Skip to Main Content
close search

Manchester Airport Group (MAG), which operates Manchester Airport, London Stansted and East Midlands Airport has become the latest major UK organisation to be hit by a significant cyberattack.

On the 27 August 2026 MAG confirmed that an unauthorised third-party had accessed customer data relating to car parks, airport lounges and fast track passes as well as airport Wi-Fi signups, affecting around 8.7 million customers.

The information accessed includes email addresses, phone numbers, vehicle registration numbers and postcodes. MAG has confirmed that neither bank nor payment details were held on the affected system and that passenger safety, aviation security and airport operations have not been compromised. MAG says it acted immediately to contain the risk, engaged specialist advisers and notified the relevant authorities.

While the incident remains under investigation, it serves as another stark reminder that cyber risk continues to present a significant challenge for organisations of all sizes and across all sectors.

The growing cost of cybercrime for UK businesses

Over the past 18 months, some of the UK’s most well-known businesses have suffered significant cyber incidents

As we have previously noted, Marks & Spencer were subject to a cyberattack after customers experienced problems with services including contactless payments and Click & Collect in April 2025. This resulted in M&S temporarily suspending its online orders and taking several systems offline while specialist cyber security teams investigated the incident. The disruption continued for several weeks, affecting areas such as sales and customer services and it’s estimated to have reduced its profits by around £300 million.

Hot on the heels of M&S was the attack on the Co-op. The retailer had to shut down parts of its IT systems as part of its containment exercise, resulting in disruption to payment systems, stock deliveries and wider business operations. You may recall that the incident led to widespread shortages on supermarket shelves and forced some areas of the business to revert to manual processes while systems were restored. Co-op subsequently confirmed that personal data belonging to all 6.5 million of its members had been compromised and later reported that the cyberattack had cost at least £206 million in lost revenue.

The scale of that wider impact became even clearer following the cyberattack on Jaguar Land Rover. The incident forced JLR to pause production across its UK factories and had knock-on effects throughout its extensive supply chain. The Cyber Monitoring Centre subsequently estimated that the attack caused approximately £1.9 billion of economic damage, with a possible range of £1.6 billion to £2.1 billion, making it one of the most economically damaging cyber incidents the UK has experienced.

These incidents demonstrate the potential far reaching consequences of a cyberattack. The impact may extend beyond the immediate cost of restoring IT systems and can include lost revenue, contractual disputes, supply chain disruption and significant reputational damage.

For businesses today, the risk is particularly significant because so many everyday services now rely on websites, apps and interconnected systems. Customer bookings, payments, communications and data storage increasingly take place digitally, meaning a cyber incident can quickly become a wider business problem.

So, what should businesses be thinking about before an attack happens?

Prepare for the first 72 hours

When a cyber incident occurs, the initial response can be critical. Businesses should have an effective business continuity and incident response plan setting out who needs to act, which systems may need to be isolated and how key stakeholders will be contacted.

An organisation dealing with an attack may simultaneously need to investigate what has happened, contain the affected systems, communicate with customers and employees, engage cyber security specialists and insurers, and obtain legal and public relations advice.

Businesses should therefore establish these responsibilities before an incident occurs rather than attempting to make those decisions for the first time during a crisis.

Where personal data has been compromised, there may also be regulatory obligations. Under the UK GDPR, a personal data breach which is likely to result in a risk to individuals’ rights and freedoms must generally be reported to the Information Commissioner’s Office (ICO) without undue delay and, where possible, within 72 hours of the organisation becoming aware of it. Where the breach is likely to result in a high risk to individuals, the affected individuals may also need to be informed without undue delay.

Not every personal data breach is reportable. However, businesses should still investigate and document breaches and be able to justify the decision where notification is considered unnecessary.

Look beyond your own systems

One of the key lessons’ businesses should take from recent attacks is that cyber resilience extends beyond an organisation’s own IT infrastructure.

Businesses increasingly depend upon software providers, cloud services, payment systems, contractors and other third-party suppliers. A weakness or disruption elsewhere in that chain can therefore have significant consequences for the business, even where the organisation’s own systems remain secure.

Commercial contracts should be reviewed to establish what happens when a cyber incident occurs. This includes considering:

  • cyber security and data protection obligations
  • liability and limitation clauses
  • incident notification requirements
  • business continuity obligations
  • rights to audit or obtain information
  • appropriate insurance arrangements

Businesses should also understand where its data is stored and transferred, which organisations process it and what safeguards are in place.

Prevention is more than installing cyber security software

Technical security measures remain essential, but cyber resilience also depends on people, policies and processes.

Phishing continues to be a significant cyber threat. Staff training can therefore be just as important as technical protections. Employees need to understand how to identify suspicious communications, protect credentials and escalate potential incidents quickly.

Businesses should also regularly review its cyber security, data protection and incident-response policies, rather than leaving them untouched until an attack occurs.

Regular data-mapping exercises can help organisations understand what personal and commercially sensitive information they hold, where it is located, who has access to it and how it moves through the organisation and its supply chain.

Cyber insurance should also be reviewed carefully. Having a policy does not necessarily mean every loss or incident will be covered, and businesses should understand the scope of its protection before they need to rely upon it.

The question is no longer whether cyber risk matters

The MAG incident is another reminder of how much information businesses hold simply through providing everyday digital services.

An email address, phone number or postcode may appear relatively routine in isolation, but compromised information can expose customers to further risks, including targeted phishing and fraudulent communications. MAG itself has warned affected customers to remain vigilant for suspicious emails, texts and phone calls.

Cyber resilience should form part of wider commercial risk management. That means understanding your data, reviewing contracts and insurance arrangements, training staff, maintaining appropriate policies and having a tested incident-response plan so that everyone knows what to do when something goes wrong.

No business can eliminate cyber risk entirely. However, organisations that prepare in advance are often far better placed to minimise disruption, meet its legal and regulatory obligations and recover more effectively when an incident occurs.

How we can help

Our team can assist businesses with reviewing contracts and commercial arrangements to identify cyber-related risks and potential exposure, carrying out data-mapping exercises, assessing data protection and international transfer requirements, developing and reviewing cyber security, data protection and breach-response policies and providing practical legal guidance following a cyber incident.

At Slater Heelis, we provide comprehensive support across all areas of law, including cybercrime, data protection and breach response and the preventative measures your business can implement. If you would like to discuss your requirements further with one of our specialist solicitors, then please fill out our contact form or call 03300 297 347 for more information.

Get In Touch

Carla Murray is a Partner and Head of the Commercial team at Slater Heelis, advising businesses on a wide range of commercial agreements, distribution models, manufacturing arrangements and technology agreements, as well as supporting clients with intellectual property protection and data protection strategy. If you’d like to speak with Carla, please don’t hesitate to contact us by calling 03300 297 347 or completing our online contact form.

Carla Murray

Contact Us Today

We're here to help.

Call us on 03301 627 279

Want to know more? Get in touch for legal advice

Contact Us Close