Company that runs Manchester, Stansted and East Midlands hubs says passenger safety is unaffected
Manchester, London Stansted and East Midlands airports have been hit by a cyber-attack in which hackers accessed the data of about 8.7 million customers.
The incident involved data related to “car park, lounge and fast-track bookings and in-airport wifi sign-ups”, and the hackers obtained email addresses, phone numbers, vehicle registration numbers and postcodes, said Manchester Airports Group (MAG), which operates the three hubs.
The company said that “at no point has passenger safety or aviation security been compromised” during the incident and operations at the airports were unaffected. The hacked system did not hold customers’ bank or payment details.
In an email to customers, London Stansted said: “We would urge you to be particularly cautious of unexpected emails, calls or text messages claiming to be from us. We will never contact you unexpectedly to ask for payment or banking information. We apologise for any inconvenience or concern this may cause.”
The cyber-attack hit the airports during the peak summer travel season. Many families are flying back into the UK this week before the start of the new school year. Fifty-four million passengers flew through Manchester, London Stansted and East Midlands airports combined last year.
A MAG spokesperson said the company had “immediately contained the risk” from the incident and was “working with specialist advisers and taking appropriate steps to protect our customers and systems”.
“We have informed and are working with the relevant authorities. At no point has passenger safety or aviation security been compromised,” they said. “Airport operations remain unaffected and customer parking services continue to operate normally.
“We would like to reassure customers that Manchester Airport Group takes the security of customer information extremely seriously and we apologise for any inconvenience or concern caused.”
Lauren Wills-Dixon, a partner at the law firm Gordons, said the scale of the attack was notable.
“Airports sell a number of services including lounge access, parking and fast-track bookings. Wi-fi access also requires customers to input their data,” she said. “As a result, operators will hold large amounts of customer data and this, together with the increased use of technology, only increases the threat of a cyber-attack.”
The incident comes as pressure grows on suppliers and operators of national infrastructure to improve their cyber-defences.
Flights were delayed and cancelled last year at three major European airports – including London’s largest, Heathrow – after the company behind the software used for check-in and boarding said it had been hit by a cyber-attack.
Hackers linked to Iran were blamed earlier this month for a cyber-attack that caused the temporary shutdown of a British power plant. The government said the incident involved a small-scale generator and that at no point was there a risk to the wider energy system.
There was a wave of high-profile cyber-attacks against British companies last year, ranging from one that shut down the operations of Jaguar Land Rover for weeks to others targeting Marks & Spencer, Harrods and the Co-op food chain.


