Around 8.7 million travellers who signed up for WiFi, car parking services and lounges in airports run by Manchester Airports Group (MAG) had their data stolen, including email addresses and phone numbers, postcodes and vehicle registration details. MAG operates airports in Manchester, London Stansted and East Midlands, and declined the demand to pay ransom.
Denis Calderone, CTO, Suzu Labs:
The 8.7 million number is attention-grabbing, but it deserves some context. MAG has confirmed that the vast majority of those records are email addresses collected through airport WiFi sign-ups. A much smaller subset includes phone numbers, vehicle registrations, and postcodes from customers who actually completed parking or lounge bookings. No payment data, no passwords, no passport information. So despite this affecting airports, which is obviously a sensitive subject, the actual data sensitivity for most affected individuals is relatively low.
What’s more interesting to us from a technical standpoint is the attack path. MAG told The Register that attackers compromised one of their internal systems and then went on to steal files from a database hosted by a third party. That’s a pivot upstream into a data provider, not downstream into operational systems. What remains unclear is whether the data was exfiltrated directly from that third-party environment or whether it was pulled back through MAG’s network first. That distinction matters for understanding where detection controls failed and who was responsible for monitoring the egress.
The UK’s Civil Aviation Authority has a Cyber Assessment Framework for Aviation, developed with the NCSC, that mandates strict separation between IT systems and operational technology. We don’t know whether MAG was formally operating under that framework at the time of this incident, but I would be very interested to find out. Because the segmentation appears to have held here. Flight operations, baggage handling, terminal systems, etc., all were unaffected. The lateral movement went upstream toward a data provider, not downstream toward the systems that keep planes in the air.
Seemant Sehgal, CEO and Founder, BreachLock:
“This data was initially collected because passengers needed a login, and somewhere along the way, the sensitivity of what was accumulating in that database stopped getting the same scrutiny as the network itself. Vehicle registration details, postcodes, and contact information across three major airports are a profiling dataset, and whoever held it for ransom understood its value better than the organization storing it did.”
This is why I use a VPN when I use public WiFi. In short, public WiFi cannot be trusted. You have to assume the same in order to keep safe.
Related
This entry was posted on August 29, 2026 at 9:38 am and is filed under Commentary with tags Hacked, WiFi. You can follow any responses to this entry through the RSS 2.0 feed.
You can leave a response, or trackback from your own site.
Around 8.7 Million travellers’ info stolen at 3 UK airports
Around 8.7 million travellers who signed up for WiFi, car parking services and lounges in airports run by Manchester Airports Group (MAG) had their data stolen, including email addresses and phone numbers, postcodes and vehicle registration details. MAG operates airports in Manchester, London Stansted and East Midlands, and declined the demand to pay ransom.
Denis Calderone, CTO, Suzu Labs:
The 8.7 million number is attention-grabbing, but it deserves some context. MAG has confirmed that the vast majority of those records are email addresses collected through airport WiFi sign-ups. A much smaller subset includes phone numbers, vehicle registrations, and postcodes from customers who actually completed parking or lounge bookings. No payment data, no passwords, no passport information. So despite this affecting airports, which is obviously a sensitive subject, the actual data sensitivity for most affected individuals is relatively low.
What’s more interesting to us from a technical standpoint is the attack path. MAG told The Register that attackers compromised one of their internal systems and then went on to steal files from a database hosted by a third party. That’s a pivot upstream into a data provider, not downstream into operational systems. What remains unclear is whether the data was exfiltrated directly from that third-party environment or whether it was pulled back through MAG’s network first. That distinction matters for understanding where detection controls failed and who was responsible for monitoring the egress.
The UK’s Civil Aviation Authority has a Cyber Assessment Framework for Aviation, developed with the NCSC, that mandates strict separation between IT systems and operational technology. We don’t know whether MAG was formally operating under that framework at the time of this incident, but I would be very interested to find out. Because the segmentation appears to have held here. Flight operations, baggage handling, terminal systems, etc., all were unaffected. The lateral movement went upstream toward a data provider, not downstream toward the systems that keep planes in the air.
Seemant Sehgal, CEO and Founder, BreachLock:
“This data was initially collected because passengers needed a login, and somewhere along the way, the sensitivity of what was accumulating in that database stopped getting the same scrutiny as the network itself. Vehicle registration details, postcodes, and contact information across three major airports are a profiling dataset, and whoever held it for ransom understood its value better than the organization storing it did.”
This is why I use a VPN when I use public WiFi. In short, public WiFi cannot be trusted. You have to assume the same in order to keep safe.
Share this:
Like this:
Related
This entry was posted on August 29, 2026 at 9:38 am and is filed under Commentary with tags Hacked, WiFi. You can follow any responses to this entry through the RSS 2.0 feed. You can leave a response, or trackback from your own site.