Ransomware Attack on three UK Airports leads to Data Breach affecting 8.7 Million customers | #ransomware | #cybercrime


A sophisticated ransomware attack on three UK airports has reportedly resulted in a potential data breach affecting more than 8.7 million pieces of customer information. The incident has raised fresh concerns about cybersecurity across the UK’s critical transportation infrastructure, particularly as airports hold large volumes of sensitive passenger and visitor data.

Manchester Airports Group (MAG), the operator of Manchester Airport and other major UK airports, has confirmed that customer information may have been accessed by unauthorized individuals during the cyber incident. The potentially exposed information includes customer email addresses, phone numbers, vehicle registration numbers and details associated with devices that connected to airport Wi-Fi networks.

According to security experts, the nature of the incident indicates that the attack could involve a ransomware variant capable of both encrypting files and stealing data. Such attacks, commonly known as double-extortion ransomware attacks, allow cybercriminals to copy sensitive information before encrypting systems and subsequently threaten to publish or sell the stolen data unless a ransom is paid.

The other airports reportedly targeted in the incident are London Stansted Airport and East Midlands Airport, both of which are also associated with Manchester Airports Group. However, the involvement of these airports has yet to be formally confirmed by the organization.

MAG has stressed that critical information and essential airport operations were not compromised. In particular, payment information and aviation security systems were not affected, while parking services at the airports continued to operate. This distinction is significant because a successful attack against aviation security or operational systems could have resulted in far more serious consequences for passengers and airport operations.

The timing of the cyber incident has also attracted attention. The attack reportedly occurred during a period when several prominent UK organizations, including Marks & Spencer, Jaguar Land Rover and the Co-op Group, faced major cyber incidents. More recently, attackers also targeted a UK-based power company, forcing it to temporarily shut down some operations. The sequence of incidents highlights the growing threat posed by organized cybercriminal groups to businesses and critical infrastructure.

Rafe Pilling of the Sophos Counter Threat Unit has suggested that the incident appears consistent with a file-encrypting malware attack. In such an operation, attackers may first infiltrate an organization’s network, identify valuable information, exfiltrate data and then encrypt files to increase pressure on the victim organization to pay a ransom.

The UK National Cyber Security Centre (NCSC) and the aviation authorities are working with Manchester Airports Group to investigate the cyber incident. The investigation is expected to determine how the attackers gained access, what information was potentially stolen and whether additional systems or organizations were affected.

The incident serves as another reminder that ransomware attacks and data breaches are no longer limited to individual companies. Transportation networks, airports, energy providers and other critical infrastructure organizations are increasingly attractive targets for sophisticated cybercriminal groups. Strengthening network security, monitoring unauthorized access and protecting customer information will therefore remain essential for organizations operating in these sectors.

Join our LinkedIn group Information Security Community!



Click Here For The Original Source.

——————————————————–

..........

.

.