Used the free Wi-Fi at Manchester or Stansted? That email address is gone
You landed, the free airport Wi-Fi asked for an email address before it would let you online, and you typed one in without a second thought. That box is the source of this breach.
Manchester Airports Group, which runs Manchester, London Stansted and East Midlands, disclosed the incident on 27 August. Around 8.7 million customers are affected. The stolen set covers email addresses, phone numbers, vehicle registration numbers and postcodes, gathered from Wi-Fi sign-ups, car park bookings, lounge access and Fast Track. For the vast majority of people, MAG says, it's the email address alone. The affected system held no bank or card details. The group says it became aware of the attack on the Tuesday, pulled access to the systems involved, called in outside specialists and told the authorities, and that passenger safety and aviation security were never in question. It also says it refused to pay the extortion demand. The "Manage My Booking" service is suspended for now, with a phone line in its place.
Data like this has exactly one use, and it isn't identity theft. It's phishing, made specific. A number plate paired with a postcode is an unusually convincing pair of details to put in an email about airport parking, and anyone holding a list of people who recently parked at Stansted knows precisely what story to tell. Expect messages about unpaid parking charges, refunds on a booking, or a fee that needs settling before you travel.
Nothing here needs a password reset, because no passwords were taken. The habit that protects you is duller than that: when an email or text about a booking arrives, don't use its link. Go to the airport's site the way you normally would, or ring the number on your original confirmation. A convincing email only does damage if it talks you into installing something, and that's the sort of leftover Tendvane's Safety check surfaces: the startup programs and browser extensions on your PC that you never deliberately added.