Your guest Wi-Fi sign-up form is a customer database

· · Security

If your business offers guest Wi-Fi and asks people for an email address before it connects them, you are running a customer database. It probably was not set up by anyone who thought of it that way. It may have been installed by the company that fitted the router, or switched on inside a marketing tool because someone wanted a mailing list. It sits outside whatever you think of as your real systems, and nobody reviews it.

Manchester Airports Group has just demonstrated why that matters.

What MAG has said

On 27 August the group published a statement across its three airport sites, Manchester, Stansted, and East Midlands. An unauthorised third party obtained a quantity of customer data. MAG says it contained the incident, engaged specialist advisers, and notified the relevant authorities.

The interesting part is where the data came from. In MAG's own words, it "relates to car park, lounge, and Fast Track bookings and in-airport WIFI sign-ups". The fields taken were email addresses, phone numbers, vehicle registrations, and postcodes. MAG states that neither the group nor the system accessed holds customers' bank or payment details.

It also says passenger safety and aviation security were never compromised, and that flights and parking are running normally. As a precaution it has temporarily suspended online booking amendments, with a phone line for changes needed inside 72 hours. Affected customers have been contacted directly.

This is a single-source story as we publish. Everything above comes from MAG's own statement, and no attacker, volume, or timeline has been made public.

The systems nobody counts

Look at that list again. Car parking. Lounge bookings. Fast Track. Guest Wi-Fi sign-ups.

Not one of those is what anyone would call a critical airport system, and MAG is right that none of them touches aviation security. That is exactly the point. These are the peripheral systems, the extras bolted on around the edges of the main operation, frequently bought separately, run by a different supplier, and integrated years ago by someone who has since left.

Small businesses have the same shape. The core thing you do is protected because it is obviously important. Meanwhile there is a booking widget, an events sign-up, an old prize-draw form, a review request tool, and a Wi-Fi splash page, each of which has been quietly accumulating names, emails, and phone numbers for years. Ask most owners how many personal records they hold and they will think of the main system. The answer is usually the main system plus five things they forgot.

Guest Wi-Fi is the clearest example because it rarely feels like data collection at all. The customer wants the internet, the form asks for an email in exchange, and everyone treats it as a formality. But every one of those sign-ups is a person, and under data protection law you are responsible for the lot.

"No payment details" is doing a lot of work

The reassurance in the statement is genuine as far as it goes: no card numbers were taken, and card fraud is not the risk here. It is worth being clear about what was taken instead, because the combination is more useful to a criminal than it first sounds.

An email address, a phone number, a postcode, and a vehicle registration is a strong kit for a convincing text message. The registration is the unusual one. Most scam texts about parking are fired off blind, and people ignore them because nothing in the message proves the sender knows anything. A text that names your actual number plate, arriving in the weeks after you actually parked at that airport, is a different proposition. So is a refund offer that cites the right booking type.

That is the realistic next step here, and it is worth telling colleagues and customers about plainly: expect texts and emails referencing parking charges, drop-off fees, or booking refunds, and treat anything asking for card details as false. MAG has said it will never contact customers unexpectedly to request card details, banking information, or passwords. Nobody legitimate will. If a message looks like it might be real, go to the organisation's website yourself rather than following the link.

What to check in your own business

Three things, none of which needs a budget.

Write down every place you collect personal data. Not the systems you consider important, all of them. The Wi-Fi portal, the contact form, the booking tool, the events list, the old campaign nobody has switched off. If you cannot produce that list, you cannot protect it, and you could not tell people what had happened if it leaked.

Ask who actually holds it, and where. For each one, who is the supplier, does the data sit with them or with you, and what would they tell you if they were breached. Peripheral systems tend to be someone else's platform, which means your incident would start with their phone call.

Stop collecting what you do not use. The cheapest fix in security is not holding the data. If nobody has ever emailed the guest Wi-Fi list, turn off the field that builds it. A form that asks for a vehicle registration when it does not need one is creating risk for free.

The lesson from MAG is not that airports are careless. It is that the systems most likely to leak your customers' details are the ones nobody thinks of as systems at all.

How Steelwise can help

Building an honest list of everywhere your business holds personal data, and working out which of those places would hurt if it leaked, is a short and well-defined piece of work. Get in touch if you would like help with yours.

Further reading

← All filings