A customer data breach does not need to start in the CRM to become a customer experience crisis.
A recent attack on Manchester Airports Group (MAG) attack showed how information collected through everyday services such as parking, Wi-Fi and Fast Track can become part of a much larger security and governance problem when data is scattered across systems, teams and third-party environments.
The attack exposed the personal data of around 8.7 million people, with the stolen information later published online after MAG refused the attackers’ ransom demand. Beyond the immediate security implications, the incident raises a more fundamental question for enterprises: do they actually know where their customer data is, who can access it, and how exposed it becomes as it moves between systems?
Sean McConnell, GovTech Lead at Datactics, told CX Today that the attack is part of a wider pattern.
“This is not a one off. It’s the latest in a pattern of these sort of breaches that many public sector services, many public services are not well equipped to manage the data or to protect the data that they rely on.”
The problem extends across the private sector, too, as enterprises accumulate customer information across legacy platforms, business units, applications, APIs and operational services.
Fragmented Data Creates Opportunities for Attackers
The more places customer data appears, the harder it becomes to apply security controls consistently, McConnell warned.
“The fragmentation of these systems and the bad data that is a result of those fragmentations, they simply make breaches more likely because they create weak points in the process.”
Those weaknesses can emerge when different systems use different authentication methods, security configurations or access controls.
“If that fragmentation, for example, includes things like security controls, different systems using different security controls, different authentication, different manners of configuring, these attackers really only need to identify one soft spot in order to get access to everything, or at least to get access to more than they should, which is nothing.”
For customer experience leaders, this makes data governance a much broader concern than simply maintaining accurate customer records.
Different teams may classify the same information differently. Older systems may remain connected to live data, permissions may vary between applications and data may be duplicated without a clear understanding of where every copy resides.
“This whole level of fragmentation introduces inconsistency and inconsistency is a weakness that can be taken advantage of,” McConnell said.
After a Breach, Visibility Becomes Critical
Once customer data has been stolen, good governance cannot put it back. It can determine how quickly an organization understands what happened.
McConnell argued that poor-quality data makes that process significantly harder.
“Messy data increases exposure and makes those breaches harder to contain. It creates a larger attack surface and makes it more difficult to assess the damage once an attack or a breach has happened.”
Duplicate records can mean duplicate exposure, as some copies may sit inside well-protected environments, while others could be stored in less secure systems. The result is uncertainty over exactly what attackers accessed.
“If you’re keeping copies of data, are they out of date? Have we got the most recent versions that have been made visible to these attackers?” McConnell said.
That can quickly become a customer communications problem. An organization needs to establish what information was compromised, which customers were affected, and whether the exposed records were current.
“Messy data that’s caused by messy governance means there’s messy visibility,” McConnell said. “And that is a real problem and a real challenge and a really bad position for any organization, whether it’s public or private to be in.”
The AI Layer Adds Another Risk
The governance problem becomes more consequential as enterprises connect AI systems to customer and operational data.
AI can process huge volumes of information, but it cannot automatically resolve the underlying problems created by fragmented or inaccurate records.
“AI is really only as trustworthy as the data behind it,” McConnell said.
Incomplete records can lead AI systems to fill gaps with assumptions. Conflicting records can produce inconsistent outputs. Incorrect metadata can cause systems to interpret information incorrectly.
“Weak governance where content records are not fully filled in leaves it exposed for AI to hallucinating answers or at least trying to put answers in there, making assumptions.”
The issue becomes particularly relevant as AI systems influence customer interactions and operational decisions. An inaccurate customer record is one problem when viewed by an employee. It can become a different kind of problem when an automated system uses that record to determine what happens next.
“When data comes from multiple unaligned systems, it’s going to receive AI or humans will receive incomplete versions of the same person or event or incompatible versions of those things,” McConnell said.
Fix the Data Before Adding More Intelligence
For executives responding to a breach, McConnell says security controls and data quality need to be addressed together.
“It is no good to have a fortress where you have got the gates that are impenetrable. You have the crown jewels hidden in the safest vault, but you have the back door lying open and you have the combinations that have all sitting out in the open.”
That means understanding where sensitive information resides, who owns it, how it is replicated, which systems can access it, and whether controls are applied consistently.
“If your data is bad then that is not a good sign that things are good elsewhere, things are possibly bad elsewhere,” McConnell warned.
For CX leaders, the Manchester Airport breach offers a warning that customer data governance cannot stop at the CRM boundary. Parking records, Wi-Fi registrations, loyalty data, support interactions, payment information, and operational systems can all contribute to the customer record.
As those systems become increasingly connected to AI, knowing where customer data lives may become as important as protecting the systems that store it.