5 min read

Manchester Airports breach exposes data on 8.7 million customers

Manchester Airports Group says hackers stole contact, postcode and vehicle data from up to 8.7 million customers, while payment data stayed secure.

Manchester Airports breach exposes data on 8.7 million customers

Image: TechRadar

Manchester Airports Group says hackers stole personal data tied to up to 8.7 million customers across Manchester, London Stansted and East Midlands airports. The exposed information includes email addresses, phone numbers, vehicle registration numbers and postcodes.

The affected records came from several airport services rather than flight operations: car-park bookings, lounge reservations, Fast Track bookings and airport Wi-Fi sign-ups. Together, those details could help attackers build credible messages for individual travelers, even though MAG says banking and other financial information was not exposed.

The company has not disclosed how the attackers got in, which systems they accessed, when the intrusion began or whether the stolen records have been published. Available reporting also does not establish whether all 8.7 million records were taken, only that the incident affects data belonging to up to that number of customers.

“We immediately contained the risk and have been working with specialist advisors and taking appropriate steps to protect our customers and systems. We have informed and are working with the relevant authorities. At no point has passenger safety or aviation security been compromised.”

Manchester Airports Group

MAG says the incident did not compromise passenger safety or aviation security. Airport services continued operating, with no reported flight cancellations or terminal queues attributed to the attack. The immediate operational impact is limited, but the customer data remains valuable to criminals.

Equifax automates half of its security tickets with AI

Recommended reading

Equifax automates half of its security tickets with AI

Sophia Reynolds 6 min read

Why the stolen fields are useful to attackers

An email address or phone number alone can support a generic phishing campaign. Combined with a postcode, vehicle registration and knowledge that someone booked airport parking or lounge access, those details can support a message that looks like a real airport notification: a parking refund, a payment problem, a Fast Track change or a warning about the breach itself.

That risk also applies to US travelers who used one of MAG’s UK airports. A message referencing a genuine trip through Manchester or Stansted may be more convincing than a broad airline scam, particularly when it includes a vehicle registration or other information the recipient recognizes.

“The absence of cancelled flights or queues at terminals does not make this a small cyber attack. The data reportedly taken can now be weaponised.”

Graeme Stewart, head of public sector, Check Point Software

Stewart said aviation companies should treat the incident as evidence of sustained pressure on the sector, not as a minor customer-database compromise. His warning focuses on the path attackers can take through suppliers and connected systems: a breach in a service such as parking or Wi-Fi can expose customers without touching aircraft-control or airport-security systems.

Vykintas Maknickas, CEO of Saily, made the same distinction from the traveler’s perspective:

“This breach shows that airport cybersecurity is no longer only protecting flight systems or operational infrastructure. The digital services travelers use every day, like airport WiFi, parking bookings, lounge access, and fast-track reservations, have become part of the security perimeter.”

Vykintas Maknickas, CEO, Saily

The exposure may support targeted phishing and smishing, including fake airport emails, fraudulent parking-payment notices, bogus flight updates and calls offering compensation. Dr. Ilia Kolochenko, founder of ImmuniWeb, warned that travel details connected to lounge and Fast Track bookings could also be used in more coercive campaigns:

“A wave of personalized and AI-enhanced blackmailing and extortion campaigns may be launched shortly.”

Dr. Ilia Kolochenko, founder, ImmuniWeb

That is an expert assessment, not a confirmed description of activity already linked to the breach. MAG has not said that extortion, cryptocurrency demands or publication of the data has occurred.

What affected customers should do

MAG advises customers to treat unexpected emails, text messages and phone calls about the airports or the incident with suspicion. Travelers should not click links or open attachments in unsolicited messages, and should instead visit an airport’s official website directly to verify a parking, booking or refund issue.

Anyone who receives a call claiming to be from an airport should end the call and contact the organization through an independently verified number. If a customer has already provided banking information after responding to a suspicious message, the source guidance recommends contacting the bank immediately. Anyone who disclosed a reused password should change it everywhere it was used and enable two-step verification.

Raghu Nandakumara, vice president of industry strategy at Illumio, said keeping terminals operating is only one part of containing a breach:

“Maintaining services during a cyberattack is critical, but organisations also need to minimise the amount of data and systems an attacker can reach before the threat is isolated.”

Raghu Nandakumara, vice president of industry strategy, Illumio

His recommendation points to segmentation as a technical control: separating customer-service databases and connected airport services can limit how far an attacker moves after an initial compromise. It cannot undo data already copied, but it can prevent a single exposed service from granting broad access to unrelated systems.

For US travelers, the practical concern is more convincing airport-themed scams. Customers who traveled through Manchester, Stansted or East Midlands should remain alert, while the underlying entry point, the full scope of the records and any law-enforcement findings remain undisclosed.

Frequently asked questions

What data did the Manchester Airports breach expose?+

The exposed data includes email addresses, phone numbers, vehicle registration numbers and postcodes linked to up to 8.7 million customers.

Was payment information exposed in the airport breach?+

No. Manchester Airports Group said banking and financial information remained secure during the incident.

Which airports are affected by the MAG breach?+

The group owns and oversees Manchester, London Stansted and East Midlands airports. The affected records came from services including parking, lounges, Fast Track and airport Wi-Fi.

How did hackers get into Manchester Airports Group’s systems?+

The available reporting does not establish how the attackers entered the systems or which specific database was compromised.

Sophia Reynolds

Security Editor

Sophia unpacks the invisible wars happening on our networks. Covering cybersecurity, privacy legislation, and cryptography, she exposes how our data is weaponized and defended. Before joining for(geeks), she spent years as a penetration tester. She's the reason the rest of the team uses physical security keys.

/ Keep reading