Severity Daily

IT and AI security incidents, checked against the primary source

Tag: aviation

  • Manchester Airports Group says 8.7 million customers’ details were taken from a third-party-hosted database, and the ICO asked it not to name the attacker

    Manchester Airports Group says 8.7 million customers’ details were taken from a third-party-hosted database, and the ICO asked it not to name the attacker

    MAG confirmed the breach on August 27, 2026 and put the figure at roughly 8.7 million customers; the data came from car park, lounge and Fast Track bookings and from airport Wi-Fi sign-ups, and the regulator asked the company not to name the group behind it.

    What happened

    On August 27, 2026, Manchester Airports Group — the owner of Manchester, London Stansted and East Midlands airports — confirmed that an unauthorized third party had obtained a batch of customer information. Reporting on August 28 put the number at approximately 8.7 million customers. This is a confirmation by the named organization, not an attacker claim: MAG announced it, gave the categories of data involved, and made statements about what was and was not affected.

    Two dates matter and both are recent. The disclosure is from August 27. MAG has described discovering the intrusion earlier that week, with the access occurring a few days before discovery. The company has not published a precise intrusion window, and neither will we.

    The data categories MAG has described are email addresses, phone numbers, vehicle registration numbers and postcodes, drawn from car park bookings, lounge bookings, Fast Track bookings and airport Wi-Fi sign-ups. In the great majority of cases, MAG has said, the only item involved was an email address. Some records came from completed bookings and some from booking attempts that were never finished.

    On payment data the company has been specific: “Neither MAG nor the system accessed hold customers’ bank or payment details.” That is a stronger claim than the usual assurance — it asserts the card data was not there to take, rather than that it was there and untouched.

    MAG’s own account of the containment: “We immediately contained the risk and have been working with specialist advisors and taking appropriate steps to protect our customers and systems.” On operations: “At no point has passenger safety or aviation security been compromised.” And on the practical question travelers were asking: “All upcoming bookings remain valid and are unaffected by this incident. Passengers should continue to travel to the airport as normal.” MAG suspended its online Manage My Booking service and advised customers to watch for phishing and smishing.

    The intrusion path, as MAG has described it to reporters, runs in an order worth noting. The attackers compromised one of MAG’s own systems, which the company has not identified, and then took the files from a database hosted by a third party. MAG has not named the third party.

    The attacker is not named, and that is a decision, not a gap. According to The Register’s August 27 account, the Information Commissioner’s Office asked MAG to withhold the group’s name and the details of the ransom demands in order to avoid giving the attackers publicity. MAG has not paid. The company has characterized the incident as a hack rather than a lapse — that is, as an intrusion rather than a misconfiguration or a credential left lying around.

    The count is not agreed. MAG’s figure, as reported, is 8.7 million customers. At least one outlet, the Yorkshire Post, headlined nine million passengers. Those are also different units — customer records in a bookings and Wi-Fi database are not passengers, and one person can be several records. We have seen no reconciliation of the two and are not supplying one.

    Why it matters

    The instinct on reading “email addresses and postcodes” is to file this under low-harm and move on. That instinct is worth resisting for two reasons specific to this dataset.

    The first is that the combination is unusually good for targeted phishing against this exact population. An attacker holding an email address, a phone number, a postcode and a vehicle registration, all tied to a specific airport and in many cases to a specific car park booking, can write a message that is correct in every checkable detail. “Your booking at Manchester Terminal 2 for vehicle [registration] requires confirmation” does not need to be clever. It needs to be accurate, and this data makes it accurate. MAG’s own advice to watch for phishing and smishing is the right advice, and the reason it is the right advice is that the stolen fields are precisely the ones that make a lure verifiable.

    The second is durability. Email addresses can be filtered and phone numbers can be changed, with effort. A vehicle registration cannot be rotated, a postcode changes only when you move, and the pairing of the two is a persistent identifier for a household. This dataset does not decay the way a credential dump does. It is still useful to whoever holds it in three years.

    Then there is where the data was sitting. Car park bookings, lounge access and Wi-Fi sign-ups are the retail exhaust of running airports — ancillary revenue systems, frequently outsourced, and almost never the thing anyone means when they say “airport security.” MAG’s statement that passenger safety and aviation security were never compromised is almost certainly accurate and also somewhat beside the point. The operational systems were fine. The commercial systems held 8.7 million people’s contact details, and those are what went.

    The order of the intrusion inverts the usual third-party story, and that inversion is the most transferable lesson here. The standard supply-chain breach starts at the vendor and reaches the customer. This one, on MAG’s account, started inside MAG and reached a database the vendor was hosting. Access controls between an internal system and an outsourced datastore tend to be built on the assumption that the internal side is the trusted side. When the internal side is the compromised side, that trust is what carries the attacker across. If you host data with a third party and your own systems hold the credentials to reach it, the vendor’s security posture is not the whole of your exposure, and their breach notification obligations will not cover you.

    Finally, the regulator’s instruction. An ICO request that a victim withhold the attacker’s name and the ransom terms is a defensible position — publicity is a product these groups sell, and denying it has value. It also means the public record of this incident is incomplete by design. Anyone trying to work out whether their own sector is being worked by the same crew cannot use this case, because the identifying detail has been deliberately removed. That trade-off may well be the right one. It is worth being explicit that a trade-off was made, and that a reader who assumes the absence of attribution here reflects an absence of knowledge would be wrong.

    What to do

    If you have parked at, used a lounge at, bought Fast Track for, or joined the Wi-Fi at Manchester, London Stansted or East Midlands, assume your email address is in this set and treat anything referencing a booking, a vehicle or an airport account as hostile until verified out of band. Go to the airport’s site directly rather than through a link. MAG’s Manage My Booking service has been suspended; a message pointing you to it is a signal, not a service.

    For organizations: inventory the datastores your ancillary and marketing systems write to, specifically ones hosted by suppliers, and check which of your internal systems hold standing credentials to them. The relevant question is not whether the supplier is secure. It is what an attacker who already has a foothold inside your estate can reach through it, and whether that access is logged where you would see the volume of a bulk extraction.

    There is no patch here, no CVE and no version to check. This is a breach story, and the action is inventory and monitoring, not remediation.

    Sourcing note

    Checked: MAG’s statements as reported by Help Net Security (August 28, 2026), The Register (August 27, 2026), Infosecurity Magazine (August 27, 2026), IT Pro (August 28, 2026) and The Record (August 27, 2026). The quotations attributed to MAG above — on containment, on passenger safety, on payment details, and on bookings remaining valid — are reproduced from those reports.

    We were not able to reach MAG’s own media center directly; the corporate press site did not resolve for us, so every MAG quotation here is at one remove from the company’s own publication. We flag that rather than present the quotes as first-hand. The account of the intrusion order — MAG system first, third-party-hosted database second — and the ICO’s request to withhold the attacker’s name and ransom details come from The Register’s August 27 report and are not independently confirmed.

    Unresolved: the third-party host is not named; the initially compromised MAG system is not named; the attacker is not named, at the regulator’s request; the intrusion window has not been published; and the 8.7 million and nine million figures have not been reconciled. No CVE or vulnerability has been associated with this incident by MAG or by anyone else. We have seen no ICO statement of its own, only the reported request.