8.7 Million UK airport customers hit by data theft: What stolen information could mean for air travellers

Manchester Airport departure lounge.

Manchester Airport departure lounge. Credit: Bardhok Ndoji - Shutterstock

Personal data belonging to around 8.7 million customers has been accessed and stolen from three major UK airports, raising fears that passengers could now face a new wave of highly convincing scams.

Manchester Airport, London Stansted and East Midlands Airport are all operated by Manchester Airports Group (MAG), which confirmed the security breach on Thursday, August 27.

Information obtained by an unauthorised third party includes email addresses, telephone numbers, vehicle registration numbers and postcodes. The data was linked to airport WiFi registrations, car park, lounge and Fast Track bookings.

MAG promised that bank and payment card information was not held on the affected system and has not been compromised. Passenger safety, aviation security and airport operations have also continued normally.

For British holidaymakers and others who regularly travel between the UK and Spain, however, the most worrying part may come after the airport journey has ended.

Why stolen airport data could be valuable to criminals

Most of the 8.7 million affected customers appear to have had only an email address accessed, according to reporting from The Register. A smaller number had additional information such as telephone numbers, postcodes or car registrations involved. An email address might sound harmless, but criminals can use it to send convincing phishing messages pretending to come from an airport, airline, parking company or travel provider.

Someone who knows that a traveller has used Manchester Airport parking, for example, could potentially send a message claiming that a parking payment has failed or that a booking needs attention.

Adding a genuine postcode, vehicle registration or telephone number could make such a message look considerably more authentic. National Cyber Security Centre guidance warns that criminals use personal information available about individuals to make phishing messages more convincing.

Your airport journey could become the scam

Imagine receiving a text shortly before a flight saying that your airport parking payment has failed. You might be more inclined to trust it if the message contains details that you genuinely provided when making your booking. A fraudster could then attempt to persuade you to click a link, enter your card details, reveal a password or provide further personal information.

That is why the absence of stolen banking information does not necessarily mean there is no financial risk. Criminals do not necessarily need your bank details if they can trick you into handing them over yourself.

MAG has warned customers to be particularly suspicious of unexpected emails, telephone calls and text messages claiming to come from the airport. The company says it will never unexpectedly ask customers for payment card details, banking information or passwords.

Vehicle registrations and postcodes add another layer

Vehicle registration numbers could also prove useful to scammers because they connect an individual with a particular car. Combined with an email address, phone number or postcode, such information can help criminals build a more detailed picture of a potential victim.

Risk can increase, however, when stolen information is combined with data from other breaches or publicly available information.

Brits travelling to Spain should take care

Many British residents in Spain regularly use Manchester, Stansted and other UK airports when visiting family or travelling elsewhere in Europe. Anyone who has used WiFi at one of the affected airports or booked parking, lounge or Fast Track services should therefore treat unexpected travel-related messages with caution. Avoid clicking links in unsolicited emails or texts, even when the message appears to contain genuine information about your journey. Instead, visit the airport or airline website by entering the address yourself or using an official app.

Despite the scale of the data breach, passengers are not facing a repeat of last year’s airport cyber chaos. Flights, parking and normal airport operations at Manchester, Stansted and East

What should affected airport customers do?

MAG is contacting affected customers, but passengers should remain cautious even if they have not yet received a warning. Check emails carefully for unusual links, unexpected payment requests or requests for passwords and banking information. Never assume a message is genuine simply because it contains your name, postcode, vehicle registration or details of a recent airport journey.

Anyone who believes they have fallen victim to a scam should contact their bank immediately if financial information has been shared and report the incident through the appropriate UK fraud-reporting channels. The National Cyber Security Centre provides guidance for people affected by data breaches and online scams.

Google News

Follow Euro Weekly News on Google News

Get breaking news from Spain, travel updates, and expat stories directly on your Google News feed.

Follow on Google News
Written by

Adam Woodward

Adam is a writer who has lived in Spain for over 25 years. With a background in English teaching and a passion for music, food, and the arts, he brings a rich personal perspective to his work at Euro Weekly News. As a father of three with deep roots in Spanish life, Adam writes engaging stories that explore culture, lifestyle, and the everyday experiences that shape communities across Spain.

Comments


    Leave a comment

    Your email address will not be published. Required fields are marked *