Nearly nine million people have been impacted by the data breach
On Tuesday, the 25th August, something happened at MAG, the operator behind Manchester, Stansted and East Midlands airports. The how and the why aren’t known, and likely won’t be shared publicly for a while. What we do know is that personal information was accessed at a grand scale. This is among the top five biggest data leaks in the UK. MAG made individuals aware of the incident two days later.
Updated with additional information
What does all of this mean?
MAG’s statements to the press and its email to customers were typical of early-stage communications about cybersecurity incidents. The wording is based on what they have to tell you and what they want to tell you, which is usually as little as possible. It also contains a number of positive statements that could be read as an attempt to paint a better picture. They also may not know that much about the incident; it is very much in play, and learnings are happening in real time.
An incident of this scale will mean that experts are brought in. These will be cybersecurity and IT experts, but alongside them will be individuals who help manage communications and the legal side. Even large businesses do not have the in-house resource or experience to handle these incidents effectively, especially on the legal, and subsequently the comms, side.
As is often the case, there is often a desire to soften the blow as much as possible. By saying things like “Your payment details are safe”, it can allay any fears that credit or debit card numbers have been accessed, but it also creates an impression that this is not as big an issue as it could have been. This is, in fact, a huge issue with significant ramifications for millions of people.
What data was accessed?
They have said that the following information has been accessed by a third party.
- Email addresses
- Phone numbers
- Vehicle registrations
- Postcodes
The wording “accessed” is a blanket term that can mean temporarily viewed or alternatively accessed and copied. In most nefarious cybersecurity incidents, it’s the latter that really occurs. That means your data hasn’t just been viewed, it has been taken away. At that point, the original holder of the data has lost control over who will access that in the future, and what it will be used for.
The near 9 million customers who had their data accessed will have engaged with one or more of the following four services:
- You entered your details to use the Wifi at one of MAG’s airports
- You paid to park your car at Manchester Airport
- You paid to use a MAG lounge
- You paid to use fast track at MAG
What’s unclear is whether data collected during the drop-off payment process was part of this, and whether this affects all the lounges MAG/CAVU operates, including many in the US.
Also unclear is whether the hackers had information on the bookings themselves. If a third party knew your postcode, your car registration AND that you booked a lounge on a particular date, that may leave you more open to theft or burglary. If you really want to know what information MAG has on you, I talk about Subject Access Requests below.
Update: MAG have confirmed that the “majority of the data accessed was restricted to customer email addresses and related to WiFi sign-ups within the airports’ terminals”.

Why Wifi?
The most frustrating part of this incident is that you had to enter your details to use the airport’s Wi-Fi. It is wholly unnecessary, and it was asked for for marketing purposes. It feels galling that you had to use the wifi (the mobile signal at MAN can be especially bad), and in some cases you had to hand your details over to get a connection. I really hope that they change this so that everyone can simply use the wifi for free, without having to enter their details.
Where will all that personal data end up?
In some cases, the data is held to ransom: pay us or we release your data. This is usually the preferred outcome if data has been exfiltrated by a bad actor, because it means they monetise the hack quickly. If no money is paid, then the data will likely be sold on to other bad actors. Insurance can cover these payments in some extreme cases, usually when the hack has disabled critical systems.
It is also entirely possible that the data was taken not for immediate monetisation, but in an attempt to scam individuals. It has been reported by some people who have already received scam-like phone calls, but it isn’t possible to connect them to the MAG breach. They may just be random, scammy calls that just so happen to take place at the point of the incident.
Update: MAG have publicly confirmed that the hackers requested funds to return/delete the data. The airport confirmed it refused to pay this.
What can you do?
There are some really important steps to take if you have had an email from MAG confirming that your data was accessed. The first one is to be extra vigilant when it comes to phone calls and emails. Pay close attention to emails, particularly the email address of the sender. Look for obvious typos, or anything that doesn’t feel right. If you have any doubts about an email, ignore it and reach out to the company it claims to be from. The NCSC has excellent advice which is far more detailed than this paragraph. I would advise you to read that.
You can also submit a Subject Access Request to MAG to find out what information they hold about you. Under GDPR and the 2018 Data Protection Act they are legally required to respond. They must respond to you within thirty days, and there is no charge for this.
A SAR is simple to request. Send an email to dpo@magairports.com with the subject of “Subject Access Request (UK GDPR) – [Your Full Name]” and use the template below.
Dear Data Protection Officer,Please supply the personal data that you hold about me under the UK General Data Protection Regulation (UK GDPR) and Data Protection Act 2018.My Details:⚬ Full Name: [Your Name]⚬ Date of Birth: [Your DOB]⚬ Email Address associated with account/bookings: [Your Email]⚬ Contact Phone Number: [Your Phone Number]In light of recent security incidents regarding Manchester Airport's systems, I specifically request:1. A copy of all personal details, contact information, financial records, and booking logs associated with my identity.2. Confirmation as to whether my personal data was impacted, accessed, or exfiltrated during the recent cybersecurity breach.3. Details of any third parties with whom my data has been shared.As per UK GDPR guidelines, I look forward to receiving your response within one calendar month.Yours sincerely,SAR’s have to be taken very seriously, as being in breach of the legislation is a significant failing. If they fail to respond within thirty days, you can lodge a formal complaint with the ICO. You can do so at this link.
I have worked with businesses that get a high volume of SAR requests. They prioritise them and commit significant resources to ensuring they abide by the legislation. This is not the same as sending a complaint to MAG’s customer services team. They cannot ignore the request.
What will happen to MAG?
There is no doubt that the group will be in a world of pain right now. These types of incidents will suck in staff members at every level, and in a good organisation, the C-suite and key stakeholders will be very present in the process. This is not the same as some luggage going missing, or the soft drinks running out in one of the lounges. For the initial days after a breach of this scale, it will be a twenty-four-hour operation. It will be horrible for all involved.
MAG have already reported this to the ICO, as is required. The ICO tends to take a sensible view around breaches, but for one of this scale they will be much more involved. They will assess whether the group handled communication properly around the breach. They will also look at the cause. This is the key area they assess. Ultimately, they will consider whether this was due to significant failings, that is, technical negligence, prior knowledge that something like this could happen, or failure to act on warnings.
Training can also play into this, and it is critically important that cybersecurity training takes place in any organisation. I can’t comment on how this incident took place, but I was involved with an organisation that lost tens of thousands of pounds due to a single employee clicking a link in an email, and then entering their login details. That email was from a hacker, and they used those login details to breach the company’s systems. The irony was that it occurred shortly after the employee had received cybersecurity training, but from a governance perspective, the company had done the right thing.
The scale of the incident does impact what happens next. It is one of the five biggest data breaches in the UK. Whilst no payment information was accessed, email addresses, car registration numbers and postcodes do fall into the category of PII. They can expose individuals to scams, and offline acts such as theft. The lack of payment detail exposure does not make this any less important in the eyes of the ICO.
Where common sense comes in is the reality that no business is hack-proof. The big question is whether MAG was the unfortunate victim of an attack by experienced and capable hackers, or if the exploit was, or should have been, known.



Add a comment