Where the data actually came from
The detail that matters most in the Manchester Airports Group breach is not the number of people affected, though that number is large. It is where the data was sitting.
The BBC reported this week that criminal hackers accessed records belonging to roughly 8.7 million customers of MAG, the group that owns Manchester, East Midlands and London Stansted airports, and demanded a ransom the company says it refused to pay. The compromised records included contact details, postcodes and vehicle registration numbers.
None of that came from a booking engine, a travel management company, an expense platform, or a corporate travel program of any kind. The bulk of it was email addresses collected when passengers signed up for WiFi inside the terminals.
The more detailed records, the ones including vehicle registrations, came from people reserving car park spaces, arranging lounge access, and buying fast-track through security.
Every one of those is a transaction a corporate traveler makes on their own, outside whatever system their employer approved. That is the part worth sitting with.
The exposure surface nobody maps
Ask a travel manager to describe their program’s data risk and you will usually get an answer about the booking tool, the expense platform, and the TMC. Those are the systems under contract, the ones with a security questionnaire on file and a data processing agreement someone in legal reviewed.
Now list what actually happens on a single business trip that touches none of those systems. The traveler connects to airport WiFi using their work email address, because that is the address they have memorized and because the sign-up form asks for one. They book airport parking through the airport’s own website, entering the license plate of a company vehicle. They buy lounge access at the gate because the connection is tight. They pay for fast-track because the security line is long and the meeting is not moving.
Each of those creates a record, held by an entity the employer has no contract with, containing information the employer would classify as sensitive if it lived anywhere else. A work email address is a directory entry. A postcode plus a name is enough to identify a person. A vehicle registration tied to a corporate fleet is an asset record.
MAG stated that no passenger safety or aviation security was compromised, and that the affected system held no banking or payment details. Both statements appear to be accurate, and both are also beside the point for a company assessing its own exposure.
Payment data is the easiest category to protect and the fastest to remediate, because a card can be cancelled in an afternoon. An email address tied to a name, a home postcode and a vehicle cannot be reissued.
The industry already lived the rehearsal
Corporate travel has a recent, uncomfortably direct precedent for what happens when the information layer fails, and it is worth revisiting because it was not a breach at all.
On 19 July 2024, a faulty software update from the security vendor CrowdStrike took roughly 8.5 million Windows systems offline worldwide. More than 5,000 flights were cancelled that day. Hotel guests found they could not check in or check out. It was not an attack, which is precisely the point: the entire disruption came from a routine update to a piece of security software, applied by a trusted vendor.
The travel industry felt this in an almost literary way. The Global Business Travel Association’s annual convention opened on 22 July in Atlanta, Delta’s home city, with the airline still working through the aftermath days later. Many of the roughly 5,800 business travel professionals expected at the event did not make it in time for the opening session. The people whose job is managing corporate travel disruption spent that week personally stranded by one.
Nobody was hacked. No data was stolen. The lesson was about dependency: how much of modern travel runs on a small number of systems, and how little visibility any single company has into the resilience of the layers beneath its own.
Read alongside an incident where data actually was taken, the two form a complete picture of what information security means for this industry. One end of the spectrum is confidentiality, what gets out. The other is availability, what stops working. A travel program is exposed on both, usually through infrastructure it does not own and cannot audit.
Why the stakes rose with AI
There is a specific reason this class of breach has grown more consequential, and it has to do with what the stolen data enables rather than what it directly reveals.
Phishing used to be a volume game. Generic messages, obvious errors, a low hit rate that still worked because the cost of sending was near zero. What a dataset like this one provides is the raw material for something considerably more targeted: a message that knows the recipient’s name, their employer’s email domain, the airport they travel through, and in some cases the car they parked there.
That specificity is what makes the warning MAG issued to its customers, to be careful with unexpected emails, calls and messages, harder to follow than it sounds. The whole point of a message built on real details is that it does not look unexpected.
There is a second layer to this that the corporate travel industry has not fully priced in. As AI agents take on more of the booking and expense workflow, they inherit the same trust problem, and they may be worse at it than people are.
Researchers from Stanford and Georgia Tech showed, in work presented at ACL in 2025, that AI agents completing web-based tasks including travel booking can be manipulated by content specifically designed to fool a machine rather than a human. A human who has learned to distrust a suspicious pop-up carries a decade of hard-won pattern recognition. An agent processing a page does not automatically have that.
Combine a breach dataset accurate enough to make a fraudulent message look legitimate with an agent authorized to act on messages, and the failure mode stops being an employee clicking something they should not have. It becomes a system acting on instructions it had no basis to question.
The governance question this lands on
Evan Konwiser of Amex GBT made a point in a Forbes interview with Jeff Fromm that reads differently after a week like this one. Discussing what it takes to build traveler profiles rich enough for AI to personalize a trip, he argued there is no shortcut around the unglamorous requirements: security, governance, compliance, and robust deletion.
Deletion is the one that usually gets skipped, and it is the one this breach turns on. An email address collected at a WiFi captive portal in 2023 has no operational reason to still exist in 2026. It exists because deleting data requires someone to decide it should be deleted, build the process to do it, and accept the marketing cost of a smaller list.
Retention is the default because retention is free until the day it is extremely expensive.
For a corporate travel program, the practical version of that question is uncomfortable and worth asking anyway. How many entities currently hold traveler data belonging to your company, and how many of them do you have a contract with? The gap between those two numbers is the exposure that no security questionnaire has ever covered.
What a certification actually commits you to
There is a reasonable objection to everything above, which is that security certifications are widely treated as procurement theater. A logo on a vendor’s website, a PDF in a bid response, a box someone ticks.
