Data breach experts at Have I Been Pwned analyzed the exposed information and found that it included email addresses, phone numbers, home addresses, vehicle registration numbers, purchase histories, and browsing device data.
Cybersecurity expert Kevin Beaumont urged affected individuals—particularly celebrities and high-net-worth people—to remain alert for follow-up fraud attempts, phishing scams, and hacking threats.
“The data includes both historical locations and planned future trips, so individuals who are concerned about having their movements exposed may need to take additional precautions,” he said.
“People should be aware that scammers reuse stolen data and may have access to details such as phone numbers and vehicle registration information,” he added.
“Our advice to affected customers is to remain cautious of unsolicited emails, text messages, and phone calls,” Manchester Airport Group (MAG) said in a statement.
“We want to reassure customers that Manchester Airport Group takes the security of their personal information extremely seriously. We apologize for any inconvenience or concern this incident may cause.”
Following the data breach, the airline said there had been no incident at the airport that threatened the physical safety of passengers.
In an unusual development, the cybercriminals’ website hosting the stolen MAG data is accessible on the clear web rather than the dark web, where most hacker “leak sites” operate.
The public availability of the information makes it easier to access and may increase the risk of identity theft, targeted scams, and other attacks against MAG victims and customers of other companies reportedly breached by the group.
Alongside the stolen data, the hackers claimed they exploited weaknesses in how companies store digital keys used to access internal networks. They also said they used the same technique to breach each targeted organization.
Source: www.bbc.co.uk


