Manchester Airports Group confirmed this week that an unauthorised third party accessed data belonging to around 8.7 million customers across Manchester, Stansted, and East Midlands airports. The exposed information came from car park, lounge, and Fast Track bookings, along with sign-ups for in-airport WiFi, and included email addresses, phone numbers, vehicle registrations, and postcodes. Flight operations and passenger safety were not affected, and MAG says no bank or card details were accessed. The attackers reportedly demanded a ransom for the data’s return; MAG says it refused to pay.

It’s a useful, if uncomfortable, case study for any UK business that stores customer contact details, because the breach didn’t come through a dramatic flaw in flight systems or core infrastructure. It came through the kind of everyday customer-facing bookings — parking, WiFi sign-up, a lounge pass — that most businesses treat as low-risk, throwaway data. That’s exactly the assumption attackers are counting on.

Why “just contact details” still matters

It’s tempting to read “no financial data taken” as good news and move on. It isn’t, not fully. Email addresses, phone numbers, and postcodes tied to a real transaction are precisely the raw material for convincing follow-up phishing: a text that looks like it’s from the airport about a parking refund, an email referencing a real booking. Fraudsters don’t need your card number if they can use stolen contact data to trick you into handing it over directly. Any business notifying customers after a breach like this should expect, and warn people about, a second wave of scam attempts using the stolen details as bait.

What this means if you hold customer data

Audit what “low-risk” data you’re actually holding. Car park and WiFi sign-up forms rarely get the same security scrutiny as payment systems, yet they were the entry point here. If your business collects names, emails, or phone numbers through a booking widget, a guest WiFi portal, or a loyalty sign-up, that system deserves the same access controls and monitoring as anything handling money.

Have a ransom-refusal decision made before you need it, not during. MAG’s refusal to pay was reported as a considered decision, not a scramble. Whatever your business’s stance on ransom payment, deciding it now, with a clear head, on the basis of standard NCSC and Cifas guidance not to pay, is far better than deciding it under pressure with a deadline ticking.

Build the notification plan in alongside the incident response plan. UK GDPR requires notifying the ICO within 72 hours of becoming aware of a breach involving personal data, and affected individuals need to be told if the risk to them is high. That’s a tight window if nobody has already decided who signs the notification off and who drafts it. KeepSafe monitors for incidents like this and helps businesses put the reporting and customer communication plan in place before an attack happens, not after.

Brief customers on the follow-up scam risk, not just the breach itself. MAG’s own customers are now a more attractive phishing target than they were last week, purely because attackers have real booking references and contact details to make a fake message convincing. A short, plain-English notice, “we will never ask for payment details by text about this,” blunts a large share of the second-wave scam attempts before they start.

Third-party data counts too

Breaches like this rarely stay contained to the company named in the headline. Car park, WiFi, and lounge booking systems are frequently run by third-party suppliers on an airport’s behalf, meaning the actual point of failure may sit a step removed from the brand customers blame. Any UK business relying on a supplier to handle bookings or sign-ups should ask directly what data they hold and what their notification process looks like if something goes wrong on their end.

The takeaway

A breach doesn’t need to touch your bank systems to be serious, and a business’s “minor” customer databases are often exactly where attackers look first because they’re the least defended. If you haven’t checked who can access your booking, WiFi, or loyalty sign-up data recently, and how it’s monitored, this is the week to do it — before you’re the one drafting the notification email.