Manchester Airports Group Hit by Cyberattack, 8.7 Million Customer Records Exposed
A recent cyberattack has impacted **Manchester Airports Group (MAG)**, a major operator of three of England's busiest airports. The breach exposed data belonging to approximately 8.7 million customers, encompassing information related to car park, lounge, Fast Track bookings, and Wi-Fi sign-ups.
On Thursday, **Manchester Airports Group (MAG)**, a public-private partnership overseeing **Manchester**, **London Stansted**, and **East Midlands** airports, confirmed a significant cyberattack. The incident led to an unauthorized third party accessing sensitive customer data.
### Scope of the Breach
The compromised information includes email addresses, phone numbers, vehicle registrations, and postcodes. **MAG** has clarified that no bank or payment card details were stored on the affected system, meaning no financial data was exposed in the incident. While the three airports serve over 65 million passengers annually, the breach specifically impacts those who utilized car park, lounge, Fast Track, or in-airport Wi-Fi services.
A spokesperson for **MAG** informed *The Yorkshire Post* that roughly 8.7 million individuals were affected. They noted that for the "vast majority" of these cases, the only information accessed was an email address.
### Incident Response and Measures
**MAG** was alerted to the intrusion on Tuesday and believes the initial access occurred a few days prior. Upon discovery, the group swiftly initiated containment measures, restricting access to affected systems, engaging external cybersecurity specialists, and notifying relevant authorities.
Passenger safety and aviation security remain uncompromised, with all flights, airport operations, and parking services continuing as normal. As a precautionary step, the online 'Manage My Booking' service has been temporarily suspended. Customers with upcoming reservations are assured their bookings remain valid, with a dedicated customer service line available for those needing to make changes within 72 hours.
### Advice for Affected Customers
**MAG** has begun emailing affected customers, advising them to remain vigilant against potential phishing attempts. The group emphasized that it will never unexpectedly request payment card details, banking information, or passwords from customers. This incident underscores the ongoing need for robust cybersecurity practices across all sectors, particularly for entities handling large volumes of personal data.