Hackers have published on the dark web the personal details of a judge, politicians, celebrities and defence workers following the cyber attack on three UK airports last month, The Mail on Sunday can reveal.
Data stolen from an estimated 8.7 million customers using Manchester, Stansted and East Midlands airports was released online on Tuesday.
The publication came after the airports’ operator refused to meet the gang’s demand for an undisclosed ransom payment.
However, the files do not just relate to ordinary members of the public but also contain sensitive information linked to the travel movements of a circuit judge, parliamentary workers, Home Office and Bank of England staff, and members of the Armed Forces, analysis by this newspaper reveals.
They also contain numerous email addresses purporting to belong to celebrities and Premier League footballers.
Among the records the gang said it had obtained was a judge’s airport booking made using an official judicial email address.
The vehicle registration and upcoming travel plans of a Bank of England official and the number plate and future travel details of a Home Office employee were also among the stolen data.
The hackers, from cyber-extortion group FulcrumSec, breached the IT system of Manchester Airports Group (MAG) on August 22 and 23. MAG later confirmed the attack on August 27.
Data stolen from an estimated 8.7 million customers using Manchester, Stansted and East Midlands airports was stolen by hackers and released online on Tuesday (Manchester airport is pictured)
It is understood that customers’ details were obtained by hackers getting access to car park, lounge and fast-track bookings, and through passengers signing up to wifi access inside the airports. Hackers did not get hold of banking or payment details, MAG said.
FulcrumSec claims that the data contained the future travel plans of almost 200,000 passengers –information that could potentially reveal to criminals when individuals would be away from home.
However, the gang withheld those records from the data it published because, it said, of the security risks they posed.
FulcrumSec said: ‘MAG declined to pay the necessary fee to protect their passengers’ data, leaving us to remove the most sensitive parts – the details of upcoming travel for 200,000 passengers – from the leak prior to publication.’
In an email to customers, MAG warned them to be alert to potential scams following the attack.
It said: ‘We would urge you to be particularly cautious of unexpected emails, calls or text messages claiming to be from us.
‘We will never contact you unexpectedly to ask for payment or banking information.’
MAG claimed that it had ‘immediately contained the risk’ from the incident and was ‘working with specialist advisers and taking appropriate steps to protect our customers and systems’.
It added: ‘We have informed and are working with the relevant authorities. At no point has passenger safety or aviation security been compromised.
‘Airport operations remain unaffected and customer parking services continue to operate normally.
‘We would like to reassure customers that Manchester Airports Group takes the security of customer information extremely seriously and we apologise for any inconvenience or concern caused.’
FulcrumSec blamed MAG for the publication of the stolen information, saying: ‘This post is the consequence of MAG’s negligence and complete lack of concern for their passengers, to whom they lied about the scale and scope of the breach… and to whom they continue to minimise shamelessly.’
You must be logged in to post a comment Login