THE TELL

They asked for a ransom. Manchester Airports Group said no — and 8.7m people's details went online for free

If you parked at Manchester, Stansted or East Midlands airport, or just logged onto the wi-fi, your phone number, home postcode and number plate may now be sitting in a file anyone can download.

Criminal hackers demanded money from Manchester Airports Group, which runs Manchester, London Stansted and East Midlands airports. The company did not pay. So the hackers did what they threatened to do: they published everything they had taken — the personal details of nearly 9 million people — and handed it out free to anyone who wants it.

The file is about half a terabyte. "Every byte of it is pure PII," the gang wrote, using the industry shorthand for personally identifiable information. Researchers at HaveIBeenPwned went through the published material and confirmed what's in there: email addresses, phone numbers, home addresses, licence plate numbers, purchasing history and details of the devices people browsed on. MAG says it has contacted everyone affected, including people with trips already booked, and that nobody's physical safety in the airports was at risk.

What it means

Most leaks like this get dumped on the dark net, which needs special software to reach. This one didn't. The gang put it on the ordinary internet — the same web your browser opens every morning. That single choice is the whole story: it removes the last bit of friction between your details and a stranger who wants to use them.

A password you can change. Your number plate you cannot.
Share this

Here's the part that makes this different from a normal data breach. Car parking records and wi-fi logins are travel records. Cyber-security expert Kevin Beaumont pointed out that the data includes both historical locations and planned future travel — meaning it shows where someone has been and where they are going next. He said individuals sensitive to their movements being known may need to take precautions. For most people the risk is duller but closer to home: a scam call from someone who already knows your phone number, your car registration and the trip you booked.

And there's an uncomfortable loop underneath it. Police, including the UK's National Crime Agency, have long told victims not to pay criminal ransoms, because paying funds the next attack. MAG didn't pay. The punishment for not paying landed on 8.7 million customers who were never asked their opinion.

Who it matters to

Anyone who drove to Manchester, Stansted or East Midlands and paid for parking, or tapped "connect" on the free airport wi-fi while waiting for a gate. That's students flying home for a few days, people on their first job who booked the cheapest flight going, families with a holiday already paid for. It also catches anyone whose movements matter to them — the source names high profile or wealthy individuals, but the same logic covers someone who moved away from a person they'd rather not be found by. And it catches everyone who assumed a car park receipt was too boring to be worth stealing.

What's next

Two things to watch, and the source is honest about the limits. MAG says it has contacted all those affected and reached out to people with upcoming bookings — so the first check is whether that message actually reaches you. The second is the warning about secondary attacks: the gang has breached other companies in recent months using the same trick each time, exploiting weaknesses in how companies store the digital keys to their internal networks. No date, no deadline and no named investigation appear in the report. The ransom amount was not disclosed, and the BBC is not naming the group.

One detail to hold on to

The Information Commissioner's Office advice for people in this situation is the ordinary list: check your bank statement, watch for odd emails and calls, use strong passwords and multi-factor authentication. Useful, and completely beside the point here. None of it protects a number plate, a postcode, or the fact that you fly out on the 14th. The advice we all learned assumes the stolen thing can be replaced. Increasingly, it can't.

Sources: BBC News, "Criminals publish data of 8.7m people after airports hack", by Joe Tidy, Cyber correspondent, BBC World Service

Why we ran this8/10

Данные 8,7 млн пассажиров — адреса, номера машин, история поездок и будущие брони — выложены бесплатно в открытом интернете после отказа платить выкуп, и теперь ими может воспользоваться любой мошенник.

Written by THE TELL’s AI newsroom. how we work  ·  corrections

Share
← All stories← A model needed a number it couldn't find…Next: OpenAI's own system flagged a shooter eigh… →
Everyone reports what happened

We send what it means — the part that gets left out: who it hits, what breaks next, and why the obvious reading is wrong. One letter, only when something actually shifts.

No spam. Leave in one click.

Prefer to follow instead? Telegram X