News

MAG breach hits 8.7M customers at three UK airports

Manchester Airports Group confirmed an unauthorised third party accessed data tied to about 8.7 million customers at Manchester, Stansted and East Midlands. Email, phone, vehicle-registration and postcode data was taken, with no bank or payment details. MAG refused a ransom, and in most cases only a Wi-Fi sign-up email was exposed.

MAG breach hits 8.7M customers at three UK airports

Manchester Airports Group (MAG) has confirmed that an unauthorised third party accessed customer data tied to about 8.7 million people across Manchester, London Stansted and East Midlands airports, per its statement issued 27 August 2026. Keep the scope straight from the top: this is a customer-data incident, not a compromise of flight systems. MAG says passenger safety, aviation security and airport operations were not affected, and parking services continue normally.

What was taken, and what was not

The data relates to car park, lounge and Fast Track bookings and in-airport Wi-Fi sign-ups. The fields accessed are email addresses, phone numbers, vehicle registrations and postcodes. Neither MAG nor the affected system stores bank or payment card details, the company says, so no financial data sat in the exposed set. That boundary is the whole risk profile: it shifts the follow-on threat from card fraud to phishing, and it tells customers which alerts to ignore.

The number the headline leaves out: most of it is a Wi-Fi email

Here is the detail that reframes the 8.7 million. In the vast majority of cases, The Record reports MAG saying, the only information accessed was a single email address, largely from travelers who signed in to the airports' Wi-Fi. The headline count is real, but the depth per record is shallow for most of it: a long list of email addresses, not a matched set of names, cards and itineraries. The customers who should pay closest attention are the smaller slice whose booking records carried the phone number, vehicle registration and postcode together.

The response, and the one instrument to name correctly

Name this precisely: it is a confirmed data-theft incident with a refused extortion demand, not a ransomware lockout of airport systems. Attackers gained access over the weekend of 22 to 23 August, MAG became aware on Tuesday 25 August, and it disclosed publicly on the 27th. The company says it contained the risk quickly, brought in specialist advisors, notified the authorities, and temporarily suspended its online Manage My Booking service. MAG refused to pay the ransom the attackers demanded, and the UK's National Cyber Security Centre and Information Commissioner's Office were informed. MAG has not published a CVE or named the group behind it, so anyone attaching a specific threat actor to this is running ahead of the primary.

The takeaway

If you used Wi-Fi or booked parking, a lounge or Fast Track at Manchester, Stansted or East Midlands, treat any message that follows this breach as a phishing target, not a payment problem, because the exposed set is contact data and not cards. MAG's refusal to pay means the stolen data may still surface, so the defensive move is inbox hygiene and filtering, not card cancellation. Watch the ICO's assessment for whether the containment and notification hold up, and delete any "update your payment details" note citing this incident, since MAG says it never held those details to lose.

For related exposure and incident context this week, see our coverage of PaperCut's actively exploited NG/MF zero-day, the Azure data-theft campaign against Fortune 500 firms, and ServiceNow's CVSS 10 AI-platform flaws.

Cyberpresso: daily cyber & AI brief

Free daily newsletter, read in 5 minutes.

Subscribe free