Severity Daily

IT and AI security incidents, checked against the primary source

Tag: phishing

  • Manchester Airports Group says 8.7 million customers’ details were taken from a third-party-hosted database, and the ICO asked it not to name the attacker

    Manchester Airports Group says 8.7 million customers’ details were taken from a third-party-hosted database, and the ICO asked it not to name the attacker

    MAG confirmed the breach on August 27, 2026 and put the figure at roughly 8.7 million customers; the data came from car park, lounge and Fast Track bookings and from airport Wi-Fi sign-ups, and the regulator asked the company not to name the group behind it.

    What happened

    On August 27, 2026, Manchester Airports Group — the owner of Manchester, London Stansted and East Midlands airports — confirmed that an unauthorized third party had obtained a batch of customer information. Reporting on August 28 put the number at approximately 8.7 million customers. This is a confirmation by the named organization, not an attacker claim: MAG announced it, gave the categories of data involved, and made statements about what was and was not affected.

    Two dates matter and both are recent. The disclosure is from August 27. MAG has described discovering the intrusion earlier that week, with the access occurring a few days before discovery. The company has not published a precise intrusion window, and neither will we.

    The data categories MAG has described are email addresses, phone numbers, vehicle registration numbers and postcodes, drawn from car park bookings, lounge bookings, Fast Track bookings and airport Wi-Fi sign-ups. In the great majority of cases, MAG has said, the only item involved was an email address. Some records came from completed bookings and some from booking attempts that were never finished.

    On payment data the company has been specific: “Neither MAG nor the system accessed hold customers’ bank or payment details.” That is a stronger claim than the usual assurance — it asserts the card data was not there to take, rather than that it was there and untouched.

    MAG’s own account of the containment: “We immediately contained the risk and have been working with specialist advisors and taking appropriate steps to protect our customers and systems.” On operations: “At no point has passenger safety or aviation security been compromised.” And on the practical question travelers were asking: “All upcoming bookings remain valid and are unaffected by this incident. Passengers should continue to travel to the airport as normal.” MAG suspended its online Manage My Booking service and advised customers to watch for phishing and smishing.

    The intrusion path, as MAG has described it to reporters, runs in an order worth noting. The attackers compromised one of MAG’s own systems, which the company has not identified, and then took the files from a database hosted by a third party. MAG has not named the third party.

    The attacker is not named, and that is a decision, not a gap. According to The Register’s August 27 account, the Information Commissioner’s Office asked MAG to withhold the group’s name and the details of the ransom demands in order to avoid giving the attackers publicity. MAG has not paid. The company has characterized the incident as a hack rather than a lapse — that is, as an intrusion rather than a misconfiguration or a credential left lying around.

    The count is not agreed. MAG’s figure, as reported, is 8.7 million customers. At least one outlet, the Yorkshire Post, headlined nine million passengers. Those are also different units — customer records in a bookings and Wi-Fi database are not passengers, and one person can be several records. We have seen no reconciliation of the two and are not supplying one.

    Why it matters

    The instinct on reading “email addresses and postcodes” is to file this under low-harm and move on. That instinct is worth resisting for two reasons specific to this dataset.

    The first is that the combination is unusually good for targeted phishing against this exact population. An attacker holding an email address, a phone number, a postcode and a vehicle registration, all tied to a specific airport and in many cases to a specific car park booking, can write a message that is correct in every checkable detail. “Your booking at Manchester Terminal 2 for vehicle [registration] requires confirmation” does not need to be clever. It needs to be accurate, and this data makes it accurate. MAG’s own advice to watch for phishing and smishing is the right advice, and the reason it is the right advice is that the stolen fields are precisely the ones that make a lure verifiable.

    The second is durability. Email addresses can be filtered and phone numbers can be changed, with effort. A vehicle registration cannot be rotated, a postcode changes only when you move, and the pairing of the two is a persistent identifier for a household. This dataset does not decay the way a credential dump does. It is still useful to whoever holds it in three years.

