A cyberattack on three of the U.K.’s busiest airports has exposed personal information belonging to about 8.7 million customers, turning routine airport Wi-Fi and booking records into a security concern.
Manchester Airport, London Stansted and East Midlands Airport were targeted in an attack on Manchester Airports Group (MAG), which operates all three facilities.
The compromised information included email addresses, phone numbers, vehicle registration numbers and postcodes. Most of the affected data appears to be email addresses collected when passengers signed up for airport Wi-Fi, according to the BBC.
Other information came from customers using services such as airport parking, lounges and fast-track bookings. MAG said it discovered the intrusion Tuesday after the attackers accessed its systems over the weekend. The company said it identified and closed the point of entry, immediately containing the threat.
The BBC reported that the attackers demanded a ransom for the stolen information, but MAG refused to pay. The amount demanded was not disclosed.
Airports say flights are safe
Despite the scale of the breach, MAG said there was no impact on airport operations or aviation security.
“At no point has passenger safety or aviation security been compromised,” a MAG spokesperson told the BBC.
The company also said the affected system did not contain customers’ bank or payment details. Flight bookings remained valid, and parking services continued operating normally. The incident comes during the busy summer travel period. More than 50 million passengers traveled through the three airports combined last year.
Must-read security coverage
What this means for customers
For affected customers, the immediate concern may be what happens after the breach rather than disruption at the airports themselves.
Stolen email addresses combined with names, phone numbers, postcodes or vehicle details can give criminals useful material for convincing phishing messages. Attackers could potentially pose as an airport, airline or travel service and use genuine-looking details to make fraudulent messages more believable.
Customers who used the affected airports should be especially skeptical of messages that claim to relate to parking, flights, refunds or payments.
MAG has said customers do not need to take specific action following the breach, but vigilance is important. Unexpected requests for passwords, payment information or other personal details should not be trusted simply because they appear to reference a recent airport trip.
The attack also shows why companies operating critical infrastructure must treat customer-facing services as part of their wider security perimeter. Even when an intrusion leaves planes flying normally, the personal data associated with those operations can still be a valuable target.
Other Security News: Australia Post’s password notebooks have reignited debate over whether writing credentials on paper can be safer than storing them on devices targeted by infostealer malware.