Manchester Airport hackers demand ransom after data breach
Manchester Airport hackers demand ransom after data breach

Criminal hackers who targeted Manchester Airport have demanded a ransom, it has been confirmed. The ransom for the return of the accessed data is understood to be monetary in nature, although no exact sum has been revealed. Manchester Airports Group (MAG) is understood to have refused to pay, with advice being taken from the relevant authorities.

The group behind the attack is known to MAG and the authorities but has not been named publicly. The Manchester Evening News understands the same known group has been behind other similar cyber attacks this year against different industries across the world.

Millions of customers affected

Millions of airport customers were informed of the hack by MAG on Thursday (August 27), with up to 8.7 million people believed to be implicated. The company operates Manchester Airport, London Stansted and East Midlands Airport.

Wide Pickt banner — collaborative shopping lists app for Telegram, phone mockup with grocery list

The hackers accessed data relating to car park, lounge and fast track bookings and in-airport WIFI sign-ups for all three airports. The data included people's email addresses, phone numbers, vehicle registrations and postcodes.

Safety not compromised

The group said 'at no point has passenger safety or aviation security been compromised' during the incident, and neither MAG nor the system hacked held customers' bank or payment details. In the vast majority of cases, the data accessed is restricted to just the customer's email address.

A MAG spokesperson said: "Manchester Airports group has been subject to a cyber security incident by an unauthorised third party. A quantity of customer data has been obtained that relates to car park, lounge and Fast Track bookings and in-airport WIFI sign-ups at Manchester, Stansted and East Midlands airports.

"We immediately contained the risk and have been working with specialist advisors and taking appropriate steps to protect our customers and systems. We have informed and are working with the relevant authorities. At no point has passenger safety or aviation security been compromised."

No operational disruption

The incident has not resulted in any operational disruption. Airport operations remain unaffected and customer parking services continue to operate normally.

In its email to customers, MAG said: "We're contacting you about a recent cyber security incident involving customer data. Our investigation has identified that some of your personal information relating to airport car parking, lounge, Fast Track bookings and on-airport WIFI sign-ups has been accessed by an unauthorised third party. Neither MAG nor the system accessed hold customers' bank or payment details.

"We took immediate action to secure the affected system and are working with cyber security specialists and the relevant authorities. We would like to reassure you that Manchester Airports Group takes the security of customer information extremely seriously and we are taking appropriate actions to manage the incident.

"There is no action you need to take. We would urge you to be particularly cautious of unexpected emails, calls or text messages claiming to be from us. We will never contact you unexpectedly to ask for payment or banking information."

Pickt after-article banner — collaborative shopping lists app with family illustration