Skip to main content
a promotional graphic telling you that PCI Compliance is no longer an annual exercise and that continuous monitory must be built in
8.7M Records Lost: Why Refusing Ransom Demands Requires Better Remote Work ControlsPrivacy and Security
5 min readFor CISOs

8.7M Records Lost: Why Refusing Ransom Demands Requires Better Remote Work Controls

The Challenge

Manchester Airports Group (MAG) faced a data breach exposing contact information, vehicle registrations, and postcodes for 8.7 million customers. The compromised records mainly came from email addresses and Wi-Fi sign-up data collected across Manchester, East Midlands, and London Stansted airports. When hackers demanded a ransom, MAG refused.

This decision raised an immediate operational question: without paying to contain the breach, what technical and procedural controls would prevent the next one? The incident revealed a gap in how the organization secured data collected through public Wi-Fi networks and remote access points. For CISOs evaluating this case, the challenge wasn't just the breach itself but the absence of preventive controls that would have made ransom demands irrelevant.

The Environment and Constraints

MAG operates in a sector where public Wi-Fi is a customer expectation. Airports must balance convenience with security across thousands of daily connections from travelers and staff. Alana Muir, Head of Cyber at Hiscox, notes, "Agile and remote working has become the norm across many industries now. But, between joining public Wi-Fi networks in cafes and on trains, to working on the go on a smartphone, businesses are notably more vulnerable to cyberattacks."

The technical constraint is inherent to public networks. Jacob Kavlo, Co-Founder & CEO of Live Proxies, explains that "any public network, whether secure or unsecured, can expose someone's data to possible interception." Attackers use man-in-the-middle techniques to capture data in transit without detection. In MAG's case, the volume of customer data collected through Wi-Fi sign-ups created a high-value target with inadequate transmission security.

Organizations in similar positions face three structural constraints:

  1. Operational necessity: Customer-facing Wi-Fi can't be eliminated without business impact.
  2. Distributed access points: Remote workers and field staff need network access from unsecured locations.
  3. Legacy data collection: Systems designed before remote work became standard often lack encryption for data in transit.

The Approach MAG Should Have Taken

The breach highlights what should have been in place before the incident. Kavlo's recommendation is specific: "If working remotely, using Virtual Private Networking (VPN) makes an attacker's job harder. With a VPN, if someone does manage to intercept the internet connection, they won't be able to read the data being sent because it's encrypted."

But VPNs alone don't close the gap. Kavlo adds that organizations should implement "endpoint protection, VPN access, and multifactor authentication (MFA) all at once to achieve maximum security." This layered approach addresses three distinct failure points:

VPN deployment encrypts data in transit, making intercepted packets unreadable. For organizations collecting customer data through public networks, mandatory VPN use should apply to any device transmitting personally identifiable information. This includes staff laptops, mobile point-of-sale systems, and administrative terminals in public areas.

Endpoint protection prevents compromised devices from becoming entry points. If an attacker gains access to an employee's laptop through public Wi-Fi, endpoint detection and response tools can identify suspicious behavior before lateral movement occurs. This matters for organizations like MAG where staff access customer databases from multiple locations.

Multifactor authentication ensures that stolen credentials alone can't grant system access. In breach scenarios involving public Wi-Fi, attackers often harvest login credentials through packet sniffing. MFA requirements force attackers to compromise a second factor, significantly raising the difficulty threshold.

Results and What's Missing

MAG's decision to refuse the ransom payment avoided immediate financial loss and removed the incentive for future attacks. Organizations that pay ransoms signal willingness to negotiate, which makes them targets for repeat incidents.

However, the source material doesn't provide specific metrics on containment time, notification timelines to affected customers, or regulatory penalties under GDPR for the 8.7 million exposed records. These outcomes matter for CISOs building business cases for preventive controls. The cost of notification, potential fines, and reputational impact typically exceed the investment required for VPN infrastructure and endpoint protection.

What we can measure is the control gap. The breach occurred because data transmitted over public networks lacked encryption. The fix requires three technical implementations:

  • VPN enforcement for any device accessing customer data systems
  • Endpoint detection and response tools on all corporate devices
  • MFA requirements for system access, particularly from public networks

What They Would Do Differently

If MAG were to redesign its remote work security architecture after this breach, the priority should be eliminating unencrypted data transmission. This means:

Mandatory VPN use for all customer data access, with network-level enforcement that blocks connections from non-VPN sources. You can't rely on policy alone; the network architecture must prevent unencrypted access.

Zero-trust network access replacing traditional VPN in the long term. Zero-trust frameworks authenticate every connection request regardless of network location, reducing the attack surface from public Wi-Fi vulnerabilities.

Segmented data storage that separates customer Wi-Fi sign-up data from operational systems. If attackers breach the Wi-Fi authentication database, they shouldn't gain access to broader customer records or internal networks.

Incident response procedures that assume ransom demands will occur. Refusing to pay requires confidence in backup systems, data recovery capabilities, and containment procedures. Organizations that haven't tested these capabilities face pressure to pay when breaches occur.

Takeaways for Your Team

If your organization supports remote work or collects customer data through public networks, this breach demonstrates three critical control requirements:

First, encrypt data in transit. VPN requirements aren't optional for devices accessing sensitive systems from public networks. Configure your network to reject unencrypted connections to customer databases, financial systems, or compliance-relevant data repositories.

Second, layer your authentication controls. MFA should be mandatory for any system access from public networks. If your VPN is compromised, MFA prevents attackers from using stolen credentials.

Third, test your ransom refusal capability. Can you restore systems from backup without paying? How quickly can you contain a breach and notify affected parties? MAG's decision to refuse payment only works if your incident response structure supports that choice.

The Manchester Airports breach wasn't sophisticated. It exploited a known vulnerability in public Wi-Fi networks that has documented mitigations. The lesson for CISOs isn't about emerging threats but about implementing baseline controls that make ransom demands unnecessary. When attackers can't exfiltrate usable data because it's encrypted in transit, the economics of cybercrime shift away from your organization.

Application Security Isn’t Optional Anymore.

You Might Also Like