MAG Airports Data Breach Hits Car Park and WiFi Bookings

Data breach impacts car park and WiFi bookings at MAG airports

The recent MAG airports data breach has affected car park and WiFi booking systems at three major UK airports. This incident puts customer data at risk and raises questions about the security of third-party integrations in critical infrastructure.

Details of the MAG Airports Data Breach

Manchester Airports Group (MAG) confirmed a data breach impacting the car park and WiFi booking systems at Manchester, London Stansted and East Midlands airports. The breach was disclosed in early June 2024, after suspicious activity was detected within the systems that manage both car park and WiFi bookings for travellers.

The breach specifically targeted systems that handle personal data for customers using online bookings and public WiFi services. These systems are integral to the customer experience at all three airports, being used daily by thousands of passengers and visitors.

  • When did it happen? The incident was identified and reported in the first week of June 2024.
  • Which airports are affected? Manchester Airport, London Stansted Airport and East Midlands Airport.
  • Which systems are involved? Car park online booking platforms and public WiFi booking systems.
  • What customer data is at risk? While MAG has not confirmed the full extent, data at risk likely includes names, email addresses, vehicle registration details and potentially contact information used for WiFi access.

The precise number of affected customers has not been disclosed, but the breadth of the breach means that anyone who has recently made a car park booking or accessed WiFi at any of the three airports may be at risk.

How the Breach Occurred: Attack Methodology and Impact

Initial investigations by MAG suggest the breach involved unauthorised access to third-party systems that underpin both car park and WiFi bookings. It is believed that attackers exploited a vulnerability in the integration layer between MAG’s main customer portals and the external providers responsible for managing these services.

The attack likely occurred via compromised credentials or an unpatched vulnerability in application interfaces (APIs) that connect the airport’s front-end systems with the third-party booking and authentication platforms. Once inside, attackers could access records stored in these systems, including customer booking details and login information used to sign up for WiFi services.

The timeline is as follows:

  • Early June 2024: Suspicious activity detected by MAG’s IT security team.
  • Immediate containment steps taken, including isolating affected systems and notifying third-party service providers.
  • Data breach publicly disclosed by MAG after preliminary investigation.
  • Ongoing investigation to determine scope and nature of data exposed.

At this time, there is no public evidence that financial information such as payment card details was accessed. However, the risk to personal data remains significant, particularly for those who reused credentials across different services.

Current Exploitation Status

MAG has stated that affected systems have been isolated and that further malicious activity has not been detected since the initial containment. Law enforcement and the Information Commissioner’s Office (ICO) have been notified, and customers will be informed if their data was specifically compromised. Security experts continue to monitor for signs of the exposed data appearing on cybercriminal forums or being used in phishing campaigns.

Who Is Affected by the MAG Airports Data Breach?

Anyone who made a car park booking or accessed public WiFi at Manchester, Stansted or East Midlands airports in the weeks prior to early June 2024 could be affected. This includes:

  • Travellers and airport visitors who pre-booked parking online
  • Passengers who logged in to airport-provided WiFi using their personal information
  • Staff and contractors using the same public systems for access

The breach demonstrates the risks that arise when critical infrastructure providers rely on third-party platforms for essential services. Integrations between internal and external systems can become a weak point if not thoroughly secured and monitored.

Why This Data Breach Matters

The MAG airports data breach is significant because it highlights the vulnerabilities in public-facing systems at major UK transport hubs. Airports are increasingly digitising services to streamline customer journeys, but this incident shows that third-party integrations can introduce new attack vectors. The potential exposure of personal data also increases the risk of identity theft and targeted phishing attacks against affected individuals.

What Should Organisations Do Now?

For organisations operating with third-party technology partners, this breach underscores the importance of:

  • Rigorously vetting third-party security controls and integration points
  • Monitoring for unusual activity across all customer-facing systems
  • Promptly disclosing data breaches and keeping affected users informed

MAG’s swift action to isolate affected systems and notify authorities sets a positive example for incident response, but ongoing vigilance will be crucial as investigations continue.

Originally reported by Unknown.

Share this bulletin

About the Author

Headshot of Jonny Pelter, leading cyber security expert in the UK and CISO

Jonny Pelter

Partner

  • CIPM
  • CIPP/E
  • CISSP
  • CISM
  • CRISC
  • ISO27001
  • Prince2
  • MSc
  • BSc

Jonny Pelter

Jonny is a Founding Partner at CyPro and executive group level CISO who has worked closely with the British intelligence agencies NCSC and GCHQ.

An ex-professional rugby player and originating from KPMG and Deloitte, Jonny has a wealth of experience across numerous sectors including technology, critical national infrastructure, financial services, oil & gas, insurance, betting, pharmaceuticals and utilities.

Jonny is a leading cyber security expert in the UK, having featured on national media for his professional commentary such as BBC News, iPlayer, Telegraph and Times Radio.

View Profile
Back to Bulletins

Related CyPro Services

  • Managed Detection and Response (MDR)

    Managed Detection and Response (MDR) is an end-to-end managed service designed to help organisations detect, analyse and respond to cyber threats quickly and effectively. It...
    View Service
CyPro Cookie Consent

Hmmm cookies...

Our delicious cookies make your experience smooth and secure.

Privacy PolicyOkay, got it!

We use cookies to enhance your experience, analyse site traffic, and for marketing purposes. For more information on how we handle your personal data, please see our Privacy Policy.

Schedule a Call