MAG, ML, and Modern Airport Malaise
A look into the cyber threats facing today’s aviation industry.
A little over a week ago the Manchester Airport Group (MAG) suffered a series of cyber attacks that leaked nearly 9 million customers’ personal information. While MAG claims their airport’s critical infrastructure and services, like air traffic control, were never at risk, cyber attacks of this nature highlight the inherent dangers of modern airports, which rely on interconnected frameworks to remain operational. It’s a complex issue that will require significantly more resources and attention as critical infrastructures continue to be targeted by AI-driven attacks.
“…mitigating cybersecurity risks in the complex and expansive aviation sector requires extensive collaboration among government agencies, industry partners, and associations. Adequate allocation of resources, budgetary considerations, skill development, and safeguarding of critical systems are essential elements in protecting the aviation industry from cyber threats.” (Eleimat and Öszi, Cybersecurity in Aviation: Exploring the Significance, Applications, and Challenges of Cybersecurity in the Aviation Sector, 2025, p. 179)
One of modern airports’ biggest vulnerability vectors is their customer-facing services. Websites, apps, and public Wi-Fi networks are commonly exploited in attempts to disrupt operations and move laterally towards secured networks that control critical communications and mission information. Most smart airports employ network segmentation to limit these risks, but data breaches of low-level information can still pose long-term threats. The most common, and one that has grown exponentially with the rise of AI, is phishing.
“AI-generated phishing emails are more well-tailored than traditional phishing emails, leveraging personal information such as job titles, trusted contacts, and social media activity to create highly targeted and convincing messages.” (Shreyas Kumar et al., Proceedings of the International Conference on AI Research, 2024, p. 222)
And the MAG airport attacks have prepared the perfect victims for this sort of campaign - as reported by BBC, the majority of data accessed consisted of customer emails, phone numbers, and postal codes. This means the 8.7 million customers affected are now uniquely vulnerable to AI phishing efforts, where personalized emails can be automated at scale to appear as if they really are coming from organizations like MAG and their connected services, an endeavor made increasingly possible by AI’s capability to evade current phishing detection methods.
Moreover, phishing messages often rely on creating a strong sense of urgency - “click this link to reset your password before it expires”, “if you don’t want to lose your flight, sign in to your account to verify your booking and payment details here”, etc. And with enough personal information, these messages can seem convincing, especially to travelers already experiencing heightened levels of urgency, stressed about flight details and car rentals and vacation budgets. It’s what makes attacks like these so insidious. As put by Gavin Millard, VP of Intelligence at Tenable in Cyber Magazine’s “Three UK Airports Face Cyberattack: Experts Have Their Say”,
“Threat actors don’t need to break into anyone’s bank account. They can sit on this data for six months, wait until the news cycle dies down and send a simple text claiming someone owes a £9 (US$12.2) airport parking overstay fee.” (2026)
This is why large-scale data breaches can pose significant security threats long after the initial leak has been dealt with. Remaining vigilant to potential phishing campaigns after a breach can be a tiring and costly endeavor with no clear end date in sight. Even so, data breaches are far from the fiercest threat facing avionic cyber security teams. The integration of the Internet of Things (IoT) into almost every aspect of airport operations has created an overwhelming amount of new attack surfaces (Ukwandu et al., 2022, p. 14), vulnerable surfaces that encouraged a “530% increase in cyberattacks within the aviation industry from 2019 to 2022” (Sivakorn et al., Safeguarding Skies: Airport Cybersecurity in the Digital Age, 2025, p. 1).
Despite this known increase in attacks, airports are struggling to implement sufficient security measures. Rolling out new security frameworks and trying to stay up-to-date with rapidly changing cybersecurity best practices has proven challenging on many counts. Airports usually employ strict network segmentation practices, with multiple layers separating public-facing IoT services from the critical infrastructure that keeps planes on course and in the air, but as briefly explained earlier, this can unintentionally create an appealing set of circumstances for cyber criminals. The relative insecurity of airports’ public services can serve as gateways to more secure aviation sectors. And as internet/technologically dependent services become industry expectations, (think charging ports, free Wi-Fi, in-flight movies, etc.), there are not enough cybersecurity professionals much less industry resources to meet the growing security demands inherent in IoT integration.
As such, many professionals have been pushing for the implementation of modern cybersecurity frameworks and Zero Trust Authentication to limit the risks posed by less secure networks and internet reliant services. Aside from customer information, employee credentials are often targeted in data breach attacks and phishing campaigns, reinforcing the need for secure authentication and AI phishing detection methods to be incorporated into a flexible and multi-faceted cybersecurity framework.
In cases of securing critical infrastructure, prevention is the most important layer of defense. Continuous monitoring, complete network segmentation, constant and explicit authentication, and detailed data preservation and recovery plans in event of an attack are essential parts of a successful and proactive cybersecurity system. Making best practice preventative cybersecurity the standard for airports will require immense industry support from both the aviation and cybersecurity sectors, as well as extensive upgrades to outdated software and infrastructure.
This is an issue that will likely be simultaneously helped and hindered by AI advancements - with AI helping to power continuous monitoring programs and detect zero day vulnerabilities before adversaries can exploit them, while also creating new challenges in the form of AI-led attacks and phishing campaigns. In any case, the current avionic security systems need to change if the aviation industry plans to withstand the rising tide of AI-driven cyber attacks that have lowered the barrier of entry to complex cyber crime.
Sources
https://pp5.omikk.bme.hu/tr/article/view/37153
What the Phish! Effects of AI on Phishing Attacks and Defense
https://www.bbc.com/news/articles/c7v4353rry7o
https://cybermagazine.com/news/three-uk-airports-face-cyberattack-experts-have-their-say
https://www.mdpi.com/2078-2489/13/3/146