When Reassurance About A Breach Isn’t Proactive Enough

“There is no action you need to take. We would urge you to be particularly cautious of unexpected emails, calls or text messages claiming to be from us. We will never contact you unexpectedly to ask for payment or banking information.”

Except that’s just going to be the tip of the iceberg.

What happened?

Manchester Airports Group (which also manages East Midlands and Stanstead airports) issued a statement after approximately 8.7 million passengers data had been stolen in a cyber attack at the end of August.

Why is this important?

It’s not just going to be e-mails or nuisance calls from hackers posing as the Manchester Airports Group, apparently the group responsible for the hack are now demanding payment for the return of the data (which MAG are refusing to pay). Regardless of payment this information could end up on the dark web – if it hasn’t done so already – and whoever uses the list of customer information could do a lot of bad things with that info:

  • Pose as other organisations “in partnership” with MAG and trick people on the list into loading fake websites or apps to “verify their account” or “correct an issue with their booking”.
  • Use the number plate and postcode information to see what cars are potentially worth stealing. 
  • Cross reference the e-mail addresses on the list with other information on the dark web to login to other accounts of interest (for example ransomware attacks on e-mail, social media or productivity app accounts such as Microsoft 365 or Google Workspace).  Alternatively they could also launch brute force/dictionary attacks on various portals to pick out logins with weak passwords and no MFA or passkeys.

What YOU should do next:

Reassurance is one thing, taking precautionary steps is the way forward and thankfully this is covered by a lot of the basics.

If using passwords make sure they are strong (combination of uppercase, lowercase, numbers and special characters), long (more than 12 characters ideally), unique (don’t reuse the password with other login pages) and difficult to guess (randomly generated are good). Commonly used passwords that may look compliant like ILoveY0u or [insert football club name here]123 appear frequently on password lists found on the dark web.

Lock your car when not in use, don’t leave valuables in it when not attended.

If someone phones you unexpectedly and asks you to urgently login to something write down the details, end the call and a bit of research should be able to tell you if it’s legitimate or not. If you’re not sure seek advice from trusted contacts.

Avoid clicking on links in unexpected messages asking you to login to something until you can verify who it’s from (check e-mail address not just senders name), check any links that may ask you to go to a login page (in other words a fake landing page) and double check any attachments that maybe included (HTML and other executable files are a no-no, zip files and document files treat with caution). If you’re not sure yourself please be cautious before actioning or replying and seek advice from a trusted contact.