OwnGlobal
Technology

Cyberattack hits three UK airports, exposing data of 8.7 million customers

Cyberattack hits three UK airports, exposing data of 8.7 million customers

Scope of the Data Breach

Manchester, Stansted and East Midlands airports were struck by a cyber‑attack that accessed personal details of 8.7 million customers, primarily from wifi registration records, according to the operator. The breach was discovered in early 2025 and raises concerns about data security across the aviation sector, and prompted immediate investigations by authorities.

Most of the compromised records concerned wifi sign‑up details collected at the terminals of Manchester, Stansted and East Midlands airports. The operator managing the three hubs confirmed that the breach involved personal information of 8.7 million individuals. It added that security protocols appeared to be weakened, allowing the intrusion.

Manchester, Stansted and East Midlands airports were hit by a cyber‑attack that accessed personal details of 8.7 million customers, mainly from wifi registration records. The operator managing the three hubs said the incident compromised security and that investigations were under way. The compromised data included names, email addresses and device identifiers linked to the wifi service.

How Did the Attack Succeed?

No payment card numbers or passport details were reported stolen, but the exposure of personal identifiers could enable phishing or identity theft attempts.

Investigators believe the attackers exploited vulnerabilities in the wifi sign‑up portals, which stored user information in unencrypted databases. The breach was discovered in early 2025 after anomalous traffic patterns were detected across the three sites. Experts say the weak authentication process allowed the attackers to harvest the records without needing admin credentials.

The incident could trigger stricter data protection scrutiny from UK regulators and may lead to significant fines under GDPR. Travelers may become more cautious about using airport wifi, prompting airlines and airport operators to overhaul their cybersecurity frameworks. Regulators are expected to review compliance and may impose penalties that could run into millions of pounds. Airlines are likely to invest in stronger encryption and multi‑factor authentication for passenger data.

Frequently Asked Questions

What personal data was compromised in the breach? Names, email addresses and device identifiers linked to wifi sign‑up records were exposed. The data did not include payment details or passport numbers.

When was the breach discovered? The breach was identified in early 2025 after unusual activity was noticed across the airports. Investigators are reviewing the incident to determine how the attackers gained access.

What measures is the operator taking to prevent future attacks? The operator is reviewing its security architecture and strengthening encryption of customer data. It is also cooperating with law‑enforcement agencies to prevent future attacks.

Content written by Sarah Mitchell for OwnGlobal editorial team, AI-assisted.

Comments (0)