NewsBeat

Airport hackers publish personal data of judge, politicians and celebrities on the dark web

Published

on

Advertisement

Hackers have published on the dark web the personal details of a judge, politicians, celebrities and defence workers following the cyber attack on three UK airports last month, The Mail on Sunday can reveal.

Data stolen from an estimated 8.7 million customers using Manchester, Stansted and East Midlands airports was released online on Tuesday.

The publication came after the airports’ operator refused to meet the gang’s demand for an undisclosed ransom payment.

However, the files do not just relate to ordinary members of the public but also contain sensitive information linked to the travel movements of a circuit judge, parliamentary workers, Home Office and Bank of England staff, and members of the Armed Forces, analysis by this newspaper reveals.

Advertisement

They also contain numerous email addresses purporting to belong to celebrities and Premier League footballers.

Among the records the gang said it had obtained was a judge’s airport booking made using an official judicial email address.

The vehicle registration and upcoming travel plans of a Bank of England official and the number plate and future travel details of a Home Office employee were also among the stolen data.

The hackers, from cyber-extortion group FulcrumSec, breached the IT system of Manchester Airports Group (MAG) on August 22 and 23. MAG later confirmed the attack on August 27.

Advertisement

Data stolen from an estimated 8.7 million customers using Manchester, Stansted and East Midlands airports was stolen by hackers and released online on Tuesday (Manchester airport is pictured) 

It is understood that customers’ details were obtained by hackers getting access to car park, lounge and fast-track bookings, and through passengers signing up to wifi access inside the airports. Hackers did not get hold of banking or payment details, MAG said.

FulcrumSec claims that the data contained the future travel plans of almost 200,000 passengers –information that could potentially reveal to criminals when individuals would be away from home.

Advertisement

However, the gang withheld those records from the data it published because, it said, of the security risks they posed.

FulcrumSec said: ‘MAG declined to pay the necessary fee to protect their passengers’ data, leaving us to remove the most sensitive parts – the details of upcoming travel for 200,000 passengers – from the leak prior to publication.’

In an email to customers, MAG warned them to be alert to potential scams following the attack.

It said: ‘We would urge you to be particularly cautious of unexpected emails, calls or text messages claiming to be from us.

Advertisement

‘We will never contact you unexpectedly to ask for payment or banking information.’

MAG claimed that it had ‘immediately contained the risk’ from the incident and was ‘working with specialist advisers and taking appropriate steps to protect our customers and systems’.

It added: ‘We have informed and are working with the relevant authorities. At no point has passenger safety or aviation security been compromised.

‘Airport operations remain unaffected and customer parking services continue to operate normally.

Advertisement

‘We would like to reassure customers that Manchester Airports Group takes the security of customer information extremely seriously and we apologise for any inconvenience or concern caused.’

FulcrumSec blamed MAG for the publication of the stolen information, saying: ‘This post is the consequence of MAG’s negligence and complete lack of concern for their passengers, to whom they lied about the scale and scope of the breach… and to whom they continue to minimise shamelessly.’

What are my rights if I’m a victim?

If your personal data is leaked on to the dark web – a hidden part in the internet used as an illegal marketplace by cybercriminals – you have the right to find out what has been exposed and what is being done to protect you. 

Under data protection law, companies which have had their systems breached must tell you without undue delay if the hacked information puts you at high risk of harm, such as from fraud, identity theft or threats to safety. 

Advertisement

You can ask the organisation for details of information it holds on you and complain if you believe it was responsible for failing to keep that data secure. 

You can also take your case to the Information Commissioner’s Office (ICO). 

If the company has broken data protection law and you have suffered financial loss or distress as a result, you may also be able to claim compensation. 

However, a data leak does not automatically entitle you to a payout

Advertisement

Advertisement

Source link

Advertisement

You must be logged in to post a comment Login

Leave a Reply

Cancel reply

Trending

Exit mobile version