Skip to main content
Emerging ThreatsData Breaches

Manchester Airports Breach Exposes 8.7M Customer Records

Modern airport terminal lounge with laptop and papers on a table.

"Generally, any public network, whether it is secure or unsecured, can expose someone’s data to possible interception," warned Jacob Kavlo, Co‑Founder & CEO of Live Proxies.

Manchester Airports Group confirms 8.7 million customer records were accessed

Manchester Airports Group (MAG), the owner of Manchester, East Midlands and London Stansted airports, confirmed that customer data was breached and that 8.7 million customers’ data was accessed. MAG said most of the information taken consisted of emails and Wi‑Fi sign‑ups. The breached dataset also included contact information, vehicle registrations and postcodes.

Attackers demanded a ransom; MAG refused

According to the BBC, the hackers who accessed MAG’s customer data demanded that the organization pay a ransom. MAG refused that demand. The public record provided does not detail whether the attackers published the data, the method used to gain access, or any timeline for the incident beyond the confirmation that customer data was accessed.

What types of customer information were exposed

The data elements explicitly stated as accessed include contact information, vehicle registrations and postcodes, with the majority of records described as emails and Wi‑Fi sign‑ups. That mix of identifiers—email addresses paired with location‑linked details such as postcodes and vehicle registrations—creates several practical risks for affected customers, ranging from increased unsolicited contact to potential fraud vectors tied to identity or travel information.

Security experts point to public Wi‑Fi and remote working as risk factors

Commenting on the broader context for this type of breach, Alana Muir, Head of Cyber at Hiscox, said: “Agile and remote working has become the norm across many industries now. But, between joining public Wi‑Fi networks in cafes and on trains, to working on the go on a smartphone, businesses are notably more vulnerable to cyberattacks.”

Jacob Kavlo elaborated on the mechanics of that exposure: “Cyber attackers can easily access data being transmitted over these Wi‑Fi networks through methods like ‘man‑in‑the‑middle’ attacks, where an attacker can position themselves between a device and the network. They can capture data in transit to read, modify, or steal sensitive information without either party noticing it.”

On mitigation, Kavlo recommended technical controls: “If working remotely, using Virtual Private Networking (VPN) makes an attacker’s job harder. With a VPN, if someone does manage to intercept the internet connection, they won’t be able to read the data being sent because it’s encrypted. However, I highly recommend implementing endpoint protection, VPN access, and multifactor authorisation (MFA) all at once to achieve maximum security.”

What this means for security teams, insurers at Hiscox, and airport customers

  • Security teams: The mix of email and Wi‑Fi sign‑up records in the exposed dataset will push technical teams to review remote‑access controls and the protection of customer‑facing connectivity logs. The experts quoted emphasize layered controls—endpoint protection, VPNs and MFA—rather than a single mitigation.
  • Insurers and risk managers (Hiscox): With Hiscox’s Head of Cyber flagging remote and agile work as a vulnerability, insurers and risk teams are likely to re‑examine underwriting assumptions and the prevalence of remote‑access and public‑Wi‑Fi exposures in their client portfolios.
  • Airport customers: People whose emails, vehicle registrations or postcodes appear in the compromised set should consider that those fields can be used for targeted nuisance campaigns, phishing, or as building blocks for more sophisticated social engineering. The public record confirms the types of data exposed but does not specify notification procedures or remediation steps MAG will take for affected customers.

The breach of 8.7 million customer records at MAG, the refusal to pay a ransom, and the expert emphasis on the vulnerabilities of public Wi‑Fi together underline a persistent tradeoff: travel and mobility increasingly depend on connected services that can create new collections of sensitive identifiers. MAG’s confirmation sets the scale and scope of the incident; the experts’ advice narrows the immediate technical focus to encrypting transit, hardening endpoints, and requiring multifactor checks. Absent further public detail from MAG or the attackers, key questions remain about how the data will be contained, whether it will be published or sold, and how affected customers will be supported.

Source: https://www.securitymagazine.com/articles/102535-manchester-airports-breach-impacts-87m