Skip to main content
Emerging ThreatsData Breaches

Manchester Airports Group Breach Exposes 8.7 Million Customers' Data

Blurred tech equipment in foreground, with people in airport parking area behind.

"At no point has passenger safety or aviation security been compromised," said Manchester Airports Group in response to a recent cybersecurity incident that exposed customer records across the operator's three UK airports.

What Manchester Airports Group disclosed

Manchester Airports Group (MAG) confirmed that "a quantity" of data was stolen during a cybersecurity incident that affected systems used for car parking, lounge and fast track bookings, and the group's public Wi‑Fi services. MAG said it "immediately contained the risk" and brought in external expertise to advise on next steps. The company also stated it has "informed and are working with the relevant authorities."

The group noted that none of its airports experienced operational disruption and that the incident did not compromise passenger safety or aviation security. MAG also confirmed the affected system does not store bank or payment details. As a precaution, it temporarily revoked access to its Manage My Booking service; customers with bookings due within 72 hours of MAG's statement were told to contact customer services to amend or cancel.

Data types affected

  • Email addresses
  • Phone numbers
  • Vehicle registrations
  • Postcodes

MAG said these are the data types "currently known to be compromised" and cautioned that not all data types will be compromised for all affected customers.

Scale and the public messaging

MAG did not specify the full scale of the breach in its public statement. The company reportedly told local newspaper Manchester Evening News that most of the 8.7 million individuals affected only had their email addresses exposed. MAG highlighted that, across its airports, the company recently celebrated 66 million passengers in a year—context the operator included alongside its disclosure.

Customer impact and response

Some customers were contacted directly; The Register said a few of its readers alerted the outlet after receiving notifications. One reader complained that being charged £80 for five days' parking at Stansted and then receiving an email that his personal data had been stolen "added insult to injury."

MAG urged customers to be extra vigilant to potential phishing attempts while the investigation continues and apologised for any inconvenience or concern caused. When The Register requested further detail, a MAG spokesperson responded with the same statement published online.

How technologists, regulators, and customers are responding

Technologists and security teams: MAG's statement that it "immediately contained the risk" and engaged external expertise suggests the operator has initiated incident response and forensic activity; heightened monitoring for phishing and follow‑up notifications will be central while investigations continue.

Policymakers and regulators: MAG said it has informed and is working with the relevant authorities, signalling formal reporting and potential regulatory engagement following the disclosure.

End users and customers: Affected customers have been contacted and are being advised to watch for phishing attempts. Manage My Booking access was temporarily revoked as a precaution, and customers with imminent travel within 72 hours were directed to customer services for booking changes.

MAG operates Manchester Airport, Stansted Airport in Cambridgeshire, and East Midlands Airport in Derbyshire. The company maintains that no bank or payment details were stored on the affected system and affirmed there was no operational impact to the airports themselves. Outside of its public statement and the report to Manchester Evening News about the 8.7 million figure and the predominance of email‑only exposure, MAG has not provided further public detail about the mechanics of the intrusion or the specific number of customers affected per data type.

The incident leaves a narrow, concrete set of facts: a credentialed operator acknowledged a data theft, certain personal identifiers are known to be exposed, operational and payment systems were not affected, and affected customers are being contacted. What remains is the follow‑through—the outcome of MAG's external forensic review, the notifications from relevant authorities, and whether further details about the scale and root cause will be released as the investigation proceeds.

Original story: https://www.theregister.com/security/2026/08/27/cybercrooks-jet-off-with-manchester-airports-group-customer-data/5292943