Data Breach Impacting 8.7 Million Customers at Three UK Airports

Data Breach at Manchester Airports Group Exposes Millions of Customer Records

The Manchester Airports Group (MAG) has reported a significant data breach affecting customer information linked to Manchester, London Stansted, and East Midlands airports. An unauthorized third party allegedly accessed this data, prompting notifications to approximately 8.7 million customers on August 27, 2026.

The compromised information has been traced back to records from airport Wi-Fi registrations, as well as bookings for parking, lounge access, and Fast Track services. According to MAG, the data accessed included email addresses, phone numbers, vehicle registration numbers, and postcodes. Notably, while the breach involved customer information, MAG clarified that the affected systems did not contain any bank or payment details. Operations at the airports continued without disruption, and both passenger safety and aviation security remained intact.

Following the incident, MAG issued warnings to customers, advising them to be vigilant against potential phishing attempts. Many customers received notifications via email, urging them to exercise caution when confronted with unsolicited communications—whether through emails, calls, or texts—claiming to be from the airports. Such personal details, including email addresses and vehicle registrations, can be exploited to generate fraudulent messages that appear genuine.

MAG emphasized that customers would not be contacted unexpectedly to provide sensitive information, such as passwords or payment card details. Despite the breach’s gravity, existing bookings were upheld, although the company temporarily suspended its online booking management service as a precautionary measure.

The specifics regarding the means of entry, duration of access, and detection timeline remain undisclosed by MAG. The organization has not provided insight into whether a third-party provider was implicated or if tactics such as ransomware or extortion were part of the breach strategy. The official notice of the incident revealed that access to compromised systems was restricted promptly after the breach was detected. Despite activating cybersecurity specialists for investigation, the identity of the perpetrators remains unknown, with no claims of responsibility from any hacking groups.

This incident adds to the ongoing discussion surrounding cybersecurity threats to the UK’s critical national infrastructure. MAG asserted that the breach did not impact operational or aviation security systems, confining the issue to customer data systems. Earlier this month, another report highlighted a breach involving the National Grid’s technical data, linked to a software supply chain attack, with no operational impact reported. However, no connections between this incident and the MAG breach have been established.

According to the National Cyber Security Centre, over the past year, the UK has faced more than 200 cyber incidents affecting critical infrastructure, with a significant proportion attributed to state actors. The alarming frequency of attacks has prompted experts to voice concerns regarding organizational preparedness for such threats. In particular, the director of cyber resilience services at Advania UK noted that the intensity of these digital assaults has left many organizations struggling to respond effectively, underscoring the importance of proactive cybersecurity measures.

While the specific tactics employed in the MAG breach have yet to be confirmed, potential methods that may have been utilized encompass initial access techniques, such as exploiting weak credentials or taking advantage of vulnerable public-facing applications, as outlined in the MITRE ATT&CK framework. Organizations are encouraged to remain vigilant, verify any communications through official channels, and exercise caution regarding unsolicited requests for information, particularly when such requests utilize familiar data points.

Source