Cybersecurity Alarm: Manchester Airports Group Faces Attack Risks

The Manchester Airports Group experienced a significant cyber attack, compromising data for 8.7 million customers across its three major airports, though no bank details were accessed. Experts warn of follow-on fraud risks, advising caution against unexpected communications and emphasizing personal cybersecurity measures like verifying callers and using credit cards for protection.
Pelumi Ilesanmi
Pelumi IlesanmiGlobal1 hour ago3 minute read
Cybersecurity Alarm: Manchester Airports Group Faces Attack Risks

In the evolving digital landscape, individuals face increased vulnerability to cybercrime and scams, often due to the constant sharing of personal information online. This reality was underscored recently when the Manchester Airports Group (MAG), which oversees major hubs like Manchester Airport, London Stansted, and East Midlands, disclosed a significant cyber security incident. This attack, identified on August 25 but believed to have occurred a few days prior, resulted in unauthorized access to data belonging to approximately 8.7 million customers.

The hackers specifically targeted data related to car park, lounge, and fast track bookings, as well as in-airport Wi-Fi sign-ups across all three affected airports. The compromised information included customers' email addresses, phone numbers, vehicle registrations, and postcodes. Notably, MAG reassured the public that for the "vast majority" of the affected 8.7 million customers, the breach was limited to email addresses, and critically, no bank or payment details were exposed. Customers whose data was affected were contacted directly, and MAG confirmed that upcoming bookings remained secure.

Following the breach, MAG issued a stern warning, advising customers to exercise extreme caution regarding unexpected emails, calls, or text messages purporting to be from them. The group explicitly stated, "We will never contact you unexpectedly to ask for payment or banking information." This proactive advice aims to mitigate the risk of follow-on fraud, a significant concern highlighted by cybersecurity experts.

Professor Daniel Dresner, Academic Lead for Cyber Security at the University of Manchester, elaborated on the risks stemming from such data breaches, particularly emphasizing the danger posed by compromised telephone numbers. He explained that beyond individual customer concerns, MAG itself faces challenges in managing the aftermath due to the vast amount of data they hold. Professor Dresner cautioned against MAG sending emails with "click on this link" prompts, as criminals often use similar tactics. Instead, he recommended encouraging customers to visit the legitimate MAG website, stressing the need for caution even when using search engines, which are not infallible.

Professor Dresner further advised individuals on how to protect themselves from potential follow-on fraud. He noted that the presence of personal details like names and phone numbers can lend an air of legitimacy to scam attempts, exploiting people's natural trusting nature. His "number one rule" is to avoid answering calls from unknown numbers, suggesting that important communications will typically go to voicemail. He pointed out that automated scam calls often ring for only a few seconds before moving on, and voicemails from scammers may be truncated or feature synthesized voices making urgent demands.

Beyond immediate scam prevention, Professor Dresner offered guidance for future financial security. He strongly recommended using credit cards for transactions, highlighting their inherent protections such as Section 75 of the Consumer Credit Act and the "air gap" they provide between a purchase and one's direct bank account. This separation offers a crucial buffer, allowing time to dispute fraudulent charges with the credit card company. Additionally, he suggested subscribing to a credit agency, some of which offer free services, to monitor for any unauthorized loan applications made in one's name.

Ultimately, Professor Dresner urged a balanced approach: "Be alert, but don’t be alarmed." He emphasized the importance of being prepared without succumbing to constant anxiety. Should someone unfortunately fall victim to a scam, he stressed that there is "no shame" in reporting it immediately. He clarified that victims are often targeted by "professional criminals" and should not feel guilt or hesitation in seeking help, as reporting is a crucial step in combating these illicit activities.

Loading...