Sector study · scan of 2 September 2026

99% of exposed staff credentials in UK aviation’s public web estate sit with suppliers, not airports

We looked at 43 UK airport-operator websites — 54 airports — and 51 organisations those airports depend on, the way anyone on the internet could: from the outside, without logging in or trying a password. No airport operational technology, air-traffic, airline, baggage or screening system was touched. The operators look reasonable. The organisations they depend on do not.

Covered by International Airport Review, 3 September 2026.

10 / 1,152

employee credential records (operators / suppliers)

0 / 3

ransomware leak-site mentions (operators / suppliers)

40%

of airport operator domains do not reject forged email

94

distinct organisations, no overlap, one day

Why two halves

On 27 August 2026 Manchester Airports Group disclosed that about 8.7 million passenger records had been taken from car-park, lounge, Fast Track and wi-fi systems. That was the commercial web estate, not the airside one.

Eleven months earlier, ransomware against Collins Aerospace’s MUSE check-in software disrupted Heathrow, Brussels, Berlin and Dublin. No airport was breached. One shared supplier was.

Those are two different estates. This study measured both, the same day, the same routine.

What we found

Airport operators (43 websites): average 69.2. Ten staff credentials. No ransomware leak-site mentions.

Suppliers (51): average 65.3. 1,152 staff credentials. Three leak-site mentions. Ground operations is the weakest class. 92% of the staff-credential exposure sits in three airside supplier classes.

The one measure on which the airports are worse is email authentication. Forty per cent cannot tell receiving systems to reject mail forged in their name. It is the cheapest finding in either half to fix, and the airport name is the more attractive one to forge.

A combined average of 67.1 hides the split. Do not use it as the headline.

Three of the 94 scores are floors rather than readings: those homepages did not fully serve to the scanner, so part of the assessment could not be completed and the true score can only be the same or higher, never lower. They are counted in every figure above, and their position should be read as provisional.

What this is not

It is not a claim that any airport system has been accessed. We could not see inside one and did not try. It is not a league table. No organisation is named. Nothing here is a verdict.

Where to start

  1. Establish which airports use the three ransomware-mentioned suppliers, and what access they hold.
  2. Ask ground-handling, passenger-processing and airfield-technology suppliers what credential hygiene they operate.
  3. Publish an enforcing email policy — one DNS record, nothing airside.

Read the full report

22 pages, for boards, journalists and the CAA.

Read the full report (PDF, 22 pages)Or check a domain against the same external checks