Cyberattack Hits Three Major UK Airports, Personal Data of 8.7 Million People Published Online

Rinky Rai
By Rinky Rai - A freelance journalist
3 Min Read

Personal data belonging to approximately 8.7 million people has been published online following a major cyberattack targeting three leading airports in the United Kingdom. Cybercriminals breached the systems of Manchester Airports Group, which operates Manchester Airport, London Stansted Airport, and East Midlands Airport, and demanded an undisclosed ransom. After the demands went unpaid, the perpetrators uploaded the stolen records to their website for free access by third parties and scammers. The airport operator said it has implemented protection measures, initiated contact with affected travellers, and reached out to passengers with future bookings to offer security guidance.

Half a Terabyte of Customer Information Exposed

​The compromised records encompass contact details, vehicle registration numbers, postcodes, and databases linked to airport Wi-Fi logins and car parking reservations. An analysis conducted by breach-tracking platform Have I Been Pwned confirmed that the leaked material contains email addresses, telephone numbers, residential addresses, vehicle plates, purchasing records, and device-browsing data. The cybercrime group, which has not been named by the BBC, claimed the repository holds around half a terabyte of purely personally identifiable information. Rather than confining the repository to the dark web, the hackers hosted the files on the open internet, significantly broadening access for secondary exploitation by opportunistic criminals.

Travel Schedules and Targeting Concerns Raised by Specialists

​Cybersecurity specialists have warned that the exposed material creates serious risks extending beyond standard fraud and spam. Security expert Kevin Beaumont noted that the archive details historical locations as well as planned future travel, which could present distinct safety risks for individuals whose physical movements require confidentiality. Beaumont also cautioned that threat actors could weaponise verified phone numbers, vehicle registrations, and personal profiles to craft highly convincing social engineering lures. The attackers claimed they compromised multiple organisations using the same method, pointing to alleged lapses in how companies manage and store digital network access keys.

Law Enforcement Stance on Ransom and Consumer Precautions

​Manchester Airports Group confirmed it is collaborating with law enforcement bodies and specialised consultants to investigate the breach, emphasising that physical safety at the three aviation hubs was never compromised. The National Crime Agency and other British policing bodies maintain a firm policy advising victims against paying ransoms, maintaining that compliance finances criminal infrastructure and drives repeated extortion campaigns. Security experts advise affected customers to monitor financial records, activate multi-factor authentication, set unique passwords, avoid sharing credentials with unverified contacts, and alert relevant issuers immediately if government identity cards, driving licences, or credit cards have been compromised.

Stay Connected