Manchester Airports Group (MAG), which operates Manchester, Stansted and East Midlands airports, has confirmed that a cyber attack exposed customer data relating to services including Wi-Fi registrations, parking and lounge bookings. The company says airport operations, passenger safety and payment information were not affected.
Mike Maddison, CEO of global cyber security company NCC Group, said:
“Airports sit at the intersection of critical infrastructure and international travel, making them attractive targets due to the wealth of data they hold and the level of disruption a cyber attack can cause. Previous attacks have demonstrated how interconnected modern aviation ecosystems are, with incidents capable of creating knock-on effects across borders. An airport car park system breach, for example, could provide a pathway into critical flight management systems. The aviation sector therefore needs to be prepared for cyber breaches that could threaten the safety of flight operations.
“Without treating cyber security with the same priority as physical security, the aviation sector risks cascading failures that undermine trust, disrupt operations and compromise passenger safety.”
What should customers do?
“Customer details held by Manchester Airports Group, including email addresses, phone number, vehicle registrations and postcodes, have been accessed. The company has warned that customers whose information has been stolen should remain vigilant for scams, which malicious actors could use their personal details to make more convincing.
“Scams have become increasingly sophisticated in recent years, with attackers using AI to make phishing messages more convincing and harder to distinguish from legitimate communications. Anyone concerned that their data may have been affected by this breach should be particularly cautious of unsolicited emails, messages or calls seeking personal information, encouraging them to click a link or requesting payment.”
Mike Maddison biography
Mike Maddison leads global cyber security and resilience company NCC Group as Group Chief Executive Officer. He oversees the firm’s global operations across cyber security, working with a team of more than 2,100 professionals delivering services that strengthen operational resilience and data security for organisations worldwide. For more than 25 years, NCC Group has supported leading companies and governments in managing cyber risk and building resilient digital environments.
Mike joined NCC Group as Group Chief Executive Officer following a career spanning senior leadership roles across global professional services firms. Prior to his appointment, he led EY’s cyber security, privacy, and trusted technology practice for EMEA, a role he held since 2017, where he oversaw growth across 97 countries and strengthened the firm’s position as a cyber security adviser. Earlier, he led PwC’s Risk Services practice in the Middle East and previously headed Deloitte’s cyber security consultancy in EMEA for a decade.
Contact
NCC Group Press Office
All media enquires relating to NCC Group plc.