Manchester Airports Group (MAG) has suffered a major cyber hack, with around 8.7 million customers' data accessed. The group, which operates Manchester Airport, London Stansted and East Midlands, was made aware of the cyber security incident on Tuesday (August 25). It is believed to have happened a few days earlier.
What data was accessed
Hackers accessed data relating to car park, lounge and fast track bookings and in-airport WIFI sign-ups for all three airports. The data included people's email addresses, phone numbers, vehicle registrations and postcodes.
A spokesperson for the MAG group said the data hack is restricted to email addresses for the 'vast majority' of the 8.9 million customers affected. The security incident did not reveal any bank details.
Customers notified by email
Customers affected by the hack have been sent an email. In full, the email states: "We're contacting you about a recent cyber security incident involving customer data."
"Our investigation has identified that some of your personal information relating to airport car parking, lounge, Fast Track bookings and on-airport WIFI sign-ups has been accessed by an unauthorised third party. Neither MAG nor the system accessed hold customers' bank or payment details."
"The data that has been accessed includes customers' email addresses, phone numbers, vehicle registrations and postcodes. We took immediate action to secure the affected system and are working with cyber security specialists and the relevant authorities."
"We would like to reassure you that Manchester Airport Group takes the security of customer information extremely seriously and we are taking appropriate actions to manage the incident. There is no action you need to take."
"We would urge you to be particularly cautious of unexpected emails, calls or text messages claiming to be from us. We will never contact you unexpectedly to ask for payment or banking information. We apologise for any inconvenience or concern this may cause."
Immediate containment
People have been told they do not need to take any action and should 'remain vigilant as normal for unsolicited emails and texts'. MAG stressed that it will never contact customers unexpectedly to request money.
All upcoming bookings remain valid and are unaffected by the incident. In a statement, a MAG spokesperson said: "Manchester Airports group has been subject to a cyber security incident by an unauthorised third party."
"A quantity of customer data has been obtained that relates to car park, lounge and Fast Track bookings and in-airport WIFI sign-ups at Manchester, Stansted and East Midlands airports. We immediately contained the risk and have been working with specialist advisors and taking appropriate steps to protect our customers and systems."
"We have informed and are working with the relevant authorities. At no point has passenger safety or aviation security been compromised. The incident has not resulted in any operational disruption. Airport operations remain unaffected and customer parking services continue to operate normally."
"Neither MAG nor the system accessed hold customers' bank or payment details. The data that has been accessed includes customers' email addresses, phone numbers, vehicle registrations and postcodes."
"We would like to reassure customers that Manchester Airport Group takes the security of customer information extremely seriously and we apologise for any inconvenience or concern caused."



