Decoding the world of cybersecurity

Manchester airports confirm customer data theft

Manchester Airports Group says an unauthorised third party obtained customer information linked to airport services, although operational systems, payment data, passenger safety, and aviation security were unaffected.

Manchester airports confirm customer data theft
Summary
  • Data linked to parking, lounges, Fast Track, and airport Wi-Fi at Manchester, Stansted, and East Midlands airports was obtained.
  • Exposed information includes email addresses, telephone numbers, vehicle registrations, and postcodes, but not bank or payment details.
  • Airport operations were not disrupted, although access to the online booking-management service was temporarily suspended as a precaution.

Manchester Airports Group has confirmed that an unauthorised third party obtained customer data connected to services at Manchester, London Stansted, and East Midlands airports.

The incident affects information associated with car-park, lounge, and Fast Track bookings, as well as registrations for airport Wi-Fi. MAG said the accessed data includes email addresses, telephone numbers, vehicle registrations, and postcodes.

The group said neither it nor the affected system holds customers’ bank or payment details. It has contacted affected customers directly.

Airport operations have not been disrupted, and MAG says passenger safety and aviation security were not compromised. The incident does not involve operational airport systems, according to the group, and passengers have been told to travel as normal.

MAG nevertheless suspended access to its online Manage My Booking service as a precaution. Existing bookings remain valid and parking services continue to operate, leaving the disruption confined to a customer-facing function rather than airport operations.

The company said it restricted access to affected systems after discovering the incident, engaged specialist cyber-security advisers, and notified the relevant authorities. Its data-protection team is overseeing the response.

MAG has not publicly identified the attacker or disclosed the initial access route. Its statement also does not specify the number of affected customers or explain whether the compromised system was operated directly by MAG or by another provider.

Those unanswered points will shape the regulatory and incident-response work that follows. Contact details, vehicle registrations, and travel-related information can have consequences even without payment-card data, particularly if several fields are combined to make subsequent communications appear credible.

The breach also shows how the cyber-security boundary around an airport extends beyond systems responsible for aviation operations. Parking, lounges, Fast Track services, booking management, and public Wi-Fi have become part of the commercial technology estate surrounding major transport hubs.

Each service collects information for a different purpose and may involve different software, suppliers, retention periods, and access arrangements. That creates a sizeable customer-data environment alongside the more tightly controlled systems used for safety, security, passenger processing, and other operational functions.

Separating those environments limits the consequences when one is compromised. MAG’s statement that operational airport systems were unaffected is therefore important, but it does not diminish the need to establish how customer information was obtained and whether access extended further within the affected environment.

The incident also presents a familiar resilience trade-off. Organisations investigating a compromise may choose to suspend customer services that have not themselves failed because keeping them online could complicate containment or create additional exposure. The temporary withdrawal of booking-management access appears to have been such a precaution rather than evidence of wider operational failure.

The next stage will depend on the investigation’s findings about the volume of information involved, the period of unauthorised access, and whether other categories of data were reachable. Those details will determine the scale of notification and any further regulatory consequences.

For now, MAG’s disclosure establishes a relatively clear boundary. Customer contact and vehicle information was obtained from a system supporting commercial airport services. Payment information, passenger safety, aviation security, and operational airport systems are outside the impact the group has confirmed.

×