UK airport cyber‑attacks spark phishing wave targeting Italian travellers, highlighting cybersecurity risks for the aviation sector
Executive summary: UK airport IT systems were hit by cyber‑attacks that enabled threat actors to launch phishing calls and messages aimed at Italian passengers who had recently transited through those airports. The incident exposes personal data of travellers to theft, threatens confidence in airport digital services, and may trigger regulatory scrutiny under EU cybersecurity and data‑protection rules.
Who is involved: UK airport operators, Italy’s consumer protection agency (presumably the Italian Data Protection Authority or similar), cyber‑criminal groups, and affected Italian travellers.
Likely next: Authorities will issue updated security guidance, airports will enhance network monitoring and passenger‑Wi‑Fi safeguards, and regulators may investigate compliance with NIS2 and GDPR obligations.
On 30 August 2026, Italy’s consumer protection agency warned passengers who had transited through UK airports not to respond to unsolicited phone calls after a series of cyber‑attacks compromised airport IT systems. The attackers are believed to be harvesting personal data and credentials via fake calls and malicious links, while also cautioning against using unsecured free Wi‑Fi at the terminals. The advisory underscores the growing threat of socially engineered attacks that exploit travel‑related data and the need for stronger security measures at airport networks.
Timeline
- — Appello agli italiani transitati per aeroporti inglesi: “Non rispondete a chiamate sospette” (la Repubblica — Economia)
Analysis — what this means
Likely next events
- UK National Cyber Security Centre to publish updated guidance for airport operators by 5 September 2026.
- Italian Ministry of Foreign Affairs to issue a travel advisory for passengers transiting UK airports by 2 September 2026.
- Major UK airports (Heathrow, Gatwick, Manchester) plan to deploy mandatory multi‑factor authentication for free Wi‑Fi access by Q4 2026.
- Action Fraud expects a rise in reported phishing calls related to UK airports, with a threshold of 500 incidents by end September 2026.
Sectors affected
- Airport operations
- Cybersecurity services
- Travel insurance
- Data protection consulting
Regulatory implications
- EU NIS2 Directive may require operators to report significant cyber incidents within 24 hours, potentially increasing compliance costs for UK airports.
- Under GDPR, any personal data breach affecting EU residents must be notified to the Italian Data Protection Authority within 72 hours, raising liability exposure.
- UK’s Network and Information Systems Regulations 2018 could be revisited to mandate stronger authentication for public Wi‑Fi networks in transport hubs.
Historical parallels
- 2017 WannaCry ransomware attack disrupted UK NHS hospitals, highlighting vulnerability of public‑sector IT to cyber threats.
- 2019 phishing campaign targeted passengers of several European airlines, stealing loyalty‑program credentials via fake booking emails.
- 2021 Colonial Pipeline ransomware attack caused fuel supply shortages in the U.S., showing how critical infrastructure attacks can ripple to consumer services.
Sources
- Appello agli italiani transitati per aeroporti inglesi: “Non rispondete a chiamate sospette” — la Repubblica — Economia