Manchester Airports Group (MAG) managed to keep its airports operational during a ICT-Related Incident in August 2026, while attackers stole data on 8.7 million customers. Both outcomes are significant, yet only one typically appears in resilience dashboards.
The Challenge
MAG faced a data theft and extortion attack that compromised a third-party database containing customer information from Manchester, London Stansted, and East Midlands airports. The stolen data included email addresses, phone numbers, postcodes, and vehicle registration numbers collected through parking, lounges, Fast Track, and airport Wi-Fi services.
The attackers didn't deploy ransomware, disrupt operations, or receive a ransom payment. They simply took the data and left.
This incident highlighted a resilience issue that traditional uptime metrics don't capture: the organization maintained full operational continuity while experiencing a significant data protection failure. Aviation security remained intact, passenger safety was unaffected, and parking systems continued to function, but millions of customer records were now in criminal hands.
The Environment and Constraints
MAG operates in a heavily regulated environment where operational continuity is mandatory. Airport closures can cascade through aviation networks, affecting thousands of passengers and attracting immediate regulatory scrutiny.
The organization relies on a network of supporting systems beyond core aviation infrastructure. Parking platforms, lounge booking tools, Fast Track services, and Wi-Fi registration all collect and store customer data, often involving third-party vendors.
The breach originated in one of these peripheral systems. According to MAG's disclosure, attackers compromised a database hosted by a third party. While the affected systems didn't hold payment card data, they contained information that creates regulatory exposure and ongoing fraud risk.
Traditional resilience frameworks often stop measuring here. The critical systems stayed online, the incident response team contained the threat, and operations continued. By conventional metrics, the response succeeded.
The 8.7 million exposed customer records tell a different story.
The Approach Taken
MAG restricted access to affected systems while maintaining airport operations. It suspended its online Manage My Booking service as a precaution and disclosed the incident publicly, notifying affected customers.
The organization demonstrated operational resilience in a narrow sense: it protected critical aviation systems and kept passengers moving.
What's less clear from public reporting is whether MAG had mapped the business impact of its supporting systems before the incident. Did risk assessments treat customer data platforms with the same rigor as operationally critical infrastructure? Were third-party data stores included in dependency mapping and control assurance processes?
The UK Cyber Governance Code of Practice asks boards to identify technology, processes, information, and services critical to organizational objectives. It requires integrating cyber risks into enterprise risk management and building resilience to risks from suppliers and business partners.
That framework considers customer data platforms and third-party services part of the cyber risk picture, regardless of their control over core operations.
Results and Downstream Impact
Airport operations continued without interruption. Passenger safety and aviation security were unaffected, representing genuine resilience value.
The compromised data creates a different category of impact. Email addresses associated with specific airports and services can support convincing phishing campaigns. Phone numbers, postcodes, and vehicle registrations add further detail. The National Cyber Security Centre warns that criminals use information from breaches to make subsequent attacks more credible.
Security experts highlighted this risk. Attackers could impersonate MAG in messages about parking, Fast Track bookings, or the breach itself. The stolen data may remain useful to criminals long after the original intrusion is contained.
This extends the business impact beyond immediate incident response. MAG now faces potential privacy reporting obligations, regulatory scrutiny, reputational consequences, and elevated fraud risk. Customer service teams will handle breach-related inquiries, compliance teams will document the incident for regulators, and security teams will monitor for follow-on attacks using the stolen data.
None of this shows up in an operational uptime metric.
What a Connected Approach Requires
The MAG incident exposes a gap between how organizations measure resilience and how cyber risk actually travels through the business.
A customer data platform may not control critical operations, but it can trigger incidents, regulatory obligations, remediation work, and assurance reviews across multiple teams. A third-party vendor may host data used by a customer-facing application that supports a business service protected by several controls. When that vendor is compromised, the organization needs to understand which services are affected, which customers are exposed, which obligations apply, and which controls require reassessment.
If this information sits in separate registers, spreadsheets, vendor records, and security systems, incident response becomes an exercise in reconstructing the business under pressure.
Effective containment requires context. During an incident, teams need to know which systems and data are affected, what those systems connect to, which suppliers are involved, which business services depend on them, and which controls are expected to limit the impact. The test is how quickly those relationships can be understood.
After containment, the same connections matter for learning. The organization should be able to convert what happened into changes to controls, risk assessments, and future response capability.
Takeaways for Your Team
First, expand your definition of critical systems. The UK Cyber Governance Code of Practice doesn't limit its scope to operationally critical infrastructure. It asks boards to identify technology, processes, information, and services critical to organizational objectives. A parking platform may not control flights, but it collects regulated data and creates regulatory exposure.
Second, map dependencies before incidents occur. When a third-party database is compromised, can your team identify affected services, customers, obligations, and control dependencies within hours? If that picture takes days to assemble, you're building your incident response capability around the wrong baseline.
Third, measure resilience across multiple dimensions. The National Cyber Security Centre's Cyber Security Toolkit for Boards covers preparedness, incident response, recovery, assurance, and the integration of cyber resilience throughout the business. It doesn't treat operational uptime as the only meaningful outcome.
Fourth, integrate cyber risk with enterprise risk management. A ICT-Related Incident can activate privacy obligations, fraud exposure, customer service demand, regulatory scrutiny, and reputational consequences without disrupting core operations. Your risk assessments should reflect that reality.
MAG kept its airports running. That mattered. The 8.7 million exposed customer records also mattered. A useful resilience assessment needs to accommodate both outcomes, not just the one that fits existing dashboards.