    Then there is where the data was sitting. Car park bookings, lounge access and Wi-Fi sign-ups are the retail exhaust of running airports — ancillary revenue systems, frequently outsourced, and almost never the thing anyone means when they say “airport security.” MAG’s statement that passenger safety and aviation security were never compromised is almost certainly accurate and also somewhat beside the point. The operational systems were fine. The commercial systems held 8.7 million people’s contact details, and those are what went.

    The order of the intrusion inverts the usual third-party story, and that inversion is the most transferable lesson here. The standard supply-chain breach starts at the vendor and reaches the customer. This one, on MAG’s account, started inside MAG and reached a database the vendor was hosting. Access controls between an internal system and an outsourced datastore tend to be built on the assumption that the internal side is the trusted side. When the internal side is the compromised side, that trust is what carries the attacker across. If you host data with a third party and your own systems hold the credentials to reach it, the vendor’s security posture is not the whole of your exposure, and their breach notification obligations will not cover you.

    Finally, the regulator’s instruction. An ICO request that a victim withhold the attacker’s name and the ransom terms is a defensible position — publicity is a product these groups sell, and denying it has value. It also means the public record of this incident is incomplete by design. Anyone trying to work out whether their own sector is being worked by the same crew cannot use this case, because the identifying detail has been deliberately removed. That trade-off may well be the right one. It is worth being explicit that a trade-off was made, and that a reader who assumes the absence of attribution here reflects an absence of knowledge would be wrong.

    What to do

    If you have parked at, used a lounge at, bought Fast Track for, or joined the Wi-Fi at Manchester, London Stansted or East Midlands, assume your email address is in this set and treat anything referencing a booking, a vehicle or an airport account as hostile until verified out of band. Go to the airport’s site directly rather than through a link. MAG’s Manage My Booking service has been suspended; a message pointing you to it is a signal, not a service.

    For organizations: inventory the datastores your ancillary and marketing systems write to, specifically ones hosted by suppliers, and check which of your internal systems hold standing credentials to them. The relevant question is not whether the supplier is secure. It is what an attacker who already has a foothold inside your estate can reach through it, and whether that access is logged where you would see the volume of a bulk extraction.

    There is no patch here, no CVE and no version to check. This is a breach story, and the action is inventory and monitoring, not remediation.

    Sourcing note

    Checked: MAG’s statements as reported by Help Net Security (August 28, 2026), The Register (August 27, 2026), Infosecurity Magazine (August 27, 2026), IT Pro (August 28, 2026) and The Record (August 27, 2026). The quotations attributed to MAG above — on containment, on passenger safety, on payment details, and on bookings remaining valid — are reproduced from those reports.

    We were not able to reach MAG’s own media center directly; the corporate press site did not resolve for us, so every MAG quotation here is at one remove from the company’s own publication. We flag that rather than present the quotes as first-hand. The account of the intrusion order — MAG system first, third-party-hosted database second — and the ICO’s request to withhold the attacker’s name and ransom details come from The Register’s August 27 report and are not independently confirmed.

    Unresolved: the third-party host is not named; the initially compromised MAG system is not named; the attacker is not named, at the regulator’s request; the intrusion window has not been published; and the 8.7 million and nine million figures have not been reconciled. No CVE or vulnerability has been associated with this incident by MAG or by anyone else. We have seen no ICO statement of its own, only the reported request.

  • Berlin confirms it is being extorted, eleven days after announcing a network compromise without mentioning it

    Berlin confirms it is being extorted, eleven days after announcing a network compromise without mentioning it

    The State of Berlin acknowledged a compromise of its administrative network on August 17 without mentioning extortion. On August 28 it confirmed the extortion and rejected the ultimatum — and almost everything published about what was taken comes from the people who took it.

