← All security news

Manchester Airports Group Data Breach

A WiFi sign-up screen and a car park booking ticket leaking data through a cracked padlock beside a runway motif, representing Manchester Airports Group's breach of side-system customer data

Manchester Airports Group (MAG), which operates Manchester, London Stansted and East Midlands airports, disclosed this week that hackers accessed customer data across all three sites. MAG says it became aware of the intrusion on Tuesday, 25 August, and believes the access happened a few days before that. Data confirmed as compromised includes email addresses, phone numbers, vehicle registration numbers and postcodes — collected through the airports' WiFi sign-up pages, car park bookings, lounge access and Fast Track services. Media estimates, not yet confirmed by MAG itself, put the number of affected travelers as high as 8.7 million; the majority reportedly had only an email address exposed. No payment card or bank details were involved, and MAG says passenger safety, aviation security and airport operations were unaffected. No ransomware or extortion group has publicly claimed the attack. MAG has temporarily taken its online booking-management service offline and is directing affected customers to phone support while it investigates with outside specialists and the relevant authorities.

The detail worth noting isn't the airport connection — it's where the data actually came from. None of the exposed information sits in MAG's core operational systems; it came from the side services that sit around the main business: a WiFi captive portal, a parking booking widget, a lounge reservation form. Those bolt-on systems are exactly the kind of thing a growing business adds over time without treating them as seriously as the "main" website or app — and they're increasingly where attackers look first, because they're often lighter on security review while still holding real customer data.

What this means for your business

  • List every customer-facing form you run beyond your main website or booking system — guest WiFi, event RSVPs, loyalty sign-ups, delivery-tracking portals. If you didn't build it in-house, find out who did and how it stores what it collects.
  • Email, phone, home postcode and (in this case) a vehicle registration number is enough to build a convincing phishing or smishing message. If you run a similar sign-up flow, have a customer-notification template ready before you need it, not after.
  • "No payment card data" doesn't mean "no notification duty." Contact information on its own is usually still reportable under data protection law wherever your business operates — know that threshold before an incident forces you to look it up.
  • MAG could take one customer-facing service offline and route people to phone support without stopping flights. Check whether you could isolate a single compromised booking or sign-up system the same way, without shutting down the rest of the business.

A breach through a side system is still a breach — the exposed data was just as real to the 8.7 million people affected as if it had come from MAG's core booking platform. The lesson for smaller businesses isn't "don't offer WiFi or online booking" — it's to hold every customer-data touchpoint to the same standard, not just the ones that feel like the "real" system.

Questions about your own setup? contact@techleetsolutions.com
Sources: BleepingComputer, The Register, Infosecurity Magazine