Manchester Airports Group Cyberattack Exposes Data Of 8.7M Customers

Manchester Airports Group said an unauthorized third party accessed customer records tied to car park, lounge, Fast Track and Wi-Fi bookings at Manchester, Stansted and East Midlands airports, affecting around 8.7 million people.

Manchester Airports Group Cyberattack Exposes Data Of 8.7M Customers

Manchester Airports Group (MAG), the UK's largest airport operator, disclosed a cyberattack that exposed customer data belonging to roughly 8.7 million people who had used online booking, lounge, Fast Track or in-airport Wi-Fi services across Manchester, London Stansted and East Midlands airports. Flights and airport operations continue normally, and no payment or banking data was accessed.

What Was Exposed

According to MAG's advisory, an unauthorized third party accessed customer records tied to car park, lounge and Fast Track bookings as well as in-airport Wi-Fi sign-ups. Compromised fields include email addresses, phone numbers, vehicle registrations and postcodes. The company said that in the "vast majority" of cases the only field accessed was an email address, and stressed that neither MAG nor the affected system stores customer bank or card details. Aviation security and passenger safety were not affected.

Manchester Airport Terminal 2 exterior at Manchester Airports Group

Timeline And Containment

MAG said it was alerted to the intrusion on Tuesday, August 25, and that attackers first accessed customer data a few days earlier. It moved to restrict access to the compromised systems, brought in external cybersecurity specialists and notified the Information Commissioner's Office and other relevant authorities. As a precaution, MAG has temporarily suspended its online Manage My Booking service; existing reservations remain valid, and customers who need to change a booking within the next 72 hours have been directed to a customer service phone line.

Where This Fits In A Bad Week For UK Infrastructure

The breach lands as UK operators of critical and consumer infrastructure absorb a cluster of incidents: an OT-linked cyberattack disrupted a 15 MW UK power plant for four days this week, and CISA warned that Citrix NetScaler CVE-2026-8452 is under active exploitation. MAG is majority-owned by ten Greater Manchester local authorities, with Australian infrastructure investor IFM Investors holding a 35.5% stake — meaning the breach also touches the roster of pension savers whose retirement money sits inside the group's ownership structure.

What Customers Should Watch For

MAG has emailed affected customers and warned them to be alert for phishing attempts that reference recent bookings. The company reiterated it will never contact customers unexpectedly to request payment card details, banking information or passwords. Security researchers have already flagged 2026 as a breakout year for AI-augmented extortion tooling — see the emergence of the industry-wide AI cyber defense pact announced this week — and email-heavy breach corpuses are exactly the fuel that automated impersonation campaigns feed on.

Reporting based on coverage from The Record from Recorded Future News and Manchester Airports Group's own advisory.

Category: Cyber Security

Tags: Cybersecurity Infrastructure Data Breach

Related Articles