Cybercrooks jet off with Manchester Airports Group customer data
UK’s largest airport operator believes 8.7 million customers affected
security
Cybercrooks jet off with Manchester Airports Group customer data
UK’s largest airport operator believes 8.7 million customers affected
The company behind three of the UK’s busiest airports says “a quantity” of data was stolen by an extortion group during a recent “cybersecurity incident."
Manchester Airports Group (MAG), which operates Manchester Airport in the North West of England, Essex’s Stansted Airport, and East Midlands Airport in Derbyshire, confirmed the attack did not involve ransomware.
A MAG spokesperson confirmed the details to The Register, as well as the scale of the breach, which is currently thought to have affected 8.7 million customers.
The company, whose airports served a record 66 million customers in the past financial year, said that the overwhelming majority of those affected have only had their email addresses compromised.
In most cases, these email addresses were collected during the sign-up phase for the airports’ public Wi-Fi services, MAG said.
It told The Register that this scenario dwarfed every other. The next most common involved data taken from customers who had made "speculative enquiries" - i.e. they entered their details in the process of booking car parking or Fast Track, but did not complete it. An even greater minority of the data came from bookings that were actually completed.
The Information Commissioner’s Office (ICO) asked MAG not to share details of the ransom note, the extortion demands, or the group name, mainly to avoid helping those responsible gain notoriety.
MAG did, however, tell us that the group's extortion demands, in this case, were considerably lower than what the group is known to ask for, per the ICO's understanding. It has not paid the extortionists.
“We have informed and are working with the relevant authorities,” said MAG in a statement. “At no point has passenger safety or aviation security been compromised.”
MAG said the attackers compromised one of its systems, which it did not specifically identify, and then went on to steal the files from a database hosted by a third party.
Company chiefs see this attack as "a hack, not a lapse." The spokesperson said it was a sophisticated attack and not the result of a human mistake, such as staff giving away credentials.
It confirmed that none of its airports experienced operational disruption as part of the attack, and that the affected system does not store bank or payment details.
However, “as a precautionary measure,” it temporarily revoked access to its Manage My Booking service. Customers who want to amend or cancel a booking due within 72 hours of the statement going live are being advised to contact customer services.
“We would like to reassure customers that Manchester Airport Group takes the security of customer information extremely seriously and we apologise for any inconvenience or concern caused.”
Affected customers have already been contacted, including a few Reg readers who kindly alerted us to the news.
While MAG continues to investigate the incident, customers are advised to be extra vigilant to potential phishing attempts, and remain assured that there is no danger of visiting MAG’s airports as a result of the cyberattack.
One Reg reader griped that in addition to being charged £80 for five days of parking at Stansted, receiving the email informing him that it had also allowed his personal data to be stolen via a cybersecurity breach added insult to injury. ®
Originally published on The Register