The personal data of around 8.7 million customers is believed to have been accessed in a cyber attack on Manchester Airports Group (MAG), which operates Manchester, London Stansted and East Midlands airports.
The compromised information is believed to include email addresses, phone numbers, postcodes and vehicle registrations — although no banking or payment details were affected, experts warn that stolen personal information can be used to make phishing and impersonation scams far more convincing.
Cyber experts at law firm Weightmans warn that the transport and logistics sector is a particularly attractive target for cyber criminals because of the particularly dangerous combination of interconnected suppliers, ageing technology and vast amounts of shared customer data.
Thomas Barrett, Partner at Weightmans, explains what this breach means for customers, why the sector is especially vulnerable, and what businesses can do to avoid becoming the next victim.
Why stolen data can still put customers at risk
Thankfully, the breach has not affected airport operations or passenger safety – but the impact may not end with the airports’ systems. Once personal information has been accessed, there’s a risk it could be used to target customers with more convincing scams, particularly where criminals can make messages appear relevant to services they have genuinely used.
Indeed, the more sophisticated cyber operators will intentionally seek to protect the source of their intelligence by ensuring their approach to victims is not directly connected.
So when Company A is hit by an attack, the information obtained from them might then be used to identify other companies relevant to the affected individuals which can then lead to scams involving the impersonation of those other companies to the individuals.
As a result, customers should watch out for any unexpected messages following the breach: details like email addresses, phone numbers and other personal information linked to airport services and specific usage information could potentially be used to make phishing attempts feel much more convincing.
For instance, if you’ve recently booked airport parking, an email or text that references that service and the dates you used it, this perhaps wouldn’t immediately raise alarm bells. Fraudsters rely on that familiarity to get individuals to lower their guard and overlook or ignore potential red flags such as slightly different email addresses and alike. .
To protect yourself from phishing, don’t click any links or share personal or payment details in response to unexpected messages. If you’re unsure whether a request is genuine, contact the sending organisation directly through other verifiable means, such as using the details on the official website for that organisation rather than those provided in the message.
Why airports are becoming prime cyber targets
There’s a reason cyber attackers are increasingly focusing attention on industries like transport, logistics, manufacturing and healthcare.
While sectors like financial services have invested heavily in cyber security, transport and logistics can be more vulnerable due to older systems and the sheer number of businesses, suppliers and customers they are connected with.
The scale and subject area spread of operations gives attackers more potential routes in, while simultaneously making the consequences of an attack harder to contain.
If a major transport or logistics business goes offline, the disruption doesn’t stop at its own doors: manufacturers can struggle to receive parts, retailers can face delayed stock and customers can be left dealing with delays or unavailable services.
The Jaguar Land Rover cyber attack in late 2025 demonstrated just how quickly disruption at one company can ripple through a wider network of suppliers and businesses. Similarly the recent Supermarket attacks have provided ample evidence that it can be those in the supply chain of the attacked business that bear the greatest pain in such circumstances, rather than the original business targeted.
With the sad truth being that the smaller individual supplier businesses can be driven out of business in days when the just-in-time supply chain breaks down.
How will the airport hack be investigated?
Attention will now turn to how the attackers gained access, exactly what information was compromised and whether the breach has been fully contained. Investigators will look at affected systems, access logs and possible points of entry, including whether any third-party suppliers or systems played a role.
Questions will be asked regarding whether appropriate security measures were in place, and whether relevant data protection obligations have been met. Businesses may be required to report certain personal data breaches to the Information Commissioner’s Office (ICO) and inform the affected individuals.
Depending on the outcome of those investigations there may be a need to deploy ongoing monitoring both to prevent any persistent access or renewed attacks as well as regards whether the information on the systems was merely accessed or extracted and potentially more widely shared (either now or at some later date)
Cyber lawyer urges customers and businesses to stay alert after breach
Thomas Barrett, Partner at Weightmans, says:
“This incident is yet another reminder of why cyber security needs to be treated as a standing and fundamental business risk rather than simply an IT issue after the fact, especially within the transport and logistics industries. Prevention is many times better than a cure, and often a cure is impossible and breaches can only be managed.
“These organisations are highly interconnected. They hold and exchange enormous amounts of relevant and valuable information with customers and third parties alike, so an incident can potentially have consequences well beyond the organisation initially compromised.
The uniquely cross-sector influence of transport and logistics businesses make them very attractive targets for Criminals as they can provide a stepping stone to a difficult to rival number of and kinds of other businesses.
“Businesses understandably invest significant technical resources in preventing cyber attacks — but many neglect to plan for what happens if those defences fail or provide similar investment in organisational measures and prevention.
Any well-prepared organisation should know who will make critical decisions, how the incident will be contained, which regulators or customers may need to be notified and how essential operations can be restored.
“Even the best systems can be undermined if someone is caught off guard by a convincing phishing email, phone call or fraudulent request, which is why staff awareness and training are just as important as technological solutions. Employees and customers alike must be wary of any unexpected requests for information or payment, especially in the aftermath of a major breach.
“As yet, we don’t know the full details of how the airport cyber attack happened, so questions around responsibility and accountability are unanswered. What we do know is that businesses recover best when they have a clear response plan already in place, rather than trying to establish roles and responsibilities while an attack is unfolding.”
Four steps businesses should take now
- Have a plan before something goes wrong. Businesses should know exactly who is responsible for making decisions during a cyber attack, how the incident will be managed and communicated as well as when customers or regulators need to be notified. Running practice scenarios can also help spot gaps before they become a real problem.
- Don’t forget about third-party suppliers. Your own systems might be secure, but businesses you work with can create additional vulnerabilities. Contracts should clearly set out cyber security and data protection responsibilities and points of emergency contact, as well as what happens if a key supplier is compromised or suddenly unable to operate.
- Know your regulatory responsibilities. A cyber attack can quickly become a legal and regulatory issue, particularly when customer or employee data is involved. Businesses should understand in advance what needs to be reported, to whom and how quickly.
- Make cyber security a leadership issue. Cyber attacks aren’t solely a problem for the IT department in the same way that Flood response isn’t just for the insurance manager
- . Senior leaders need to understand how the business is protecting itself, how it would keep operating during an attack and how it would handle customers, regulators and any wider legal consequences if an attack did occur.