🔍 Search...

CYBERSECURITY NEWS

Cyber criminals attack Manchester Airport Group

Share

Manchester Airports Group (MAG) in the UK has become the latest airport to fall victim to a cyber-attack.

The attack, which is believed to have happened a few days ago, has led to the breach of data of around 8.7 million customers.

A statement issued by MAG today reads: “Manchester Airport Group has been subject to a cyber security incident by an unauthorised third party.

“A quantity of customer data has been obtained that relates to car park, lounge and Fast Track bookings and in-airport WIFI sign-ups at Manchester, Stansted, and East Midlands airports.

“We immediately contained the risk and have been working with specialist advisors and taking appropriate steps to protect our customers and systems.

“We have informed and are working with the relevant authorities. At no point has passenger safety or aviation security been compromised.

“The incident has not resulted in any operational disruption. Airport operations remain unaffected and customer parking services continue to operate normally.

“Neither MAG nor the system accessed hold customers’ bank or payment details. The data that has been accessed includes customers’ email addresses, phone numbers, vehicle registrations and postcodes.

“We would like to reassure customers that Manchester Airport Group takes the security of customer information extremely seriously and we apologise for any inconvenience or concern caused.”

MAG, which operates Manchester, London Stansted and East Midlands airports, was made aware of the cyber security incident on Tuesday.

Commenting on this, Muhammad Yahya Patel, vCISO and cybersecurity advisor for EMEA at Huntress, said: “Email addresses, phone numbers, and vehicle registrations combined is a precise targeting profile for anyone planning a follow-on fraud or phishing campaign.

“Scammers now know you travelled, roughly when, and have two direct contact routes to reach you with a convincing story. When that data ends up in an unauthorised third party’s hands alongside parking and lounge booking details, it fills in a surprisingly detailed picture of someone’s travel habits.

“If you’ve received a notification as I have, treat any communication referencing your airport booking, parking, or travel details in the coming weeks with serious caution.

“MAG has confirmed they will never contact you to request payment details or passwords. Anything that does should be treated as a scam attempt using data from this breach.”

Also commenting on today’s news, Graeme Stewart, head of public sector at Check Point Software, said: We warned after the attacks on the automotive sector last year that aviation needed to move onto a war footing. This feels like the moment that warning becomes very real.

“Cyber criminals have already shown us what sustained pressure on a major industry can look like. They find the weak points, work through suppliers and connected systems, steal data and keep coming.

“There was every reason to believe aviation would become an attractive target, and an incident affecting almost nine million airport customers should concentrate minds across the sector.”