
Cyber attacks have put millions of travellers at risk. (Image: -)
Millions of holidaymakers are feared to have had their personal data exposed following a cyber-attack targeting Manchester Airport, London Stansted and East Midlands Airport. The summer holiday attack on airports saw hackers access the data of about 8.7 million customers.
The incident involved data related to “car park, lounge and fast-track bookings and in-airport Wi-Fi sign-ups”, and enabled the hackers to obtain email addresses, phone numbers, vehicle registration numbers and postcodes.
Now, cyber security expert Zain Javed has warned how the hackers might use the information gleaned for follow-up attacks that could drain their bank accounts.
He said: “What this incident really demonstrates is the scale of data that large organisations accumulate through everyday digital services, such as offering public Wi-Fi, can result in millions of customer records being retained over time.”
Javed, director of strategic growth and cyber services at Citation Cyber, said airports are attractive targets for cybercriminals because of the large number of people passing through, all keen to access Wi-Fi whilst waiting for their flight.
He added: “Any incident involving information relating to around 8.7 million customers is significant simply because of the scale involved.
“The biggest risk for customers is likely to be follow-on phishing and social engineering rather than someone immediately accessing their bank account.
“An email address, phone number, postcode or vehicle registration may not seem particularly sensitive individually, but attackers can combine pieces of information with information obtained elsewhere to make a scam much more convincing.
“For example, somebody could receive an email or text claiming there is an issue with airport parking, Fast Track, a lounge booking or a refund. If the message references an airport the customer has genuinely used, it immediately becomes more believable.
“That is where we increasingly see stolen data being exploited. The initial breach gives criminals information and context, and social engineering is then used to persuade the victim to provide the information the attacker doesn’t already have.”

Hackers attacked Manchester, Gatwick and East Midlands airports (Image: Getty Images)
Manchester Airports Group (MAG), which operates the three hubs, insist that “at no point was passenger safety or aviation security compromised” during the incident and said operations at the airports were unaffected. The hacked system did not hold customers’ bank or payment details.
The security expert, however, says affected customers should be particularly cautious about receiving unexpected emails, calls or text messages claiming to relate to an airport booking, parking, Wi-Fi or a refund.
They should also avoid clicking links in unexpected messages and instead go directly to the airport’s official website or app.
It is also crucial never to provide passwords, banking information, or payment card details in response to an unexpected request. Messages might also attempt to create urgency, such as claiming a booking might be cancelled unless immediate action is taken.
Javed added: “If the same password used with an airport-related account has been reused elsewhere, change it and use unique passwords for different services.
“MAG has also made clear that it will not unexpectedly contact customers asking for banking details, payment information or passwords, which is useful guidance for customers when assessing whether a communication is genuine.”

Manchester Airport. (Image: MEN MEDIA)
Why airports and critical infrastructure are attractive targets
Javed said: “Airports are part of a much wider critical transport ecosystem and are highly visible organisations that depend heavily on technology. They operate complex environments involving passenger-facing systems, suppliers, airlines, retailers, operational technology, booking platforms, parking, Wi-Fi and a large number of third-party services. That complexity naturally creates a large digital footprint.
“For an attacker, organisations of this scale can also hold significant volumes of information and have a strong public profile. Depending on the attacker’s motivation, they may be motivated by financial gain, data theft, extortion, or, in some circumstances, disruption.
“However, it is important to distinguish between an attack involving customer-facing systems and an attack against operational aviation infrastructure. In this case, MAG has been clear that aviation security, passenger safety and airport operations were not compromised. The fact that those operational environments remained unaffected is an important distinction.”

Gatwick Airport, aircraft and control tower, from Norwood Hill. (Image: Surrey Advertiser – Grahame Larter)
What organisations can learn from incidents like this
“One of the biggest lessons is that organisations need to think beyond what they traditionally consider to be their most sensitive systems,” Javed revealed.
“Cyber security teams naturally focus heavily on payment systems, corporate networks and business-critical infrastructure, but organisations can also accumulate millions of records through services such as Wi-Fi registrations, marketing systems, customer portals and booking platforms.
“Businesses should regularly ask themselves: what information are we collecting, why are we keeping it, how long do we actually need it, and what would happen if somebody gained access to it?
“There are several areas organisations should continually review, including reducing unnecessary data retention, understanding where customer information is stored, assessing third-party and supplier risk, applying appropriate access controls and multi-factor authentication, maintaining effective monitoring and regularly testing their security.
“Organisations should also have a rehearsed incident response plan. It is impossible to reduce cyber risk to zero, particularly for large organisations with complex technology estates. The difference is often how quickly an organisation can identify an incident, contain it, understand what has been affected and communicate clearly with customers and the relevant authorities.
“Cyber resilience is therefore not simply about preventing every attack. It is also about making sure that when something does happen, the organisation is able to respond quickly and prevent a cyber incident from becoming an operational crisis.”
Leave a comment