Manchester Airports Group (MAG) confirmed on August 27 that a cyberattack by an “unauthorised third party” exposed customer data from approximately 8.7 million records across three of England’s busiest airports, marking one of the largest aviation data breaches in UK history.
The breach affected data connected to in-airport WiFi registrations, car parking bookings, lounge access and Fast Track security purchases at Manchester Airport, London Stansted Airport and East Midlands Airport. MAG, which handles over 61 million passengers annually across its three hubs, said the exposed information includes email addresses, phone numbers, vehicle registration numbers and postcodes. The company stressed that no bank details or payment card information were stored on the affected system, and that passenger safety and aviation operations were never compromised.
What Data Was Taken
MAG disclosed that the vast majority of affected individuals had only their email addresses exposed. However, the inclusion of phone numbers, postcodes and vehicle registrations for some customers creates what cybersecurity experts describe as a “precise targeting profile” for follow-on fraud. Muhammad Yahya Patel, a cybersecurity advisor at Huntress, warned that the combination of contact details and travel-related information gives criminals the material to craft convincing phishing campaigns. “Scammers now know you travelled, roughly when, and have two direct contact routes to reach you with a convincing story,” Patel said. Graeme Stewart of Check Point Software added that a fake parking refund or a message about the breach itself would be much harder for ordinary customers to spot.
Timeline and Response
MAG discovered the intrusion on Tuesday, August 26, and issued its public disclosure two days later on Thursday, August 27. The company immediately restricted access to the affected systems, engaged specialist cybersecurity advisors and notified the Information Commissioner’s Office (ICO) and other relevant authorities. Under UK GDPR regulations, organizations must report data breaches to the ICO within 72 hours if they could put people’s rights or freedoms at risk. MAG has also temporarily suspended its online Manage My Bookings service as a precautionary measure and contacted affected customers directly, warning them to treat any unexpected emails, calls or text messages with suspicion.
No Attribution Yet
As of publication, no ransomware group or extortion crew has claimed responsibility for the MAG breach. The company has not confirmed whether a ransom demand was received. This stands in contrast to the September 2025 Collins Aerospace attack, which disrupted check-in and boarding systems at Heathrow, Brussels and Berlin and was later linked to the HardBit ransomware group. That incident exfiltrated a 50GB database and caused widespread operational chaos across European aviation. The MAG breach is a separate incident with a fundamentally different profile: a data confidentiality breach with no reported operational impact, versus an availability attack that grounded airport systems.
A Pattern of Aviation Targets
The MAG breach is the latest in a growing string of cyberattacks targeting airports and aviation infrastructure. In February 2026, the Qilin ransomware group claimed an attack against Tulsa International Airport, allegedly accessing and leaking airport data. In early 2026, a separate cyberattack compromised data from Dubai International Airport, with hackers claiming to have obtained passport images and security-scanner material. These incidents underscore why airports have become prime targets: they process massive volumes of personal data through customer-facing systems including WiFi sign-ups, loyalty programs and booking platforms, often operated by regional authorities rather than centralized security teams. The MAG breach shows that a single compromised shared system can expose millions of records across multiple sites simultaneously.
What Customers Should Do
MAG has told affected customers that no immediate action is required, but cybersecurity experts recommend standard precautions. Travelers who used car park, lounge, Fast Track or WiFi services at the three airports should treat unsolicited emails or texts referencing airport services with heightened suspicion, especially any requesting payment details or login credentials. The ICO has the power to fine organizations up to 17.5 million pounds or 4% of global turnover for serious GDPR violations, though no enforcement action has been confirmed in this case. The breach remains under investigation and MAG has said its data protection team is overseeing the full response.
discussion