Back to Blog

8.7 Million Travelers’ Data Stolen – What Small Businesses Must Do

8.7 Million Travelers’ Data Stolen – What Small Businesses Must Do
August 28, 2026|David Velarde RoblesDavid Velarde Robles

The breach in a nutshell

Earlier this week Manchester Airports Group (MAG) confirmed that an unnamed threat actor stole personal data belonging to about 8.7 million people who used its airports. The stolen information includes email addresses, phone numbers, post‑codes and vehicle registration plates – data collected through parking, lounge and Fast Track bookings as well as Wi‑Fi sign‑ins.

No payment details were taken and the airport’s operations continue as normal, but the breach highlights a very real risk: once personal details are out in the open, scammers can build precise profiles and launch targeted fraud attempts. For a small business that stores customer contact information, the lesson is clear – any breach that exposes personal details can hit you just as hard as a headline‑making airport incident.

Why this matters to your small business

You might think “that’s a big airport, not my bakery or boutique.” The truth is that the type of data compromised at MAG is the same kind many small businesses already keep: names, email addresses, phone numbers and, in some cases, vehicle registration numbers for deliveries or parking permits.

If a breach of that size can happen to a major airport operator, it can happen to a local shop that uses a simple spreadsheet or an off‑the‑shelf booking system. The consequences are similar:

  • Fraud risk – criminals can send convincing phishing emails or SMS messages that appear to come from your business, asking for payment or login details.
  • Reputation damage – customers lose trust when they hear their data may have been exposed.
  • Regulatory pressure – the Dutch GDPR and European privacy rules require you to protect personal data and to report breaches promptly.

In short, data security is no longer a “nice‑to‑have” for large organisations only; it’s a baseline expectation for every business that handles personal information.

Three practical steps you can take today

1. Encrypt data at rest and in transit

Encryption is like locking your data in a safe that only you have the key for.

  • At rest – make sure any database, file server or cloud storage where you keep customer details is encrypted. Most modern hosting providers offer this as a built‑in option; ask your provider to confirm it’s enabled.
  • In transit – whenever data moves between your website, email system or internal tools, use HTTPS (the padlock you see in the browser) or a secure VPN. Even simple email communications should be sent over encrypted channels whenever possible.

If you’re not sure whether encryption is active, a quick check with your web host or a short audit from a security specialist can reveal gaps.

2. Verify and test backups regularly

Backups are your safety net, but they only help if they actually work.

  • Automate – set up daily automated backups of all customer data. Store the copies in a separate location (e.g., a different cloud region or an offline drive).
  • Test – once a month, restore a small sample of data from the backup to confirm you can retrieve it quickly and completely.
  • Versioning – keep several recent versions so you can roll back to a point before any accidental deletion or ransomware encryption.

A reliable backup strategy means you can recover quickly without paying a ransom or losing valuable customer information.

3. Create a simple incident‑response checklist

When a breach occurs, panic can slow you down. A concise, step‑by‑step checklist keeps you focused.

Step What to do
Detect Identify the source of the breach (e.g., a compromised account, a vulnerable system).
Contain Isolate the affected system – disconnect it from the network if needed.
Assess Determine what data was accessed and how many customers are affected.
Notify Inform affected customers with clear instructions (e.g., watch for phishing attempts).
Report If required by law, report the incident to the Dutch Data Protection Authority within 72 hours.
Recover Restore data from verified backups and patch the vulnerability.
Review Conduct a post‑mortem to improve security controls and update the checklist.

Keep this checklist in an easily accessible place (a shared drive or printed copy) and review it with your staff at least once a year.

FAQ

Q: I only keep a small Excel file with customer emails. Do I still need encryption?
A: Yes. Even a simple spreadsheet can be opened and copied if someone gains access to your computer or cloud storage. Most spreadsheet programs now offer password‑protected encryption – enable it.

Q: How often should I change passwords for systems that store customer data?
A: Aim for every three to six months, and use a password manager to generate strong, unique passwords. Enable two‑factor authentication (an extra step like a code sent to your phone) wherever possible.

Q: What if a customer contacts me saying they received a suspicious email that looks like it came from my business?
A: Follow the “Notify” step in the checklist. Tell the customer not to click any links or share passwords, and advise them to forward the email to you for verification. Internally, investigate whether any of your accounts were compromised.

How IT Move NL can help

Protecting customer data may feel overwhelming, especially when you’re busy running your business. Our Security & Protection service is designed for small‑business owners who need practical, hands‑on help without the jargon.

We can:

  • Audit your data handling – identify where personal information lives and how it’s protected.
  • Implement strong encryption – set up encryption for all storage and communications, tailored to the tools you already use.
  • Set up automated, tested backups – ensure you have reliable copies of your data and that they’re restored smoothly when needed.
  • Create a ready‑to‑use incident‑response checklist – a clear, step‑by‑step plan that your team can follow the moment something goes wrong.

Think of us as the friend who checks the locks on your doors, backs up the keys, and knows exactly what to do if a window is broken. Reach out today for a free security review and make sure your customers’ data – and your peace of mind – stay safe.


Sources:

David Velarde Robles
David Velarde Robles

He/Him · AWS Certified Solutions Architect | Cloud Engineer @ Essent

Cloud Engineer at Essent B.V. with 10+ years of experience in the tech industry. AWS Certified, passionate about serverless architectures, Infrastructure as Code, and DevOps. Proficient in TypeScript, Python, and Terraform. Based in Amersfoort, Netherlands.

>

STAY IN THE LOOP

// Cloud, AI & DevOps insights — straight to your inbox.

>

No spam. Unsubscribe anytime.

Share this article:

Need help with your cloud infrastructure?

Our team of experts is ready to help you navigate the complexities of modern cloud architecture.

Get in Touch