Three Major UK Airports Hit by Cyberattack Affecting 9 Million People

Flight operations suspended to and from Pak until May 10

LONDON : A major cyberattack has compromised the personal data of approximately 8.7 million passengers across three of the UK’s busiest airports, with hackers now demanding a ransom for the stolen information.

 

Manchester Airports Group (MAG), which operates Manchester, London Stansted, and East Midlands airports, confirmed that unauthorised individuals gained access to customer contact details, vehicle registrations, and postcodes over the weekend.

 

The attack targeted the airports’ free Wi-Fi registration system, according to the company. The vast majority of compromised data consists solely of email addresses that passengers provided to access internet services while travelling through the terminals.

 

MAG confirmed to the BBC that a ransom demand had been issued by the hackers, though the company has refused to pay and has not disclosed the amount requested.

 

In a statement, the group emphasised that passenger safety and aviation security were never compromised during the incident. The company also confirmed that the breached system did not contain any customer bank account details, payment information, or passport data.

 

“We are working closely with the National Cyber Security Centre and law enforcement agencies to investigate the incident and mitigate any potential impact,” a MAG spokesperson said.

 

The affected airports serve millions of passengers annually, with Manchester handling approximately 30 million travellers, Stansted around 28 million, and East Midlands serving about 5 million before the pandemic.

 

Security experts have warned passengers to remain vigilant against potential phishing attempts following the breach, as hackers may use the stolen email addresses to target individuals with fraudulent communications.

 

MAG has begun notifying affected customers directly and has advised passengers who used airport Wi-Fi services to be cautious of unsolicited emails requesting personal or financial information.

 

The incident highlights growing concerns over cybersecurity vulnerabilities in critical transport infrastructure, as airports increasingly rely on digital systems to manage passenger services and operations.

 

The investigation remains ongoing, and authorities have not yet identified the perpetrators or their origin.

Scroll to Top