Manchester Airports Group, the operator of Manchester, London Stansted and East Midlands airports, says hackers breached its systems and stole customer data. The incident did not disrupt airport operations and did not compromise passenger safety or aviation security, according to the company statements reported by The Register and BleepingComputer. The Register reports that a MAG spokesperson confirmed the breach is currently thought to affect 8.7 million customers. BleepingComputer says MAG did not disclose an affected-customer figure to it, and that it could not confirm local media reports putting the exposure at up to 8.9 million travelers. On the evidence available, the scale should be treated as reported by The Register rather than independently confirmed across both outlets. The exposed data appears to be broad but uneven in sensitivity. The Register says the overwhelming majority of affected customers had only email addresses compromised, mostly collected during sign-up for airport public Wi-Fi. BleepingComputer reports that the stolen data also relates to car park, lounge and Fast Track bookings, and may include email addresses, phone numbers, vehicle registration numbers and postcodes. MAG told The Register that the next most common scenario involved data from customers who had begun but not completed bookings for services such as car parking or Fast Track, and that an “even greater minority” of the data came from completed bookings. Both outlets report that payment details were not accessed; The Register says the affected system does not store bank or payment information. The Register reports that MAG characterized the incident as a hack rather than a staff error, saying attackers compromised one MAG system and stole files from a database hosted by a third party. BleepingComputer reports that after detecting the intrusion, MAG restricted access to affected systems, brought in external experts and notified law enforcement. The incident also appears to have an extortion element. The Register says MAG confirmed the attack did not involve ransomware, that an extortion group made demands, and that MAG has not paid. The outlet also reports that the Information Commissioner’s Office asked MAG not to share the group’s name or details of the demand, in part to avoid giving the attackers notoriety. BleepingComputer separately notes that no ransomware or data-extortion group had publicly claimed the attack at the time it published. As a precaution, MAG temporarily suspended or restricted access to its online Manage My Booking service. BleepingComputer says travelers are being directed to use a phone line instead; The Register says customers seeking to amend or cancel bookings due within 72 hours of MAG’s statement were advised to contact customer services. MAG says it has contacted affected customers directly. The company is advising customers to watch for suspicious emails or text messages, avoid clicking unexpected links and reject any request for payment card information, banking details or passwords, according to BleepingComputer. Who benefits: Security teams and incident-response providers benefit from heightened demand for containment, notification and post-breach hardening. Attackers may benefit if exposed contact data is reused in phishing campaigns that reference airport bookings or services. Who's exposed: MAG customers who used airport Wi-Fi or interacted with car park, lounge or Fast Track booking flows are the exposed population identified in the reports. The available reporting says payment details were not accessed, but some customers may have had contact or vehicle-related data exposed.