That reading is fair for some standards and unfair for ISO/IEC 27001, mostly because of what the standard demands in the areas companies least enjoy addressing. It is not a checklist of technical controls. It requires an organization to map its own risks, implement proportional controls, and monitor them on a continuing cycle, which means answering the question of what data exists, where it lives, who can reach it, and on what schedule it gets destroyed. Retention and deletion are not optional annexes in that framework. They are the part an auditor returns to.
At VOLL, the corporate travel and expense management platform I cofounded, we were the first Brazilian corporate travel management solution built on proprietary technology to obtain the international certification, which the trade press covered in 2024. Others in the market have since certified as well, which is the outcome anyone serious about this should want.
I am not raising it as a credential, and a certification is emphatically not a guarantee against incidents, since nobody credible in security would claim otherwise. I raise it because the process changes what a company knows about itself.
The uncomfortable discovery in that kind of audit is rarely a missing firewall. It is a dataset nobody remembered was still being kept.
The more useful application of the standard is on the buying side rather than the selling side. A travel manager evaluating suppliers can ask a certified vendor concrete questions with verifiable answers: what is the retention schedule for traveler profile data, what is the response time commitment when an incident occurs, what happens to the data when the contract ends, who inside the vendor can access a traveler profile and under what approval.
Those questions are answerable under a certified management system and largely unanswerable without one. That is the practical difference, and it matters more than the logo.
What a program can actually do about it
The instinct is to write a policy prohibiting travelers from using airport WiFi, and that policy will be ignored, in the same way that policies against premium cabins get quietly routed around by executive exception. A rule that makes a traveler’s day materially worse does not survive contact with a delayed connection.
More workable options exist, and most of them cost very little. What follows is what I would put in front of my own team, offered as one operator’s view rather than as security advice from a security professional, which I am not.
Start with the captive portal problem, since it produced the bulk of the records in this case. Giving travelers a mobile data allowance removes most of the reason to connect to airport WiFi at all, and it costs less per trip than most programs assume. Where terminal WiFi is genuinely necessary, a simple instruction not to use the corporate email address at sign-up captures a meaningful share of the exposure at no cost whatsoever.
Then map what your program does not control. Most travel managers can list their contracted systems from memory and have never written down the uncontracted ones: airport parking accounts, lounge memberships, fast-track purchases, hotel loyalty profiles, rental car programs, airline accounts. That list is the actual exposure surface, and building it is an afternoon of work that almost nobody has done.
Add retention questions to supplier reviews, not just security questions. Every vendor will confirm they encrypt data. Far fewer can tell you how long they keep it, what triggers deletion, and what happens to a traveler profile ninety days after a contract ends. The answer to that last question is frequently that nobody has thought about it.
Treat traveler profile data as a live inventory rather than a permanent record. Passport numbers, dietary information, emergency contacts and loyalty credentials accumulate in travel systems and are almost never pruned. A profile for an employee who left three years ago is pure liability with no operational value.
Build the disruption plan and the breach plan as one exercise. The 2024 outage and this breach have almost nothing technically in common, and yet the first hour of a company’s response to either is identical: who decides, who communicates to travelers, and through which channel when the usual channel may itself be compromised or offline.
Finally, run the drill before it matters. Most companies have a duty of care protocol for physical incidents and nothing equivalent for information incidents, despite the second being considerably more likely in any given year.
None of this is glamorous, which is exactly why it does not get done. I have argued before that the real cost of a travel program lives in the parts that never show up on an invoice, and this belongs in that category. There is no line item for data that has not leaked yet.
It is worth noting that the travel managers doing the most advanced work in this field have been treating the traveler’s full journey as their responsibility for a long time. When BTN named Moderna’s Jennifer Steinke its Travel Manager of the Year this year, the recognition was for AI work built on a data foundation she spent years assembling deliberately. That same discipline, knowing precisely what data exists, where it sits, and why it is being kept, is what makes a program resilient rather than merely modern.
The regional footnote
One last observation, and it is the reason I keep returning to this theme.
This breach happened in the UK, was reported by British media, and is being assessed by a British regulator. The 2024 outage originated with a US vendor and grounded aircraft on four continents. Neither is a local story, because the infrastructure underneath corporate travel is not local. The exposure exists wherever business travelers move through airports, which is everywhere.
Latin America has been ahead of the curve on adopting new travel technology, and that pace has come with real investment in the governance underneath it. The certification work I described above happened in Brazil, in a Brazilian market, driven by Brazilian corporate clients who were asking the right questions of their suppliers before regulation forced anyone to. That is worth saying plainly, because the default assumption in global industry coverage runs the other way.
I have written before about how much of this industry’s real learning happens in rooms rather than in press releases. This is a case where the learning is available for free, from someone else’s incident, before it becomes anyone’s own. The airports involved will absorb the regulatory consequences. Everyone else gets a map of an exposure surface they were not looking at, at no cost, which is the cheapest security audit a travel program will ever receive.
About me
I am an entrepreneur with over 20 years of experience at the intersection of tourism and technology. I am co-founder and Chief Business Officer of VOLL, the largest mobile-first corporate travel and expense management platform in Latin America, and a recognized reference in the development of the corporate travel industry.
A Marketing specialist from Fundação Dom Cabral, I serve on the Tourism Council of FecomércioSP and on the Executive Council of the Latin American Association of Corporate Events and Travel Management (Alagev). A frequent traveler and close observer of human behavior in motion, I write and speak about innovation, digital transformation, entrepreneurial leadership, and the future of corporate travel.




