In fact, for the people whose information has been stolen, it can be the point where a new wave of attacks begins.

That’s the concern following the recent publication of 8.7 million customer records stolen from Manchester Airports Group (MAG) after the organisation refused to pay an extortion demand.

The leaked information reportedly included email addresses, phone numbers, vehicle registration numbers and postcodes, with data collected through services including terminal Wi-Fi sign-ups, lounge access and parking reservation portals.

While financial information and flight safety systems were not affected, the publication of this data creates another problem.

Cyber criminals now have access to real personal information they can use to make scams more convincing.

And this isn’t just an issue for large organisations or people travelling through Manchester.

For Isle of Man businesses and residents, it highlights a wider issue: once personal or business information is exposed, it can potentially be used in further attacks anywhere in the world.

What happens when stolen data is made public?

When criminals steal data, there is an obvious immediate risk.

But once that information is published online, the potential audience becomes much bigger.

Stolen email addresses, phone numbers and other personal details can be collected, shared and used by different criminals for months or even years after the original breach.

Think of it as a chain reaction:

Data is stolen 

 

The data is published or sold 

 

Criminals analyse the information 

 

Targeted phishing, smishing and account takeover attempts begin 

The more information criminals have, the more convincing those attacks can become. 

A generic scam might ask you to “click here to confirm your delivery”. 

A targeted scam could reference a recent airport visit, a parking booking or your vehicle registration number. 

That difference matters. 

  1. More convincing phishing attacks

Phishing works by creating a sense of trust or urgency. 

The problem is that stolen personal information can make those messages much more believable. 

If criminals know your email address, phone number and vehicle registration, for example, they could potentially use that information to impersonate an organisation you have recently dealt with. 

For an Isle of Man resident, that could mean a message appearing to come from a bank, delivery company, travel provider, utility company or another service you use. 

For a business, it could be an email appearing to come from a supplier, customer or colleague. 

You might receive a message claiming: 

  • Your airport parking payment has failed 
  • You have an outstanding parking charge 
  • Your recent booking needs to be confirmed 
  • Your account has been suspended 
  • You need to verify your details 

The information included in the message may look legitimate because some of it is legitimate. 

But that doesn’t mean the message is. 

Never assume a message is genuine just because it contains personal information about you. 

  1. Credential stuffing and account takeovers

Another risk comes from password reuse. 

If an email address appears in a leaked dataset, criminals can use automated tools to test whether the same email address and password combination works elsewhere. 

That could include: 

  • Personal email accounts 
  • Business accounts 
  • Online shopping accounts 
  • Subscription services 
  • Banking and financial services 
  • Remote working and VPN accounts 
  • Microsoft 365 and other cloud-based business systems 

This is particularly relevant for Isle of Man businesses, where teams may work across offices, from home or while travelling between the Island and the UK. 

The more services a business relies on online, the more important it becomes to protect the accounts sitting behind them. 

This type of attack is known as credential stuffing. 

The problem is simple: if you use the same password across multiple services, one breach can potentially put several accounts at risk. 

That’s why using a unique password for every important account is one of the simplest ways to reduce your exposure.

  1. SMS and phonescams

Leaked phone numbers can also be used for smishing – phishing carried out through SMS – or phone-based scams, sometimes called vishing. 

Again, the more information criminals have, the more convincing the approach can appear. 

You could receive a text claiming to be from a parking provider, bank or travel company, followed by a request to make a payment or click a link. 

Or you could receive a phone call from someone claiming to be investigating suspicious activity on your account. 

For individuals and businesses on the Isle of Man, it’s worth remembering that being a relatively small community doesn’t make you invisible to cyber criminals. 

In fact, information gathered from different sources can help criminals build a surprisingly detailed picture of a person or organisation. 

The message may sound convincing. 

That doesn’t make it genuine. 

If you’re unsure, end the call or ignore the message and contact the organisation directly using a phone number or website you know is genuine. 

What about public Wi-Fi? 

The MAG incident also highlights an important question around the information businesses collect through public Wi-Fi and online portals. 

Public Wi-Fi itself isn’t automatically unsafe. 

However, businesses providing guest networks need to think carefully about both how the network is secured and what customer information they collect and store. 

