Manchester Airports Group Breach Exposes Personal Data of 8.7 M Passengers Across Three UK Airports
What Happened — An unauthorised third‑party accessed Manchester Airports Group’s (MAG) systems and extracted customer records from Manchester, Stansted and East Midlands airports. The stolen data set includes email addresses, phone numbers, vehicle registrations and postcodes for an estimated 8.7 million individuals. No payment‑card or banking details were compromised.
Why It Matters for Compliance & Audit Readiness
- The incident is a textbook example of a privacy breach that SOC 2 CC5.2 (Privacy) controls are designed to prevent and document.
- Continuous evidence of data‑handling policies, consent management and DSAR processes is essential to demonstrate audit‑ready privacy posture.
- Verisq’s CookiePLUS capability can provide the automated consent‑capture and audit‑ready evidence needed to satisfy both GDPR/CCPA obligations and SOC 2 privacy criteria.
Who Is Affected – Transportation & Logistics (airport operators) and the millions of passengers who used the three UK airports.
Recommended Actions
- Map the exposed data elements to SOC 2 CC5.2 privacy controls and capture current policy evidence.
- Deploy a consent‑management solution (e.g., CookiePLUS) to retroactively document lawful bases for any future data collection.
- Conduct a privacy impact assessment (PIA) and update breach‑response playbooks with clear notification timelines.
- Verify that all third‑party portals (e.g., “Manage My Booking”) enforce strong authentication and least‑privilege access.
Source: Help Net Security
Technical Notes – The breach appears to stem from unauthorised access; the exact vector (phishing, credential theft, misconfiguration) was not disclosed. Exfiltrated fields: email, phone, vehicle registration, postcode. No CVEs were cited. Source: same as above