    What happened

    On August 28, 2026, Berlin’s Senate confirmed that the state administration is the subject of an extortion attempt following a cyberattack, and the Governing Mayor, Kai Wegner, rejected the attackers’ ultimatum. His statement, in full: “Das Land Berlin wird sich nicht erpressen lassen” — the State of Berlin will not allow itself to be extorted.

    That is the news. It is worth setting against what the state said eleven days earlier.

    On August 17, the Senatskanzlei published a press release titled IKT-Vorfall im Landesnetz Berlin — ICT incident in the Berlin state network. Its operative sentence: “Im Zuge forensischer Untersuchungen hat sich eine Inkriminierung des Landesnetzes Berlin ergeben” — in the course of forensic investigations, a compromise of the Berlin state network was established. The release named two Senate administrations that had been isolated from the network the preceding Friday: Urban Development, Building and Housing, and Mobility, Transport, Climate Protection and Environment. It gave no dates for any data outflow, no volume, and no attacker. It stated that “aus ermittlungstaktischen Gründen” — for investigative reasons — no further concrete information could be provided.

    It did not mention extortion at all.

    What the Senatskanzlei has since acknowledged, as reported by German outlets that carried its statements, is that personalized and other non-public data may have been taken from the Mobility, Transport, Climate Protection and Environment administration, and that the full scope is not yet established. Coverage places the data outflow in a window between August 7 and 12, and reports that all Senate administrations were reconnected to the network on August 23. Neither of those specifics appears in the August 17 release, and we have not found them in a primary statement.

    Everything that follows is claimed by the attackers, labeled as such throughout because Berlin has confirmed none of it.

    The claimed inventory includes roughly 80,000 administrative-offense files, more than 46,500 contracts, court documents, details described as relating to critical infrastructure, emergency plans, passwords, and approximately 6,000 files of login credentials. The claimed ransom is 30 bitcoin, characterized in reporting by Der Spiegel as around €2 million, with an initial ultimatum set for Friday afternoon and a deadline a week out.

    The claimed volume does not agree with itself across sources. One figure circulating is 5.79 terabytes; German reporting gives 5.7 terabytes copied from the environment and transport administration. On people affected, one account reports a claim of personal information on 12,076 individuals, while German coverage describes 100,000 to 200,000 individual data records. Those last two are not necessarily contradictory — records are not people — but they are not reconcilable from anything published either, and no official figure exists for any of it.

    On attribution: the ransomware group Rhysida has been named by Der Spiegel and by security sources, and a leak-site entry appeared on August 28. Berlin has not publicly attributed the attack, and neither do we. A leak-site listing establishes that someone claims the data; it does not establish who took it, and it is not evidence of the inventory it advertises. Reporting also describes the initial access as a phishing email opened by an employee. That has not been confirmed by the Senatskanzlei and is carried here as reporting.

    Why it matters

    The eleven days between the two statements are the part worth studying, and not because anyone did anything improper.

    The August 17 release is a model of a certain genre: accurate, prompt by public-sector standards, and almost entirely uninformative. Every sentence in it is defensible. It confirms a compromise, names the isolated departments, and declines further detail on investigative grounds — a real constraint, not an excuse, when a criminal investigation is running. What it does not do is tell anyone whose data sits in those systems that a party with a financial motive is holding it.

    Eleven days later the extortion is public, and it is public on the attackers’ schedule. The ultimatum, the leak-site entry and the ransom figure all surfaced together, and the state’s confirmation followed them. That is the structural problem with staged disclosure: an organization that holds back the extortion element for legitimate investigative reasons has ceded the timing of that disclosure to the criminal, who has every incentive to choose the moment that maximizes pressure. Berlin ended up confirming the extortion in response to an ultimatum rather than announcing it on its own terms, and the sequence reads as reactive even though the underlying decisions may each have been sound.

