Skip to main content
Emerging ThreatsData Breaches

Manchester Airports Group Breach Exposes Customer Data

Bustling airport terminal with travelers and blurred departure board.
"This is a significant breach affecting a large number of customers ahead of one of the busiest travel periods of the year for UK airports," said Raghu Nandakumara, VP of industry strategy at Illumio.

What was taken: bookings and contact data across three airports

Manchester Airports Group (MAG) confirmed that an unauthorized third party obtained customer data tied to car park, lounge and Fast Track bookings, and in‑airport Wi‑Fi sign‑ups. The affected locations are Manchester, London Stansted and East Midlands airports. The specific fields accessed included customers' email addresses, phone numbers, vehicle registration numbers and postcodes. MAG said neither it nor the affected system held customers' bank or payment details.

How MAG responded immediately

MAG said it had "immediately contained the risk" and restricted access to the affected systems. The company engaged specialist cybersecurity advisers, notified the relevant authorities and placed its Data Protection team in charge of the response. MAG also contacted affected customers directly and advised them to remain alert for suspicious emails, text messages and phone calls, and to avoid clicking links or opening unexpected attachments.

Operationally, MAG stressed that passenger safety and aviation security were not compromised and that airport operations remained unaffected. All upcoming bookings were said to remain valid; however, MAG suspended its online Manage My Booking service as a precaution. Customers needing to amend bookings due within 72 hours were directed to MAG's customer services team, which MAG said was open on weekdays between 9am and 5pm, while warning that call wait times may be longer than expected.

Illumio's analysis: the immediate exploitation risk and a mitigation reminder

Raghu Nandakumara of Illumio warned that the exposed data increases the risk of targeted phishing and smishing attempts, because attackers can use legitimate travel‑related information to make malicious communications appear convincing. He also suggested a mitigation that is operational rather than speculative: "Measures such as segmentation can help restrict access to critical systems and sensitive data, reducing the risk that a single compromise becomes a wider incident."

Operational impact on passengers and airport security

MAG's statement emphasized continuity: it said passengers should continue to travel as normal because airport operational systems were not affected. At the same time, MAG advised heightened vigilance for communications that could be malicious and warned of possible longer telephone wait times for customers seeking last‑minute amendments.

What this means for technologists, affected customers, and MAG's Data Protection team

  • Technologists and security teams: MAG has restricted access to affected systems and engaged specialist advisers, and Illumio's comment underscores segmentation as a practical control to limit lateral exposure if a system is compromised.
  • Affected customers and travelers: MAG has contacted those affected and advised vigilance for suspicious emails, texts and calls; customers have been told not to click unexpected links or open attachments and that existing bookings remain valid.
  • MAG's Data Protection team and operations staff: the team is overseeing the incident response, coordinating with specialist cybersecurity experts and the relevant authorities while balancing service continuity with the temporary suspension of the online Manage My Booking tool.

The breach lands at a sensitive moment: as Illumio noted, it comes ahead of what is described as one of the busiest travel periods of the year for UK airports. MAG has contained access to the affected systems, engaged outside help and informed customers, but the immediate digital security risk now shifts to whether attackers will use the exposed contact and travel‑related information in convincing phishing or smishing campaigns. MAG's decision to suspend online booking changes and route urgent amendments through a staffed customer service line reflects a defensive posture meant to reduce exposure while the Data Protection team and advisers work.

Original story