Free Wi-Fi sign-ups are customer data, as three UK airports found out this week
Cyber Security

Free Wi-Fi sign-ups are customer data, as three UK airports found out this week

Manchester Airports Group confirmed on 27 August that an unauthorised third party took customer records from car park bookings, lounge passes and in-airport Wi-Fi sign-ups. The lesson for a smaller firm is in what was taken, not in how big the target was.

31 August 20266 min read

On 27 August Manchester Airports Group confirmed that an unauthorised third party had obtained customer data held on one of its systems. MAG operates Manchester, London Stansted and East Midlands airports, and the records involved came from car park bookings, lounge bookings, Fast Track bookings and sign-ups for in-airport Wi-Fi. The company said it had immediately contained the risk, restricted access to the affected systems, engaged specialist cyber security advisers and notified the relevant authorities. Passenger safety and aviation security were not compromised, airport operations were unaffected, and existing bookings remain valid.

Most of the coverage led on the airports. The part worth a business owner's attention is the list of systems involved, because every one of them is the sort of thing a much smaller company also runs and rarely thinks of as a customer database.

What was taken, and what was not

The data accessed covered email addresses, phone numbers, vehicle registration numbers and postcodes. MAG was clear that neither it nor the affected system held customers' bank or payment details, so this is not a card fraud story. It contacted affected customers directly and told them to stay alert for suspicious emails, text messages and phone calls, and to avoid clicking links or opening unexpected attachments. Its online Manage My Booking service was suspended as a precaution, with anyone needing to change a booking due within 72 hours directed to a customer services line open on weekdays between 9am and 5pm, and warned that wait times may be longer than usual.

The headline number keeps moving, which is worth noticing

MAG has not published a figure for how many people are affected. Help Net Security reported around 8.7 million customers, citing UK media. BleepingComputer put it nearer 8.9 million, citing local reports of private MAG statements, and noted that no ransomware or extortion group had publicly claimed the attack at the time of writing. Treat any headline figure as a press estimate until the company or the regulator confirms one. Two credible outlets landing a couple of hundred thousand apart in the first week of a breach is normal, and it is a reminder to read the attribution rather than the number.

A Wi-Fi sign-up list is a customer database

The guest Wi-Fi captures are the quiet part of this. A visitor portal that asks for an email address and a phone number before it lets somebody online is collecting personal data, and it usually keeps that data for as long as nobody thinks to delete it. The same goes for a car park booking system, a visitor book, an events list, or an old enquiry form still writing rows into a table nobody has opened in two years. None of them feel like the crown jewels. All of them are personal data under UK GDPR, all of them carry a retention obligation, and all of them become a ready-made phishing list the moment somebody else has a copy.

Vehicle registrations and postcodes make that worse rather than better. On their own they are dull. Combined with an email address and a booking, they let an attacker write a message that quotes real details back at the person reading it, which is the thing that makes a scam message work.

What tends to follow a breach like this

Raghu Nandakumara, VP of industry strategy at Illumio, made the practical point in Infosecurity Magazine: the exposed data increases the risk of targeted phishing and smishing attempts, where attackers can use legitimate travel-related information to make malicious communications appear convincing. He also pointed at segmentation, noting that measures such as restricting access to critical systems and sensitive data reduce the risk that a single compromise becomes a wider incident.

Segmentation sounds like an enterprise word. In a twenty-person business it means something plainer. The booking form should not sit on the same box as the accounts package. The guest Wi-Fi should not be on the same network as the till, the file server or the CCTV recorder. When one thing does get compromised, the question that decides how bad your week becomes is what else that thing could reach.

Five things worth checking this week

First, list every place your business collects personal data, including the ones nobody owns: guest Wi-Fi, contact forms, event sign-ups, the booking system, the CRM you replaced but never switched off. Second, decide how long each of those keeps records, and configure it, rather than leaving retention open ended. Third, check that guest Wi-Fi is properly separated from the network your staff and systems use, which on most business kit means a guest SSID on its own VLAN rather than a shared password half the town knows. Fourth, work out who you would tell and in what order if data went missing, because the ICO gives you 72 hours to report a notifiable breach and that clock starts when you become aware of it, not when you finish investigating. Fifth, warn your staff that a breach anywhere in your supply chain is followed by convincing emails quoting real details, and that the right response to an unexpected message about a booking is to go to the supplier's own website rather than the link in the email.

What this means for your business

Nobody reading this runs an airport. Plenty of readers run a guest Wi-Fi portal, a booking form and a mailing list built up over a decade, which is the same problem at a different scale. Start with an inventory of where personal data actually sits in your business, then set a retention rule for each one, then prove the guest network is separated from everything that matters. If a breach happened tomorrow, the two things that decide the damage are how much data you were still holding and what else the compromised system could reach, and both of those are settled long before anyone attacks you. If you are not sure what your systems currently collect or how long they keep it, that is a sensible thing to put in front of your IT provider this month rather than next year.

#WEARECOBALT

Ready when you are.

Tell us what's slowing your business down. We'll tell you exactly how we'd fix it — plainly, with no obligation.