Manchester Airports Group (MAG) disclosed a major data breach on Thursday affecting 8.7 million customers, after attackers compromised systems storing WiFi sign-up records, parking bookings and Fast Track passes across its three UK airports.
MAG, which operates Manchester, London Stansted and East Midlands airports, said the breach exposed email addresses, phone numbers, vehicle registrations and postcodes. The company insisted that bank card details and payment information were not stored on the affected system, but cybersecurity experts warned the harvested data could power highly convincing phishing campaigns targeting millions of air travelers.
The group said it became aware of the intrusion on Tuesday and immediately restricted access to the compromised systems, brought in specialist cyber security investigators and notified the relevant data protection authorities. MAG suspended its online Manage My Bookings service as a precaution, though it said all existing flight bookings remained valid and airport operations, passenger safety and aviation security were not impacted.
What data was taken?
According to the company statement, the breach affected data linked to in-airport WiFi registrations as well as car parking, lounge and Fast Track bookings. MAG said the vast majority of affected individuals had only their email addresses exposed, but the scope of the compromise extended well beyond email for a significant minority of those impacted.
For customers who booked parking or used airport WiFi, the leaked dataset could include names, mobile phone numbers, vehicle registration plates, home postcodes and booking reference numbers. That combination of fields gives threat actors enough detail to craft highly targeted social engineering attacks, according to two independent security analysts who reviewed the disclosure.
One analyst warned that a fake parking refund email or a message referencing a recent booking would now be extremely difficult for ordinary travelers to distinguish from legitimate communications. The risk is amplified because the breach captures data at multiple touchpoints, from initial WiFi sign-up through to parking and lounge reservations, meaning affected customers likely used these services repeatedly across multiple trips.
A growing pattern of airport targeting
MAG has not disclosed the specific attack vector or attributed the breach to any known threat group. The incident mirrors a broader surge in cyber attacks against aviation infrastructure worldwide. In February, the Qilin ransomware group claimed responsibility for an attack on Tulsa International Airport, allegedly leaking stolen operational data. Earlier this year, an alleged cyber attack compromised data from Dubai International Airport, with hackers claiming to have obtained passport images and security scanner footage.
Airports present a particularly attractive target for cyber criminals because they are processing hubs where millions of passengers interact with multiple digital services, often on public WiFi networks that sit outside corporate security perimeters. The sheer volume of personally identifiable information collected at check-in desks, lounge entrances and parking barriers creates vast repositories of customer data that, when breached, have immediate resale value on criminal forums.
The pattern also underscores a persistent weakness in how transportation hubs handle customer data. Many airports still store WiFi registration data in centralized databases that are accessible to multiple internal systems, creating a single point of failure that attackers can exploit to harvest records at scale.
What passengers should do now
MAG said it was continuing to investigate the breach and that its data protection team was overseeing the response. The company has not yet confirmed whether it will offer identity monitoring services to affected customers, nor has it provided a timeline for restoring the Manage My Bookings portal.
Security researchers urged travelers who used airport WiFi at Manchester, Stansted or East Midlands to change passwords on any accounts accessed during their visit, enable two-factor authentication on email accounts and be alert for phishing messages referencing parking, flight bookings or travel itineraries. Using a virtual private network on public WiFi networks is strongly recommended for anyone traveling through the affected airports.
Consumers are also advised to monitor their bank statements and credit reports for unusual activity, even though MAG stated that financial data was not compromised in this incident. The precautionary approach reflects the reality that data harvested in breaches often surfaces weeks or months later as part of secondary fraud operations.

discussion