Hackers steal data of 8.7 million Manchester Airports Group customers
The operator of Manchester, Stansted and East Midlands airports says contact and vehicle information was accessed in a breach that did not affect flight operations, security screening or payment data.

Manchester Airports Group confirmed on Thursday that hackers accessed personal data belonging to about 8.7 million customers across the three UK airports it operates: Manchester, London Stansted and East Midlands. The company said the exposed information came from car park, airport lounge and Fast Track bookings, as well as sign-ups for in-terminal Wi-Fi, and included email addresses, phone numbers, vehicle registration plates and postcodes. In a statement posted to its own website, the group said no bank card numbers or payment details were held in the systems that were accessed, and that the incident has not disrupted flights, security screening or day-to-day airport operations.
The numbers
The 8.7 million figure makes the incident one of the larger customer-data breaches disclosed by a UK transport operator this year, according to reporting from The Record and BleepingComputer. MAG has not disclosed how the intrusion occurred or how long the attackers had access to its systems before detection, and it has not named a suspected group or attacker. As a precaution, the operator temporarily suspended its online Manage My Booking service while it investigates, according to coverage from The Register. The company said it became aware of the unauthorized activity earlier in the week and moved to contain it before disclosing the breach publicly.
How the group responded
Manchester Airports Group, which is majority-owned by Manchester City Council and other Greater Manchester local authorities alongside a minority stake held by the Australian investment fund IFM Investors, said it engaged external cybersecurity specialists as soon as the intrusion was identified and has been working with law enforcement and regulators since. Under UK data protection law, organizations that suffer a breach affecting personal data must notify the Information Commissioner's Office within 72 hours of becoming aware of it. The regulator confirmed it has received a breach report from MAG and said it is assessing the information provided, a standard first step before the ICO decides whether to open a formal investigation. The airport group has also begun contacting affected customers directly by email, and published guidance urging them to watch for phishing attempts that might exploit the stolen contact details, while stressing the company will never ask customers for banking information or passwords by phone, text or email. MAG has also pointed customers to the National Cyber Security Centre's published guidance on responding to data breaches, which advises people to verify any communication through an organization's official channels rather than links or numbers contained in unsolicited messages, and to watch for scam contact that may arrive weeks or months after a breach is first disclosed.
Manchester Airports Group is not a conventional private company. It is majority owned by ten Greater Manchester local authorities, with Manchester City Council holding the largest single stake, alongside a 35.5 percent holding by the Australian pension-fund manager IFM Investors, which bought in to help finance the group's 2013 acquisition of Stansted Airport. That ownership structure means the financial and reputational fallout from the breach lands partly on public bodies rather than solely on private shareholders, even though the group is run on a commercial, arm's-length basis from its council owners.
Who is affected
The breach potentially touches millions of travelers who used any of the three airports' paid parking, executive lounges, priority security lanes or free Wi-Fi networks, a customer base that spans both domestic UK passengers and international arrivals passing through one of the country's busiest regional airport groups. Manchester Airport alone handles tens of millions of passengers annually, making it the largest airport outside London and a significant node in UK air travel. Because the compromised data includes vehicle registration numbers and postcodes alongside contact details, security researchers cited by Cybernews warned that the combination could be used for convincing, targeted phishing messages that reference a victim's actual car or travel history, even though no financial account numbers were taken.
"At no point has passenger safety or aviation security been compromised, and the incident has not resulted in any operational disruption," the company said in its public notice to customers.
What happens next
The Information Commissioner's Office will determine whether MAG's security controls met the standards required under UK data protection law and could ultimately levy a fine if it finds shortcomings, a process that in comparable cases involving airlines and transport operators has taken many months to conclude. British Airways, for example, faced a multi-year ICO enforcement process after a 2018 breach before a final penalty was settled. MAG has not said when it expects to restore its online booking management tool or complete its investigation into how attackers gained access, nor has it disclosed whether it has been contacted by any group claiming responsibility or demanding payment. Passengers awaiting updates have been directed to the company's dedicated incident page for further guidance, and the group said it will provide additional information as its investigation, conducted alongside external forensic specialists, continues.
Cybersecurity analysts following the case say the disclosure is likely to renew scrutiny of how much personal data travel and transport operators collect through ancillary services such as parking and Wi-Fi sign-ups, which are often managed through third-party booking systems that can be less tightly secured than core reservation or payment platforms. The incident follows a string of cyberattacks against European aviation and transport infrastructure over the past two years, and airport operators across the UK are likely to face renewed pressure from regulators and industry bodies to audit the security of ancillary customer-facing systems that sit outside the core operational networks governing flights and security screening. For travelers, the practical guidance from both MAG and the National Cyber Security Centre remains the same: treat unexpected emails or texts referencing car parking, lounge bookings or Wi-Fi accounts with caution, and report anything suspicious directly to the airport rather than responding to it.
Manchester Airport — Data security incident: official customer notice
The Record — Cyberattack on Manchester Airports Group exposes data of 8.7 million customers
BleepingComputer — Manchester Airports Group says hackers stole travelers' data
The Register — Cybercrooks jet off with Manchester Airports Group customer data

Judge Rules Pentagon Illegally Blacklisted Anthropic Over AI Safety Guardrails

Apple sets September 9 event, teases first foldable iPhone
