Manchester Airports Group (MAG) has suffered a major cyberattack in which data belonging to around 8.7 million customers was reportedly accessed, raising concerns about how the stolen information could now be exploited by cybercriminals.
The incident affected customer information associated with Manchester Airport, London Stansted and East Midlands Airport. Data connected to car park, lounge and Fast Track bookings, as well as airport Wi-Fi registrations, was reportedly accessed.
Email addresses, phone numbers, postcodes and vehicle registration details are among the information affected. However, payment information was not compromised, while airport operations, passenger safety and aviation security were unaffected.
While this limits the immediate operational impact, security experts warn that the combination of information exposed could prove particularly useful for targeted phishing, impersonation and social engineering.
Stolen data could make scams much harder to spot
Simon Pamplin, CTO at Certes, said the fact that operations were unaffected should not distract from the significance of the data exposure.
“Around 8.7 million customer records have reportedly been accessed, including email addresses, phone numbers, postcodes and vehicle registration details. Individually these may appear relatively innocuous, but together they create a detailed dataset that can be extremely useful for targeted phishing, impersonation and social engineering.”
The context surrounding the information could make it especially valuable. Criminals could potentially create fraudulent parking notices, travel communications or airport-related messages containing enough genuine information to appear legitimate.
Muhammad Yahya Patel, vCISO and cybersecurity advisor for EMEA at Huntress, described the combination of information as a “precise targeting profile” for criminals.
“Scammers now know you travelled, roughly when, and have two direct contact routes to reach you with a convincing story,” he said.
Carole Reeves, Director of Security Operations at ANS, agreed that the absence of payment information should not lead customers to underestimate the risk.
“Attackers do not always need financial credentials from the initial breach. They can use the information they have to impersonate a trusted organisation and manipulate someone into revealing further personal or financial details.”
Aviation sector faces growing cyber pressure
Graeme Stewart, Head of Public Sector at Check Point Software, said the incident should serve as a warning to the wider aviation industry.
“The absence of cancelled flights or queues at terminals does not make this a small cyber attack. The data reportedly taken can now be weaponised,” he said.
Knowledge of a customer’s relationship with an airport could potentially be used to create fake parking refunds, Fast Track problems or communications about the breach itself.
“Aviation needs to behave as though a sustained campaign has begun, because waiting for an attack that stops planes moving before treating this as serious would be a dangerous mistake,” Stewart added.
Complex airport ecosystems create additional risks
The attack also raises questions about the complex technology ecosystems supporting modern airports.
Nathan Davies-Webb, Principal Consultant at Acumen Cyber, said airport groups sit at the centre of numerous booking, parking, loyalty, payment and internet connectivity services, many of which can be operated by subsidiaries or third-party suppliers.
“That’s a sensible commercial model but it creates an uncomfortable reality for security. A breach like this one in a shared upstream system can expose customer data from multiple services at multiple airports simultaneously.”
Davies-Webb also highlighted the speed of MAG’s response, with public disclosure roughly 48 hours after it became aware of the incident.
“Either way, it’s a better disclosure posture than we’ve seen from organisations involved in some comparable incidents, and MAG will probably benefit from having been quick and open here,” he said.
Tim Williams, CEO at Quod Orbis, also pointed to the importance of visibility beyond an organisation’s core systems.
“While the systems targeted were car parking, lounge bookings and WiFi sign-ups, they were not responsible for flight operations; they formed part of the wider digital environment through which customers interact within the airport,” Williams said.
He argued that security teams need visibility across systems, applications and third-party services so that risks can be identified before they become incidents.
“Rapid response can contain an incident, but having visibility across the wider technology and third-party ecosystem can help organisations identify potential weaknesses earlier, understand their exposure and strengthen their defences before an incident occurs.”
Knowing what data was accessed matters
The breach also highlights the importance of understanding exactly what information has been exposed once an attacker gains access.
Jerry Caviston, CEO at Archive360, said good data governance can provide organisations with the traceability needed during an incident.
“Having good data governance is like having CCTV footage of what data was touched and when,” he said.
Maintaining an event audit history can help organisations trace compromised information back to its original source and provide affected customers with clearer information about the risks they face.
Pamplin argues organisations should go further by attaching security directly to the data.
“We have to work on the assumption that systems will eventually be accessed. The objective should be that when this happens, sensitive data remains encrypted and unusable outside its authorised context,” he said.
“If an attacker can steal information but cannot read or exploit it, the value of the breach changes fundamentally.”
Customers should prepare for follow-on attacks
The immediate concern for affected customers is what criminals could do with the information next.
Jamie Akhtar, CEO and Co-Founder of CyberSmart, advised customers to be particularly cautious of unexpected emails, calls or texts claiming to relate to airport or travel services.
“Avoid clicking links or sharing personal information in unsolicited messages and, where possible, verify communications independently through an organisation’s official website or app,” he said.
Shankar Haridas, UK Business Head at ManageEngine, warned that the original breach could be followed by attacks designed to exploit customers’ trust in MAG.
“A breach like this doesn’t end when the data is taken. A flood of cloaked attacks, dressed up in the airport’s name is next,” he said.
“With 8.7 million email addresses, phone numbers and postcodes now in criminal hands, every ‘confirm your booking’ or ‘update your car park payment’ message must be questioned.”
Brian Higgins, Security Specialist at Comparitech, added that AI is making it easier for criminals to aggregate breached information and find new ways of monetising it.
“As AI makes data aggregation swift and easy, consumers are waking up to the fact that criminals can monetise successful breaches in increasingly inventive ways,” he said.
For those potentially affected, the consequences of the MAG cyberattack may therefore continue long after the initial incident has been contained. Emails or messages referencing airport parking, lounge access, Fast Track services or travel details could contain genuine personal information, making the next wave of scams considerably harder to recognise.

