World
digital threat •
A cyberattack has hit three British airports, but the problem is Europe-wide. The perimeter has shifted
The data of eight million seven hundred thousand customers at Manchester, Stansted and East Midlands airports has fallen into the hands of unknown parties. Moscow does not appear to be behind it, but it is precisely this ambiguity that makes such attacks the perfect tool of hybrid warfare. London is rewriting its civil defence manual, whilst Italy is discovering the problem the hard way.

No flights were cancelled, no radar systems malfunctioned, and no aircraft were put at the slightest risk. What the hackers made off with from Manchester, London Stansted and East Midlands airports was a list of those who had booked a parking space, those who had entered a lounge, those who had paid for priority boarding and, above all, those who had provided an email address to connect to the terminal’s Wi-Fi. Eight million seven hundred thousand people. The digital ‘thieves’ have already demanded a ransom. The Manchester Airports Group, the company that manages the three airports and is controlled by the ten local authorities of Greater Manchester, has refused.
It is a modest haul, but that is precisely why the case is instructive. The Manchester Airports Group has stated that “passenger safety and aviation security have not been compromised in any way”, and clarified that the compromised systems did not contain any banking or payment details. Most of the information leaked is believed to consist of email addresses and telephone numbers required for registration on the airports’ Wi-Fi network. Other data, such as postcodes or vehicle details, are believed to have been obtained from the systems used to book parking spaces and priority boarding passes, and to access lounge areas. As a precautionary measure, the company has decided to suspend its online booking service for 72 hours. Customers have been advised to be wary of emails, calls and messages from unknown senders and not to open suspicious attachments. That is precisely where the danger lies: addresses, telephone numbers, postcodes and number plates can be used to set up the next scam. A message mentioning your car park, your number plate and your flight is almost indistinguishable from a genuine one.
Although the criminal operation appears to rule out the involvement of state actors, the events in the United Kingdom once again highlight the importance of cyber security as an integral part of a country’s defence. The recent spate of Russian cyberattacks against European Union member states and allies clearly demonstrates the extent to which digital infrastructure is a sensitive target in the ongoing conflict and, as such, requires adequate protective measures.
Cyber-attacks on sensitive infrastructure lend themselves to hybrid conflicts due to their ambiguous nature: the instigators remain in the shadows, and the perpetrator may decide at a later stage to whom to offer their services. What begins as extortion may, a month later, become the transfer of information to a hostile country. Russian espionage already operates in this way, pairing skilled spies with ‘disposable agents’ recruited via Telegram: the line between low-level criminality and international sabotage is blurred. For this reason, in July, the EU’s High Representative for Foreign Affairs, Kaja Kallas, referred in a statement to a veritable “cyber ecosystem”: the network of state and non-state actors – intelligence agencies, hacktivist groups, cybercriminals, private companies – which Moscow utilises for its “dangerous cyber activities”.
Airports, which accumulate personal data simply by providing services, are vulnerable targets. Cybersecurity agencies have long recommended avoiding airport Wi-Fi networks – whether free or paid – and using your mobile phone’s hotspot instead. If you really must use a public network, you should use a VPN – a virtual private network that protects data in transit. But the Manchester case also reveals something else. In that instance, no one intercepted communications: the data was extracted from servers, where it had been stored for months or even years. The right advice, then, does not concern the connection itself but the registration process. Every email address provided in exchange for twenty minutes of free Wi-Fi is a debt that someone, sooner or later, might decide to collect on.
The United Kingdom has realised that the scope has shifted and is rewriting the ‘Government War Book’, the manual for the country’s defence in the event of physical or cyber attack. This falls within the broader concept of ‘whole-of-society defence’, namely the idea that defence is no longer solely the responsibility of the Armed Forces, but involves institutions, businesses, infrastructure and even individual citizens.
And how is Italy faring in this regard? For the time being, it is lagging behind, both in terms of government initiatives and public debate. An initial sign of a response came in the form of the policy statement by Defence Minister Guido Crosetto, published last month, which stated that a ‘civil defence system’ – designed to adapt the country to the changing nature of warfare – was currently ‘in the process of being established’.
Meanwhile, events are unfolding. On 24 August, TeamSystem, one of Italy’s leading providers of business management software, detected unauthorised access to its Cloud Accounting service, which is used by businesses, accountants and consultants. Two days later, it notified its customers. Personal details, contact information, IBAN bank details and complete accounting transactions – including payment descriptions, amounts and counterparties (who pays whom, how much and for what) – were exfiltrated. Investigations into which databases were accessed are still ongoing. A few days earlier, it was the turn of the Spaggiari Group, which provides electronic registers to a large number of Italian schools.
In the space of a week, in short, the travel details of eight and a half million British travellers, the accounts of a small Italian business and our children’s school records ended up in unknown hands. None of these records were considered critical infrastructure. But civil defence is not just about protecting power stations, because it can be circumvented from the bottom up, via car parks, accountants and school registers. In London, they are redefining the perimeter with a manual; we are discovering it one data breach at a time.