
Criminal hackers have published the personal information of nearly nine million individuals online following a breach of three United Kingdom airports. The cyber-crime group, which the BBC is not naming, released the data after failing to secure a ransom payment from Manchester Airports Group. The stolen records cover customers of Manchester, London Stansted and East Midlands airports, leaving them vulnerable to secondary attacks by other malicious actors.
The breach appears to have accessed databases containing Wi-Fi login credentials and car parking details. Stolen information includes contact details, vehicle registrations, postcodes, email addresses, phone numbers, physical addresses, licence plate numbers, purchasing history and browsing device data. Experts at HaveIBeenPwned have analysed the published material and confirmed the presence of this personally identifiable information. The hackers are offering the entire data set for free to other criminals and scammers through their website, describing the half-terabyte file as pure personally identifiable information.
Cyber-security expert Kevin Beaumont has warned affected individuals to remain on high alert for further scams and hacking attempts. He noted that the data includes both historical locations and planned future travel, meaning those sensitive to their movements being known may need to take precautions. Beaumont added that people should be alert to scammers reusing the data, particularly those who know details such as phone numbers and car registration numbers. He specifically advised high-profile or wealthy individuals to be especially cautious.
Manchester Airports Group stated that it is confident effective measures have been taken to protect customers. The company said it has contacted all affected parties, including those with upcoming bookings, to advise them of additional support. MAG is working with authorities and specialist advisors and confirmed that passengers’ physical safety has not been at risk within the airports. Law enforcement organisations, including the UK’s National Crime Agency, have long advised victims of extortion attacks not to pay criminal ransoms, as doing so fuels the hacker ecosystem.
Unusually, the website hosting the stolen data is located on the clear internet rather than the dark net. This makes the information easier to access, thereby increasing the risk to victims of MAG and other companies the gang has breached in recent months. The hackers boasted about breaching each victim using the same method, which involved exploiting weaknesses in how companies store digital keys for internal networks. The Information Commissioner’s Office has provided advice for those whose data has been hacked, recommending users report stolen documents, check bank statements for unusual activity, remain alert for suspicious communications and use strong passwords with multi-factor authentication.
The following content has been published by Stockmark.IT. All information utilised in the creation of this communication has been gathered from publicly available sources that we consider reliable. Nevertheless, we cannot guarantee the accuracy or completeness of this communication.
This communication is intended solely for informational purposes and should not be construed as an offer, recommendation, solicitation, inducement, or invitation by or on behalf of the Company or any affiliates to engage in any investment activities. The opinions and views expressed by the authors are their own and do not necessarily reflect those of the Company, its affiliates, or any other third party.
The services and products mentioned in this communication may not be suitable for all recipients, by continuing to read this website and its content you agree to the terms of this disclaimer.