Manchester Airports Group breached, millions of customers’ data stolen
Manchester Airports Group confirmed attackers stole customer booking and WiFi signup data affecting about 8.7 million customers across three UK airports.
Manchester Airports Group (MAG) confirmed an unauthorized third party obtained customer data tied to car park, lounge and Fast Track bookings and WiFi sign-ups at Manchester, Stansted and East Midlands airports. Stolen data includes email addresses, phone numbers, vehicle registrations and postcodes; no payment or banking details were held in the affected systems. UK media reported roughly 8.7 million customers affected. The Manage My Booking portal was disabled as a precaution, authorities were informed, and airport operations were not disrupted.
- Data stolen covers car park, lounge, Fast Track and WiFi signup records
- Exposed fields include emails, phone numbers, vehicle registrations and postcodes
- No payment or banking data held in affected systems; aviation security unaffected
- Manage My Booking portal taken offline; customers warned of phishing follow-ups
- Company contained the incident and is working with authorities and specialist advisors
Full article451 words · extracted from helpnetsecurity.com · click to collapse
Someone broke into the systems of Manchester Airports Group (MAG) and walked away with a “quantity” of customer data from three UK airports, the company has confirmed.

The breach hit Manchester, Stansted, and East Midlands airports, after an unauthorised third party obtained a batch of customer information.
“We immediately contained the risk and have been working with specialist advisors and taking appropriate steps to protect our customers and systems. We have informed and are working with the relevant authorities. At no point has passenger safety or aviation security been compromised,” MAG said in its statement.
The exposed information covers car park, lounge, and Fast Track bookings, along with sign-ups for in-airport WiFi. According to the company, the stolen data includes email addresses, phone numbers, vehicle registrations, and postcodes.
“Neither MAG nor the system accessed hold customers’ bank or payment details,” it added.
Passengers with upcoming travel don’t need to do anything, MAG says, and existing bookings remain valid. Airport operations haven’t been disrupted, and parking services continue as usual.
However, the online Manage My Booking portal has been switched off as a precaution. Anyone needing to change or cancel a booking within the next 72 hours has to call customer services instead, and MAG is warning that wait times may be longer than usual.
“We have contacted affected customers directly,” the company noted.
Customers are advised to remain vigilant for suspicious emails, text messages, or phone calls, and to avoid clicking links or opening attachments from unexpected communications.
“Manchester Airports Group will never contact you unexpectedly to request payment card details, banking information, or passwords,” it warned.
UK outlets have reported around 8.7 million customers were caught up in the breach.
“We would like to reassure customers that Manchester Airport Group takes the security of customer information extremely seriously and we apologise for any inconvenience or concern caused,” the company added.
“The swift action taken by Manchester Airports Group to contain the incident and protect its customers is a positive example of how quickly organisations can respond when cyber threats emerge. Crucially, passenger safety and aviation security were not compromised and airport operations continued as normal. However, the incident still highlights how broad the cyber risk landscape can be for organisations handling significant volumes of customer data,” Tim Williams, CEO at Quod Orbis , told Help Net Security.
“While the systems targeted were car parking, lounge bookings and WiFi sign-ups, they were not responsible for flight operations, they formed part of the wider digital environment through which customers interact within the airport. This reinforces the importance of having clear visibility across the entire technology ecosystem, including the systems, applications and external services that sit around core operations,” Williams concluded.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2026/08/28/manchester-airports-group-data-breach/