across Manchester, Stansted and East Midlands airports.
A spokesperson for MAG noted that while the breach covers all three airports, it is restricted to email addresses in the vast majority of cases.
MAG stressed that neither the group nor the accessed system holds customers’ bank or payment details. However, other data accessed includes phone numbers, vehicle registrations and postcodes.
The airport operator emphasised that the breach has caused no operational disruption, aviation security has not been compromised, and all airport operations and parking services continue to run normally.
A MAG spokesperson said: “Manchester Airports Group has been subject to a cyber security incident by an unauthorised third party. A quantity of customer data has been obtained that relates to car park, lounge and Fast Track bookings and in-airport WIFI sign-ups at Manchester, Stansted and East Midlands airports.
“We immediately contained the risk and have been working with specialist advisors and taking appropriate steps to protect our customers and systems. We have informed and are working with the relevant authorities. At no point has passenger safety or aviation security been compromised.”
The airport operator apologised for any concern caused, adding that it takes data security “extremely seriously”.
Affected customers are being contacted directly by email and advised to remain vigilant against suspicious communications.
MAG reiterated that it will never contact customers unexpectedly to request payment card details, banking information or passwords.
As a precautionary measure, access to MAG’s online Manage My Booking portal has been temporarily suspended.
Which? consumer law expert Lisa Webb said: “Millions of people will understandably be concerned to learn that their personal information may have been accessed in this cyber-attack. While no bank or payment details were compromised, the information could still be valuable to fraudsters.
“Manchester Airport Group must ensure that everyone affected is given clear information about exactly what data has been compromised and what they can do to protect themselves.
"Customers should also be on their guard for unexpected emails, calls or messages, as scammers may try to exploit this breach. If you receive an unexpected message, don’t click on links or share personal information.”