    A related sequencing detail, stated without insinuation: all Senate administrations were reportedly reconnected on August 23, five days before the extortion was publicly confirmed. Reconnection turns on forensic confidence about persistence and access, which is a different question from whether stolen data is being used as leverage, and both can be handled correctly at once. But the public timeline shows restoration completed before the public learned an extortion demand was involved.

    Wegner’s refusal is the right call and deserves to be said without hedging. Paying funds the next operation, guarantees no deletion, and buys a promise from a party whose business model is breaking promises. But it is not costless: if the claimed material is genuine, it gets published, and the remediation burden falls entirely on the state. Refusal absorbs that cost deliberately rather than gambling on avoiding it, and calling it free does the decision a disservice.

    For everyone else, the operationally important claim in that inventory is not the terabyte count. It is the roughly 6,000 credential files and the emergency plans. If credentials were genuinely taken at that scale from a state administration, the exposure does not stop at the two isolated departments — it extends to every system, supplier portal and federated service those credentials could reach, and isolating a network segment does nothing about a valid password used somewhere else. Credential rotation across an organization the size of a city-state administration is measured in months, and it is the work that outlasts the headline. We stress again that this is the attackers’ claim. It is also the claim that, if true, matters most, which is precisely why it should not be repeated as fact.

    What to do

    • If you are a supplier, contractor or federated partner of the Berlin administration — particularly the Senate administration for Mobility, Transport, Climate Protection and Environment — treat any credential, API key or shared account you have exchanged with those systems as potentially exposed and rotate it. Do this on the claim, not on confirmation; rotation is cheap and confirmation may take months.
    • Do not build a response around the leak-site inventory. Volumes and file counts published by an extortion group are promotional material. Use them to scope what to check, never as an assessment of what was lost.
    • Decide your own disclosure triggers now, in writing. Berlin’s sequence — incident notice first, extortion confirmation eleven days later under an ultimatum — is the default outcome when nobody has predetermined whether “we are being extorted” is disclosed with the incident or held. Make that call before you need it, and record the reasoning.
    • Check that you could isolate an administrative unit the way Berlin did. Whatever else is unresolved here, segmenting two departments off the state network was possible and was done quickly. If your equivalent action would require an all-or-nothing shutdown, that is a design finding you can act on today.
    • Treat “emergency plans” as a data class. Continuity documentation usually sits outside the classification schemes applied to personal data, and it describes exactly how an organization behaves under stress. Find out where yours lives and who can read it.

    Sourcing note

    Checked: the Senatskanzlei’s press release of August 17, 2026, IKT-Vorfall im Landesnetz Berlin, on berlin.de, which supplied the quoted German text, the two named Senate administrations, the isolation action, and the investigative-reasons caveat — and which contains no reference to extortion. That is the primary source for the state’s initial position.

    The August 28 confirmation and Wegner’s quoted statement come from Tagesspiegel’s report of that date, published 6:37 p.m. and updated 8:37 p.m., which is where we read them. We could not locate a Senatskanzlei press release carrying the same language, so the confirmation reaches us at one remove from a German outlet that carried the Senate’s statements, not from a government page.

    All figures for volume, file counts, individuals affected, ransom amount and the contents of the stolen material originate with the attackers and are reported as claims. The conflicting volume figures (5.79 versus 5.7 terabytes) and the two different measures of scope (12,076 individuals versus 100,000 to 200,000 records) are shown as they stand; we have not chosen between them, and no official figure has been published. The ransom of 30 bitcoin, described as approximately €2 million, is Der Spiegel’s reporting.

    Attribution to Rhysida is reporting by Der Spiegel and unnamed security sources, plus a leak-site entry dated August 28. It is not confirmed by Berlin and is not stated as fact here. The phishing-email account of initial access is likewise reporting and is unconfirmed by the Senatskanzlei.

    Unresolved: the actual volume and nature of data taken; whether credentials were among it; the dates of the data outflow, which appear in coverage as August 7 to 12 but not in any primary statement we located; and whether Berlin will make an attribution of its own.