decrypted · 27 august 2026 · ransomware and cybercrime · vulnerabilities and patching · uk policy and law
The Manchester Airports breach that turned a Wi-Fi login into 8.7 million records
Manchester Airports Group said on Wednesday that hackers had lifted personal data on around 8.7 million customers from the systems behind car park bookings, airport lounges, Fast Track and the free Wi-Fi sign-up pages at Manchester, Stansted and East Midlands. No card numbers or passwords, the company says, but email addresses, phone numbers, postcodes and vehicle registration plates were taken, and the intruder appears to have been inside for several days before anyone noticed. It is a useful, unglamorous story precisely because it needed no nation state and no zero-day: it is a straight line from "we collected this because we could" to "we lost it because someone got in."
What actually failed
MAG has not said how the attacker got in, and it would be guesswork to speculate on the vector. What the company has confirmed is more telling: a guest Wi-Fi sign-up form and a car park booking page were sitting on, or connected to, the same customer data store that held vehicle registrations and postcodes collected for entirely separate services. Free airport Wi-Fi does not need to know your car's number plate. A car park booking does not need to be joined up with a lounge visit from three years ago. When low-friction, low-value services like a Wi-Fi splash page share a backend with genuinely sensitive records, the splash page becomes the weakest door into the vault, and attackers will always look for the weakest door first.
The Secure by Design lesson
Secure by Design asks a simple question before a system is built, not after it is breached: does this component need access to that data at all? A well-segmented architecture would have let a Wi-Fi sign-up leak nothing more than a Wi-Fi sign-up. The second lesson is retention. Vehicle registrations from car park bookings and postcodes from Wi-Fi logins have a shelf life measured in the length of a visit, not in years. Data that is deleted on schedule cannot turn up in a breach five years later. UK organisations running loyalty schemes, booking platforms or "one login for everything" customer portals should treat this as a prompt to ask what their own aggregated customer database actually needs to hold, and for how long, rather than assuming that centralising everything is efficiency rather than risk concentration.
Also this week
A Citrix flaw CISA now rates a live threat. CISA added CVE-2026-8452, a NetScaler ADC and Gateway bug Citrix originally described as only a denial-of-service risk, to its Known Exploited Vulnerabilities catalogue, with a patch deadline of 29 August for US federal agencies. Researchers at watchTowr showed in August that the flaw actually allows remote code execution as root on appliances configured with Gateway VPN or AAA virtual servers, and attackers have been dropping web shells on unpatched boxes since. NetScaler sits at the network edge of a lot of UK enterprises and public bodies; if you run one with VPN or AAA virtual servers enabled, this is a this-week patch, not a this-quarter one.
Ministers want the power to block suppliers in secret. Amendments laid before Parliament on Monday would let the government order essential service providers in energy, water, transport, health and digital infrastructure to stop buying from named suppliers, or to rip out kit already installed, on national security grounds. Unlike the Huawei-era telecoms regime, the new powers would not require the supplier to be named publicly or even notified, and the receiving company would be barred from discussing the order. It follows this month's four-day shutdown of a UK power plant by Iran-linked hackers, and the trade-off is real: faster action against hostile-state suppliers, at the cost of the transparency that let industry scrutinise the last such regime.
The ICO marks police facial recognition homework. An ICO audit of live and retrospective facial recognition use at two forces, West Yorkshire and Greater Manchester Police, produced 107 recommendations and a mixed report card: "reasonable" assurance for live facial recognition at both, but only "limited" assurance for Greater Manchester's retrospective use, where policy gaps were found. Deputy Commissioner Emily Keaney called strong data protection governance a pillar of public trust in facial recognition, which rather underlines how much of that trust is currently running on audit findings rather than settled practice.
Sources
- Cyberattack on Manchester Airports Group exposes data of 8.7 million customers
- Manchester Airports Group Hit by Cyber Incident
- CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs
- CISA: hackers now exploiting Citrix NetScaler RCE flaw in attacks
- UK government seeks powers to secretly block risky tech suppliers
- UK police widen live facial recognition deployments despite opposition
Thinking about what your own customer data actually needs to hold, and for how long? Get in touch.
More like this
- MikroTik routers are being hijacked exactly as NCSC warned they would be 8 september 2026
- CrowdStrike's macro clean-up tool turns into a SYSTEM shell 5 september 2026
- The UK just gave ministers a veto over your suppliers 2 september 2026
Get the next post by email: subscribe to Decrypted. Double opt-in, unsubscribe any time, or take the RSS feed.
Prefer to listen? Decrypted on Apple Podcasts, or paste the podcast feed into any app.