Human Error and Data Protection Governance:...
When a data breach is attributed to human error, the underlying cause may extend far beyond the actions of one...
Read MoreLondon Stansted Airport customers have been warned to remain vigilant following a recent cyber security incident in which personal information was accessed by an unauthorised third party.
The incident involved customer information associated with airport car parking, lounge and Fast Track bookings, as well as on-airport Wi-Fi sign-ups.
London Stansted is operated by Manchester Airports Group (MAG), which confirmed that the wider incident also affected Manchester Airport and East Midlands Airport. Across the three airports, data relating to approximately 8.7 million customers was accessed.
While no banking or payment information was compromised, the incident highlights how other forms of personal data can still be valuable to cyber criminals.
The information accessed included:
For the majority of those affected across the three airports, the information accessed was limited to email addresses associated with airport Wi-Fi registrations.
MAG confirmed that neither the organisation nor the affected system held customers’ bank or payment details. Passenger safety and aviation security were also not compromised, and airport operations have continued as normal.
Although financial information was not accessed, personal information can still be used by criminals to make phishing and impersonation attempts more convincing.
For example, knowing that somebody has previously used London Stansted’s parking, lounge or Fast Track services could allow a criminal to create a fraudulent email or text message relating to a booking, refund or payment.
Personal information obtained during a cyber attack can also be combined with details from previous data breaches, social media or other publicly available sources. This can help criminals create more personalised social engineering attacks that may be harder for individuals to recognise as fraudulent.
AJC recently explored some of these risks in more detail in our article, Data Protection at the Airport: The Travel Habits That Could Put Your Personal Data at Risk. It looked at how information linked to travel can create opportunities for phishing, impersonation and other forms of social engineering.
Customers have been advised to be cautious of unexpected emails, telephone calls or text messages claiming to come from London Stansted or MAG.
Following a widely reported cyber incident, criminals may attempt to exploit customer concerns by sending fraudulent security alerts, refund offers or requests to verify personal information.
Customers should be particularly cautious of communications that:
If there is any uncertainty about whether a communication is genuine, customers should avoid using the links or contact details within the message and instead visit London Stansted’s official website independently.
The London Stansted incident is a reminder that cyber security is not simply about protecting financial information. Even seemingly routine customer data can provide criminals with valuable information for phishing, impersonation and social engineering.
For organisations, this highlights the importance of understanding what data is held, who has access to it and whether appropriate security controls are in place. Businesses should also have clear processes for identifying, responding to and recovering from cyber incidents.
Taking a proactive approach can help organisations identify vulnerabilities before they are exploited. Measures such as Cyber Essentials and Cyber Essentials Plus, penetration testing, cyber security assessments and effective risk management can all contribute to strengthening cyber resilience.
At AJC, we support organisations in understanding their cyber security risks, strengthening existing controls and building greater resilience against evolving threats.
The Stansted incident demonstrates that even when financial information is not compromised, a cyber attack can still create significant risks for organisations and their customers.
Contact us on 020 7101 4861 or email us at info@ajollyconsulting.co.uk if you think we can help.
Sources:
https://www.stanstedairport.com/help/data-security-incident
Image accreditation: Christopher Kern from WikiMedia Commons. Last accessed on 27 August 2026. Available at:
https://commons.wikimedia.org/wiki/File:London_Stansted_Airport_Terminal_2.jpg
When a data breach is attributed to human error, the underlying cause may extend far beyond the actions of one...
Read MoreThe alleged theft and leak of Ariana Grande’s unreleased material highlights how cyber criminals can reach valuable information through trusted...
Read MoreRecent incidents involving OpenAI, Anthropic and Meta have shown how advanced AI models can cross intended boundaries during cyber security...
Read More