Cyberattack on Manchester Airports Group Exposes Personal Data of 8.7 Million Travelers
What Happened — Manchester Airports Group (MAG) confirmed that an unauthorized third party accessed customer records linked to car‑park, lounge, Fast Track bookings and airport Wi‑Fi sign‑ups across three UK airports, exposing email addresses, phone numbers, vehicle registrations and postcodes of roughly 8.7 million individuals.
Why It Matters for Compliance & Audit Readiness —
- The breach highlights a failure of privacy‑related controls that SOC 2 CC5.2 (Privacy) requires organizations to define, monitor, and evidence.
- Demonstrating a defensible consent‑management process and a ready DSAR workflow is essential for GDPR/CCPA compliance and provides auditors with continuous‑compliance artifacts.
- Verisq’s CookiePLUS capability can supply audit‑ready consent logs and DSAR evidence to close the privacy control gap.
Who Is Affected — Aviation & transportation operators, passengers, and any third‑party services that process booking‑related personal data.
Recommended Actions —
- Map the exposed data elements to SOC 2 privacy controls and capture evidence of consent collection.
- Conduct a DSAR‑readiness review and update incident‑response playbooks to include privacy‑focused steps.
- Deploy continuous monitoring of booking platforms for unauthorized access and retain logs for audit review. Source: The Record
Technical Notes — Attack vector not disclosed; breach involved unauthorized access to systems storing booking and Wi‑Fi sign‑up data. Compromised fields: email, phone, vehicle registration, postcode. No payment data was exposed. Source: The Record