This applies to businesses everywhere, including Isle of Man organisations offering Wi-Fi to customers, visitors or guests. 

Many public Wi-Fi networks use a captive portal – the sign-in page you see before you’re allowed online. 

This might ask for information such as your: 

  • Name 
  • Email address 
  • Mobile number 
  • Booking details 

That information can be useful for providing the service, but it also becomes another dataset that needs to be properly protected. 

The same principle applies to customer information collected through websites, booking systems, contact forms and other online services. 

The less unnecessary data you collect, the less data there is to lose. 

Public Wi-Fi isn’t just a Wi-Fi security issue 

For businesses, there are really two things to consider: 

The connection 

Public networks should be configured securely and designed to prevent users from accessing each other’s devices or internal systems. 

The data 

If a guest Wi-Fi portal collects personal information, that data needs to be securely stored, protected and only retained where there is a genuine reason to do so. 

For Isle of Man businesses, this is particularly important when customer and visitor information is being collected through everyday digital services. 

A free Wi-Fi network might seem like a simple customer convenience, but behind that sign-in screen could be another database containing valuable personal information. 

What can you do if your details have been leaked? 

If your information appears in a publicly available data breach, don’t panic. 

But do take it seriously. 

Be more cautious with unexpected messages 

If you receive an email, text or phone call referring to something you’ve recently done, don’t automatically trust it. 

Especially if it asks you to: 

  • Click a link 
  • Download an attachment 
  • Make a payment 
  • Share a password 
  • Provide security information 

Instead, go directly to the organisation’s official website or app and check your account there. 

For businesses, make sure employees know the same rule applies to work accounts. 

An email that appears to come from a customer, supplier or director can still be a phishing attempt. 

Turn on Multi-Factor Authentication 

MFA adds another layer of protection to your accounts. 

Even if someone manages to obtain your password, they still need the additional authentication method to gain access. 

Start with your most important accounts, particularly email, banking and business systems. 

For businesses, MFA should be considered a standard part of protecting Microsoft 365, cloud applications, remote access and administrator accounts. 

Use unique passwords 

If you use the same password across multiple accounts, now is a good time to change it. 

A password manager can make this much easier by generating and storing unique passwords for you. 

You don’t need to remember dozens of complicated passwords yourself. 

For businesses, encouraging employees to use unique passwords is a simple but important part of reducing the impact of a compromised account. 

Be careful on public Wi-Fi 

Public Wi-Fi can be useful, whether you’re working from a café, hotel, airport or another public location, but avoid carrying out sensitive activities on networks you don’t trust where possible. 

Make sure your device is up to date, use secure websites and consider using a reputable VPN when connecting through public networks. 

Most importantly, don’t assume that the presence of a Wi-Fi password automatically means the network is secure. 

The bigger lesson for Isle of Man businesses 

The important point isn’t just what happened in one particular breach. 

It’s that a data breach can have a much longer lifespan than businesses or individuals expect. 

Once information is stolen, it can be copied, shared and reused. 

For Isle of Man businesses, that means cyber security isn’t just about protecting your systems from an attack today. 

It’s about thinking about what information you hold, where it goes and what could happen if it fell into the wrong hands. 

That could be customer contact details, employee information, supplier records, booking information, email addresses or data collected through your website and guest Wi-Fi. 

And with many local businesses relying on cloud platforms, online payments, remote access and digital communication every day, there are more opportunities for information to move between systems. 

So ask yourself: 

  • What data are you collecting? 
  • Where is it stored? 
  • Who has access to it? 
  • How long do you keep it? 

And perhaps most importantly: 

  • What would happen if it was published tomorrow? 

Cyber security is about reducing the opportunities for criminals at every stage, not just trying to stop them at the front door. 

For individuals, that means protecting your accounts, being cautious with unexpected messages and treating your personal information as something worth protecting. 

For businesses, it means looking beyond firewalls and antivirus software and considering the wider security of your data, systems, people and processes. 

At Noventre, we help Isle of Man businesses identify vulnerabilities, protect their systems and data, and put practical cyber-security measures in place that work alongside the way they operate. 

For advice on protecting your business or staying safer online, get in touch with the Noventre team today.