Data Breach Affects 8.7 Million Customers of Three UK Airports

Data Breach Affects 8.7 Million Customers of Three UK Airports

Manchester Airports Group data breach affected 8.7 million customers at three UK airports, exposing mainly emails, phone numbers, postcodes and vehicle details.

Listen to this article

0:00

Press play to start listening

Manchester Airports Group (MAG) says an unauthorised third party obtained customer data connected with Manchester, London Stansted and East Midlands airports. Around 8.7 million customers were notified about the incident on August 27, 2026.

The affected records came from airport Wi-Fi registrations and bookings for parking, lounges and Fast Track services. According to MAG, the information accessed included email addresses, phone numbers, vehicle registration numbers and postcodes.

MAG told ITV News that the vast majority of the accessed data consisted of email addresses, so not every customer had every listed data field exposed.

Although the breach involved customer information, MAG said neither the company nor the affected system held bank or payment details. Airport operations, flights, and customer parking services continued normally, while passenger safety and aviation security were unaffected.

Customers Warned About Phishing Attempts

Customers began receiving notification emails on Thursday. MAG advised them to be cautious about unexpected emails, calls or text messages claiming to come from one of its airports.

For context, information such as an email address, phone number, postcode and vehicle registration can help criminals make a fraudulent message or call appear credible. Someone posing as an airport employee could refer to a parking booking or vehicle details before requesting payment or account information.

MAG said it will not contact customers unexpectedly to request passwords, banking information or payment card details. Existing bookings remain valid, although the company temporarily suspended access to its online Manage My Booking service as a precaution.

Attack Method and Hacker Identity Remain Unknown

MAG has not disclosed how the attacker entered the system, how long access lasted, or when the incident was detected. The company has also not said whether a third-party provider was involved or whether ransomware or extortion played a role.

The official incident notice states that access to affected systems was restricted after the breach was found. Cybersecurity specialists were brought into the investigation, and relevant authorities were notified, although MAG did not name them.

Cyberattack Exposes Data of 8.7 Million Customers at Three UK Airports
Screenshot of MAG’s official incident notice

At the time of writing, no hacking group has publicly claimed responsibility, and there is no evidence connecting the incident to a hostile government.

UK Infrastructure Faces Continued Cyber Pressure

Airports form part of the UK’s critical national infrastructure, but MAG said this incident did not reach operational or aviation security systems. Based on what has been disclosed, the breach was confined to customer-data systems.

A separate incident reported earlier this month involved an alleged 40GB archive of National Grid technical data, including source code, DevOps scripts and cloud configuration files. National Grid said the data compromise was associated with a software supply chain attack, but found no evidence of impact on its operations, internal systems or customer or employee information. No connection has been established between that incident and the MAG breach.

In June, the National Cyber Security Centre said it managed more than 200 incidents affecting UK critical national infrastructure and organisations supporting it during the year to May 2026. Around 75% were believed to be connected with state actors.

Pravesh Kara, director of cyber resilience services at Advania UK, told Hackread.com that the pace of attacks has left many organisations struggling to respond quickly enough.

“Most organisations are still working at human speed while the attacks move at machine speed. It feels mismatched,” Kara said. “Resilience does not work if it starts after an incident; proactive planning matters more than people assume.”

Kara’s comments address attacks on critical infrastructure generally. MAG’s breach remains unattributed, and nothing disclosed so far indicates that airport operations were targeted.

Affected customers should verify airport communications through the official MAG, Manchester Airport, London Stansted or East Midlands Airport websites. Unexpected payment requests, booking problems or security warnings should not be trusted solely because the sender knows a postcode, telephone number or vehicle registration.

I am a UK-based cybersecurity journalist with a passion for covering the latest happenings in cybersecurity and tech world. I am also into gaming, reading and investigative journalism.
Leave a Reply

Your email address will not be published. Required fields are marked *

Related Posts