Manchester Airports Group has confirmed that customer data linked to Manchester, Stansted and East Midlands airports was accessed. We know the affected systems held information from Wi-Fi sign-ups and car park, lounge and Fast Track bookings. We also know that no bank or payment details were held on those systems. What we do not yet know is whether MAG had reasonable security in place before the attack.
In previous breaches at British Airways and (pre gdpr) Cathay Pacific, they were not fined simply because attackers got in. The ICO found serious security failings behind each incident. BA was fined £20 million after the regulator found it was processing large amounts of personal data without adequate security measures. Cathay Pacific received the maximum £500,000 penalty available under the old law after the ICO identified a series of basic weaknesses across its systems.
The lesson is not that every company must spend an unlimited amount on cyber security. Businesses are making difficult choices while salaries, software, insurance and almost every other operating cost continue to rise. The lesson is that cost pressure does not remove the obligation to understand and manage risk.
That matters even more as companies build their own apps, integrations and AI-assisted tools. Vibe coding can help a business move quickly, but speed is not the same thing as security. An app may work perfectly and still expose data through weak authentication, excessive permissions, poor API configuration, missing rate limits, insecure secrets or inadequate logging if MAG have had an incident small business can most definitely be assured if they have vibe coded an app with API interface its not as secure as it would be if completed professionally.
Before a customer-facing system goes live, and regularly afterwards, get it reviewed by a security professional.
To help keep security costs down configuration changes in the already in place technology can do more than a new firewall or latest software.
We cannot say yet whether MAG's security was sufficient as yet. Every other business should use the time before its own incident to ask a simpler question: is ours?