Full Report
Manchester Airports group has been subject to a cyber security incident by an unauthorised third party. A quantity of customer data has been obtained that relates to car park, lounge and Fast Track bookings and in-airport WIFI sign-ups at Manchester, Stansted, and East Midlands airports. We immediately contained the risk and have been working with specialist advisors and taking appropriate steps to protect our customers and systems. We have informed and are working with the relevant authorities. At no point has passenger safety or aviation security been compromised. The incident has not resulted in any operational disruption. Airport operations remain unaffected and customer parking services continue to operate normally. Neither MAG nor the system accessed hold customers’ bank or payment details. The data that has been accessed includes customers’ email addresses, phone numbers, vehicle registrations and postcodes.
Analysis Summary
# Incident Report: Manchester Airports Group (MAG) Data Breach
## Executive Summary
Manchester Airports Group (MAG) experienced a cybersecurity incident involving unauthorized third-party access to a system containing customer service data. The breach resulted in the exfiltration of personal information belonging to customers who used parking, lounge, Fast Track, and Wi-Fi services at Manchester, Stansted, and East Midlands airports. MAG successfully contained the incident without impact to aviation safety or airport operations, and no financial data was compromised.
## Incident Details
- **Discovery Date:** August 27, 2024 (Based on statement date)
- **Incident Date:** Not explicitly disclosed; ongoing investigation
- **Affected Organization:** Manchester Airports Group (MAG)
- **Sector:** Aviation / Transportation
- **Geography:** United Kingdom (Manchester, Stansted, East Midlands)
## Timeline of Events
### Initial Access
- **Date/Time:** Not disclosed
- **Vector:** Unauthorized third-party access (Specific vector not disclosed)
- **Details:** Access was gained to a system holding ancillary service bookings and Wi-Fi registrations.
### Lateral Movement
- **Details:** Based on the report, the attack appears limited to specific customer-facing booking and Wi-Fi systems; no evidence of movement into operational or safety-critical aviation networks.
### Data Exfiltration/Impact
- **Details:** Unauthorized extraction of customer data including:
- Email addresses
- Phone numbers
- Vehicle registration numbers (VRNs)
- Postcodes
- Booking details (Parking, Lounge, Fast Track)
### Detection & Response
- **Discovery:** Identified by MAG internal security monitoring or notification.
- **Response Actions:** Immediate containment of the affected systems, engagement of third-party specialists, and notification of relevant law enforcement and data protection authorities.
## Attack Methodology
*Note: Specific technical details were not provided in the public statement. The following is inferred based on the impact.*
- **Initial Access:** Unauthorized third-party access (potentially via credential stuffing, vulnerability exploitation, or misconfigured API).
- **Collection:** Gathering of records from car park and lounge booking databases.
- **Exfiltration:** Transfer of customer PII (Personally Identifiable Information) to an external third-party environment.
- **Impact:** Data breach involving PII; no operational disruption (non-destructive).
## Impact Assessment
- **Financial:** No direct theft of funds; MAG is offering free cancellations/refunds for concerned customers. Potential future regulatory fines (ICO).
- **Data Breach:** Compromise of PII (Emails, phones, vehicle regs). **Note:** No bank or payment details were stored in the affected system.
- **Operational:** Zero. Airport operations, safety, and security remained unaffected.
- **Reputational:** Moderate; affects customers across three major UK airports.
## Indicators of Compromise
- **Network indicators:** [Not disclosed]
- **File indicators:** [Not disclosed]
- **Behavioral indicators:** Unauthorized access to booking databases; unusual data outbound traffic.
## Response Actions
- **Containment:** Restricted access to affected systems immediately upon discovery.
- **Eradication:** Engaged specialist advisors to purge unauthorized access and secure vulnerabilities.
- **Recovery:** Notified affected customers directly; established a refund/cancellation policy for worried travelers.
- **Compliance:** Working with the Information Commissioner's Office (ICO) and relevant authorities.
## Lessons Learned
- **System Segregation:** The effective isolation of the booking system from operational/aviation systems prevented a larger-scale crisis.
- **Data Minimization:** The practice of not storing payment details in this specific system significantly limited the severity of the breach.
- **Communication:** Prompt public disclosure and direct customer notification helped manage reputational risk.
## Recommendations
- **Audit Third-Party Integrations:** Review security posture of Wi-Fi and booking platforms.
- **Enhance Authentication:** Implement or strengthen Multi-Factor Authentication (MFA) for all administrative access to customer databases.
- **Encryption at Rest:** Ensure all PII, including vehicle registrations and phone numbers, are encrypted at rest to provide a secondary layer of defense.
- **Monitoring:** Implement enhanced database activity monitoring (DAM) to detect bulk data exports in real-time.