$ techbeacon▋
Ransomware

Hacker Group Publishes 550GB of Manchester Airports Data After Ransom Refusal

Hacker Group Publishes 550GB of Manchester Airports Data After Ransom Refusal

A hacker collective has released approximately 550 gigabytes of data allegedly belonging to Manchester Airports Group (MAG), the operator of several UK airports, after the company declined a ransom demand. The leak, first reported by SecurityWeek, includes personal information on an estimated 8.8 million individuals, raising concerns about the exposure of passengers, employees and partners linked to the airport network.

According to the attackers, the breach was enabled by unsecured administrative keys that were inadvertently exposed online. By exploiting these credentials, the group says it gained privileged access to MAG's internal systems, allowing it to extract a large volume of files before the organization detected the intrusion.

MAG has not confirmed the specifics of the incident, but industry analysts note that the use of exposed admin keys is a common vector for data exfiltration, especially in organizations with complex IT environments. The incident underscores the ongoing challenge for large infrastructure operators to maintain stringent access controls and regularly audit privileged accounts.

The public release of the data follows a pattern observed in other recent cyber incidents, where threat actors forego ransom payments and instead weaponize stolen information to pressure victims. By publishing the files, the group aims to amplify reputational damage and potentially extract a higher payout in the future. Regulators may scrutinize MAG's handling of personal data under the UK’s Data Protection Act and the EU’s GDPR, which could lead to investigations or fines if compliance gaps are identified.

Experts suggest that affected individuals should monitor their accounts for suspicious activity and consider credit monitoring services, while MAG is expected to notify those impacted in accordance with legal obligations. The breach also serves as a reminder for businesses to adopt zero‑trust architectures, enforce multi‑factor authentication for privileged access, and conduct regular penetration testing to uncover hidden exposures before malicious actors can exploit them.

Suresh Kanwar — Suresh reports on security breach post-mortems and enterprise incident response, breaking down attack timelines after major disclosures.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related