Search Beyond News…

UK airport cyber‑attacks spark phishing wave targeting Italian travellers, highlighting cybersecurity risks for the aviation sector

Executive summary: UK airport IT systems were hit by cyber‑attacks that enabled threat actors to launch phishing calls and messages aimed at Italian passengers who had recently transited through those airports. The incident exposes personal data of travellers to theft, threatens confidence in airport digital services, and may trigger regulatory scrutiny under EU cybersecurity and data‑protection rules.

Who is involved: UK airport operators, Italy’s consumer protection agency (presumably the Italian Data Protection Authority or similar), cyber‑criminal groups, and affected Italian travellers.

Likely next: Authorities will issue updated security guidance, airports will enhance network monitoring and passenger‑Wi‑Fi safeguards, and regulators may investigate compliance with NIS2 and GDPR obligations.

On 30 August 2026, Italy’s consumer protection agency warned passengers who had transited through UK airports not to respond to unsolicited phone calls after a series of cyber‑attacks compromised airport IT systems. The attackers are believed to be harvesting personal data and credentials via fake calls and malicious links, while also cautioning against using unsecured free Wi‑Fi at the terminals. The advisory underscores the growing threat of socially engineered attacks that exploit travel‑related data and the need for stronger security measures at airport networks.

Timeline

Analysis — what this means

Likely next events

Sectors affected

Regulatory implications

Historical parallels

Sources

Related cases

Browse the full archive →