Skip to main content
Emerging ThreatsData Breaches

Hackers Breach Manchester Airports Group, Exfiltrate Traveler Data

Bustling airport terminal with travelers and check-in counter in normal operation.

“The incident has not resulted in any operational disruption,” Manchester Airports Group said, assuring passengers that flights and on‑site services continued to run even as the company confirmed hackers removed customer records from its systems.

Manchester Airports Group's disclosure and immediate actions

Manchester Airports Group (MAG) disclosed that an unknown intruder breached its systems and exfiltrated customer data connected to services at Manchester, London Stansted and East Midlands airports. MAG said it moved quickly to contain the intrusion: it restricted access to the affected systems, engaged external experts, and notified law enforcement. The company also temporarily suspended its online “Manage My Booking” service and is directing customers to use its phone line instead.

What data was taken — and what was not

MAG stated the stolen records include Wi‑Fi sign‑ups at the three airports and data related to car park, lounge and Fast Track bookings. The list of compromised items, as disclosed by the company, includes customers' email addresses, phone numbers, vehicle registration numbers and postcodes. MAG said customer payment details were not accessed during the intrusion.

Service impact and customer guidance

Despite the data theft, MAG stressed there was no operational disruption: “Airport operations remain unaffected and customer parking services continue to operate normally.” The company said it has contacted impacted customers directly and advised all potentially exposed individuals to be alert for suspicious communications and to avoid clicking on links arriving by email or SMS. MAG reminded customers that it will never ask for payment card information, banking details or passwords, and encouraged people to reject and report any attempts to obtain such information.

Scope, public reporting, and extortion status

MAG did not disclose the number of affected customers. Local media outlets reported that data for up to 8.9 million travelers may have been exposed, citing private statements attributed to MAG; BleepingComputer noted it was unable to confirm that figure. At the time of reporting, no ransomware or data‑extortion groups had publicly claimed responsibility for the attack.

What this means for travelers, security teams, and regulators

  • Travelers: Those who booked Wi‑Fi, parking, lounge or Fast Track services at the three airports should watch for phishing attempts and verify any unusual requests through MAG’s phone line or official channels. MAG’s direct contact to impacted customers is the company’s stated channel for notifications.
  • Security teams and airport IT leaders: MAG’s account of restricting system access and engaging external experts reflects standard containment steps; teams will also need to validate that interfaces handling bookings and Wi‑Fi sign‑ups have been purged of attacker access and that credentials or session tokens have been rotated where relevant.
  • Regulators and law enforcement: MAG has notified law enforcement and publicly encouraged affected people to follow the National Cyber Security Centre’s post‑breach recommendations. The nondisclosure of an exact affected‑customer count and the unconfirmed media figure of 8.9 million are likely to shape inquiries and any required reporting.

The incident also surfaced a technical observation present in the reporting: once attackers achieve valid credentials, prevention can fall sharply. The Blue Report 2026 — cited in the source material — measures defenses technique by technique across 338 million simulations and underscores the difficulty of stopping malicious activity after initial access.

MAG is the UK’s largest airport operator, owning Manchester, London Stansted and East Midlands airports, which together handle over 66 million passengers a year. The company employs 40,000 people and reports annual revenue of £1.5 billion.

MAG’s immediate containment and public guidance aim to limit further harm. The outstanding facts the company has not disclosed — most notably the total number of affected customers — and the absence of any extortion claims at the time of reporting leave key questions open: how many travelers were exposed, whether the stolen records will appear in criminal markets, and which systems allowed the initial access. Until those details are shared by MAG or revealed through law‑enforcement action, travelers and institutional responders must rely on the company’s notifications and the defensive steps it has described.

Source: BleepingComputer — Manchester Airports Group says hackers stole travelers' data