Jessica Entwistle
August 28 2026
Infosecurity Magazine reports that Manchester Airports Group has confirmed a cyber incident in which customer data linked to bookings and airport Wi-Fi registrations at Manchester, Stansted and East Midlands airports has been accessed by an unauthorised third party. The breach affects personal information provided by customers when making bookings or registering for Wi-Fi services at the three airports. Manchester Airports Group has not disclosed the scale of the breach, the nature of the attack, or how long the unauthorised access persisted. The organisation has notified affected customers and is working with the Information Commissioner's Office and law enforcement. The incident is a reminder that customer-facing services, including Wi-Fi portals and booking systems, are attractive targets for attackers seeking personal data.
This highlights the operational risk associated with customer data held in ancillary systems that may not receive the same security attention as core business applications. Airport Wi-Fi registration systems and booking platforms often collect names, email addresses, phone numbers and payment information, and they are frequently managed by third-party suppliers or sit outside the main IT estate. When these systems are compromised, organisations face regulatory reporting obligations under GDPR, reputational damage, and the operational burden of notifying potentially large numbers of customers. The challenge is that many organisations do not have full visibility of where customer data is stored, who has access to it, or how well it is protected. Customer-facing systems are often deployed quickly to meet business needs, and security considerations can be secondary to functionality and user experience.
Organisations should audit where customer data is held across their environment, including in booking systems, CRM platforms, Wi-Fi portals, loyalty programmes and other customer-facing services. Review whether these systems are included in your security monitoring, whether access is appropriately restricted, and whether you have a clear understanding of what data is collected, how long it is retained, and who has access to it. Consider whether third-party suppliers are involved in managing these systems and whether their security practices have been assessed. This is also a useful moment to review your GDPR breach notification procedures and ensure you know who is responsible for coordinating the response if customer data is compromised, including notifying the ICO within 72 hours and communicating with affected customers. Review whether you have a clear data inventory and whether your incident response plan includes specific steps for handling data breaches.
Source: Infosecurity Magazine