A major data breach affecting 3 UK airports has escalated after cybercriminals published the personal information of nearly 9 million people online following an unsuccessful ransom demand.
Manchester Airports Group (MAG), which operates Manchester, London Stansted and East Midlands airports, was targeted in the attack. The criminals reportedly demanded an undisclosed ransom from MAG, but the company did not pay.
The stolen information includes email addresses, phone numbers, addresses, postcodes, vehicle registration numbers, purchasing history and browsing device data. The breach appears to have accessed databases containing information linked to airport Wi-Fi logins and car parking services.
The cybercrime group has made the entire dataset available for free through its website, potentially allowing other criminals and scammers to access and reuse the information.
“MAG is confident that we have taken effective measures to protect our customers and we have contacted all those affected, including reaching out to all those with upcoming bookings to advise them of additional support,” the company said.
Data breach specialists at HaveIBeenPwned analysed the published material and confirmed the presence of personal information. Cybersecurity expert Kevin Beaumont warned affected individuals to remain particularly alert to scams and further attacks.
“The data includes both historical locations and planned future travel, so individuals sensitive to their movements being known may need to take precautions,” Beaumont said.
He also warned that scammers could use details such as phone numbers and vehicle registration numbers to make fraudulent messages or calls appear more convincing.
MAG said it is working with authorities and specialist advisers, while stressing that passengers’ physical safety at the airports has not been affected.
The leak is particularly concerning because the criminals’ website is hosted on the clear internet rather than the dark web, making the stolen information easier for other criminals to access.
The group also claimed it used the same method to breach multiple organisations by exploiting weaknesses in how companies store digital keys used for internal networks.
Law enforcement agencies, including the UK’s National Crime Agency, have long advised victims of extortion attacks against paying ransoms, as payments can encourage further criminal activity.
People who believe their information may have been compromised should report stolen documents such as passports, credit cards or driving licences to the relevant issuer. They should also monitor bank statements and credit reports, remain cautious about suspicious emails, messages and calls, and use strong passwords and multi-factor authentication.
Also read: Viksit Workforce for a Viksit Bharat
Do Follow: The Mainstream LinkedIn | The Mainstream Facebook | The Mainstream Youtube | The Mainstream Twitter
About us:
The Mainstream is a premier platform delivering the latest updates and informed perspectives across the technology business and cyber landscape. Built on research-driven, thought leadership and original intellectual property, The Mainstream also curates summits & conferences that convene decision makers to explore how technology reshapes industries and leadership. With a growing presence in India and globally across the Middle East, Africa, ASEAN, the USA, the UK and Australia, The Mainstream carries a vision to bring the latest happenings and insights to 8.2 billion people and to place technology at the centre of conversation for leaders navigating the future.


