A new assessment identifies suppliers as the biggest cyber security weakness across UK aviation, with credentials and ransomware exposure concentrated among third parties.

A new assessment of cyber security across UK aviation has highlighted a significant gap between the resilience of airport operators and the suppliers supporting them, with exposed employee credentials and ransomware leak-site appearances concentrated among third parties.
The assessment examined 43 UK airport operator websites representing 54 airports, alongside 51 organisations supporting those airports. It used only information available on the public internet and did not access or test air traffic, baggage, passenger screening or airside systems.
According to Hugh Cox, Chief Information Officer at Huro Data, the immediate priority for airport operators should be to investigate the cyber exposure of their supply chains, rather than focusing solely on their own websites.
Cox recommends four actions, starting with identifying which suppliers have appeared on ransomware leak sites and understanding what access those organisations hold.
Three of the 51 suppliers assessed appear in leak-site data, while no airport operator does. Cox stressed that a listing does not necessarily indicate a current compromise, as data can be stale or relate to another part of a corporate group.
However, he said the finding should prompt airport operators to ask suppliers questions immediately.
The second priority is to challenge ground handling, passenger processing and airfield technology suppliers about how they protect employee credentials. These three classes account for 1,068 of the 1,162 exposed employee credential records identified across UK aviation.
The findings are particularly concentrated in ground operations and equipment and airfield technology. Six of seven ground operations organisations assessed and seven of eight equipment and airfield technology organisations were affected.
Cox said these conversations do not necessarily require security specialists on either side, highlighting the need for airport operators to understand the exposure within critical third-party services.
UK aviation cyber security exposure extends beyond airport operators
Email security remains another weakness for airport operators. Seventeen of the 43 airport operators assessed, equivalent to 40 per cent, cannot instruct receiving mail systems to reject an email forged in their name.
Cox described this as the one measure where airports are performing worse than their suppliers and argued that it is also one of the simplest improvements to make.
He recommends that airport operators publish and enforce an email security policy, with the required change involving a DNS record rather than an operational aviation system.
The issue also carries a passenger-facing dimension. Cox noted that passenger information obtained through previous cyber incidents could make fraudulent communications more convincing, particularly where travellers are accustomed to receiving legitimate messages about parking, lounges and disruption.
The assessment’s fourth immediate recommendation is for airport operators to establish a clear route for reporting security problems.
Cox said none of the 43 airport operators assessed currently provides such a route, while 90 of the 94 organisations examined across the wider study have no obvious reporting mechanism.
For security researchers or other parties identifying vulnerabilities, the absence of a clear disclosure route can make it harder to report issues privately before they become public.
Why suppliers are emerging as the weak point
Cox argues that the assessment points to a structural issue in how aviation cyber security responsibilities are currently distributed.
“Airports are designated critical national infrastructure. They have a named regulator in the Civil Aviation Authority, they are assessed against the NCSC’s framework, and it shows in the results. A ground handler, a parking reseller or a lounge operator usually carries none of that, and that shows too. The perimeter was drawn in 2018 and the risk has since walked across it.”
In his view, regulation and accountability have strengthened airport operators while leaving a broader supplier ecosystem outside the same level of scrutiny.
The assessment also found that suppliers with passenger-facing websites can have a different cyber security profile from less visible technical organisations.
Cox said nobody is consistently looking at these estates, while airport websites receive attention from passengers, journalists and regulators.
The result, he said, can be counter-intuitive. Suppliers holding passenger data may score higher than organisations without such data because consumer-facing companies maintain consumer-facing websites, whereas engineering suppliers may have websites that have received little attention for years.
Workforce structures may add another layer of exposure. Cox said this is an explanation rather than a directly measured finding, but argued that ground handling and screening operations often involve large, distributed and shift-based workforces, alongside high turnover and the use of shared or personal devices.
Infostealer malware can harvest credentials from individual devices. A larger workforce using more devices, with greater staff turnover, can therefore create more opportunities for credentials to enter criminal data collections.
This is particularly relevant where employees may hold access to check-in platforms, baggage handling systems or airfield technology, although the assessment did not establish that any such access has been used to compromise operational systems.
Cox also highlighted what he described as an accountability gap between airports and their suppliers.
“The structural finding is that the risk does not sit where the accountability sits. Airports get named when something goes wrong. The exposure is one layer down, with organisations most passengers have never heard of. The Cyber Security and Resilience Bill would bring designated suppliers inside the regime, and on this evidence that is the right direction.”
The findings do not indicate a compromise
Cox stressed that the assessment should not be interpreted as evidence that any airport or supplier has been compromised.
The exposed credentials identified in the study are circulating in public collections, with most having been harvested by malware from individuals’ devices. The assessment cannot establish whether those credentials remain valid.
Similarly, the appearance of a supplier in ransomware leak-site data does not by itself demonstrate that the organisation is currently compromised or that aviation systems have been accessed.
The assessment was conducted without logging into systems or interacting with operational infrastructure. No air traffic, baggage, passenger screening or airside systems were accessed as part of the work.
For airport operators, the findings therefore point towards a need to improve visibility and accountability across the supply chain, rather than suggesting that operational aviation systems have already been breached.
The immediate measures identified by Cox focus on practical checks: establishing whether suppliers have appeared on leak sites, understanding how credentials are managed, strengthening email authentication and creating clear vulnerability reporting routes.
The wider issue is whether airport cyber security can remain effective when a growing proportion of aviation services are delivered through organisations outside the airport’s direct regulatory perimeter.
The assessment suggests that improving resilience will require airport operators to look beyond their own infrastructure and apply greater scrutiny to the organisations that support passenger processing, ground operations and airfield technology.
Read more about the report here.




No comments yet