Skip to Content

8.7M Records Exposed: The Risk of Forgotten Systems

A guest Wi-Fi sign-up and a booking database show why peripheral systems deserve the same care as critical ones
August 28, 2026 by
8.7M Records Exposed: The Risk of Forgotten Systems

An incident that started far from the financial system

Manchester Airports Group, the group that operates the Manchester, Stansted, and East Midlands airports, publicly confirmed a cyber incident in which an unauthorized third party accessed customer data. Around 8.7 million people were impacted, and the information was reportedly tied to bookings and to airport Wi-Fi registrations, according to reporting by The Record.

According to the group itself, in the vast majority of cases the data accessed was reportedly just the email address, with no detail on the period covered, and the case remains under investigation with oversight from data protection authorities, according to Infosecurity Magazine. No one on the outside knows what happened inside that operation, and that is precisely why the episode is worth more as a mirror of format than as a technical case study.

The detail that catches the attention of partners and C-levels lies in the origin of the information: Wi-Fi registration and the bookings database, two assets that almost never show up on a company's list of critical systems. If a simple visitor form became headline news in your operation, how many people would end up on the notification list?

Why peripheral systems concentrate so much risk

Every company, from 5 to 5000 employees, has its equivalent of the Wi-Fi registration: the scheduling form on the website, the contact database in the CRM (Customer Relationship Management system), the spreadsheet of registrants from the last event, the newsletter platform paid for on the corporate card. These assets are born to solve a specific marketing or customer service problem, then start holding real people's data, and rarely enter the same review cycle as the ERP or the file server.

There is also the third-party factor, which grows quietly. Third-party involvement appeared in 30% of the breaches analyzed in 2025, double the previous year, according to Verizon's Data Breach Investigations Report. Integrations, plugins, and vendor dashboards touch the customer database just as naturally as an internal user does, almost always without the same level of control.

Two practical fronts for protecting the customer database

The good news is that this type of risk responds very well to organization, and the first front costs more discipline than budget: mapping where customer data actually resides. A simple inventory, with system, owner, data type, and a list of who has access, already reveals duplicates and forgotten accounts. Next comes network segmentation, which separates the visitor Wi-Fi from corporate systems, so that a marketing registration does not act as a hallway to the finance server.

The second front is identity. MFA (Multi-Factor Authentication) on administrative dashboards, on corporate email, and on third-party integrations blocks most of the improper access that starts with a reused password. Add to that the principle of least privilege, periodic account reviews, and the immediate removal of access for anyone who has left the company or ended a contract, practices that underpin any serious managed cybersecurity.

Does your company know exactly where your customers' data is?

If the answer takes more than a few minutes, that is the best destination for your next hour of meeting time. Start by listing the ten systems that touch customer data and mark, on each line, which one has MFA enabled, which one had a backup verified in the last quarter, and which one has an owner with a first and last name. The exercise usually reveals two or three surprises that are much better to find internally.

From there, the path is incremental and predictable: segment the visitor network, standardize identity and access, enable EDR with continuous monitoring, keep patch management on a cycle, test the backup at a scheduled time, and train the team a few times a year. Companies backed by managed IT support gain exactly that, cadence and record-keeping, with each item leaving the realm of good intentions and entering the realm of a documented process. No environment is immune, and even so the distance between a manageable scare and a crisis usually fits within these simple choices, made calmly and before the incident.

References

Frequently asked questions

What are peripheral systems and why do they matter for data protection?

Peripheral systems are the tools that hold data without being considered critical by the company, such as visitor Wi-Fi, scheduling forms, event spreadsheets, and newsletter platforms. They usually stay outside the security review cycle, even though they store real customers' information. Treating them within the same inventory as core systems is the first step to reducing this risk.

Is a leak of email addresses alone really serious?

Yes, because a broad email database associated with a known context fuels far more convincing phishing campaigns against customers, vendors, and employees. Beyond the technical risk, there is the cost of notifying data subjects and exposure before regulators in markets governed by GDPR or LGPD. The reputational impact with those who entrusted their data also weighs on the bill.

Where do I start if my company has never mapped where customer data is?

Start with a simple inventory that records each system holding customer data, the person responsible for it, the type of information stored, and the list of who has access. Then apply multi-factor authentication on administrative dashboards, separate the visitor network from the corporate network, and confirm that a tested backup exists. This initial set already raises the level of protection considerably without requiring major investments.

To turn this map into a plan, Zamak offers a Strategic IT Assessment, No Strings Attached.

8.7M Records Exposed: The Risk of Forgotten Systems
August 28, 2026
Share this post
Tags
Archive