Cyberattack Exposes Data Linked to 8.7 Million UK Airport Customers
A cyber security breach at Manchester Airports Group has exposed personal data of 8.7 million customers Natã Romualdo/Pexels

Around 8.7 million customers linked to Manchester, London Stansted and East Midlands airports have been affected by a cyber security incident, with hackers accessing personal information including email addresses, phone numbers, vehicle registration numbers and postcodes.

Manchester Airports Group (MAG), which operates all three airports, confirmed the breach on 27 August 2026, saying an unauthorised third party had obtained customer data connected to car park, lounge and Fast Track bookings, as well as in-airport Wi-Fi registrations.

The incident has raised concerns about how criminals could use the information for targeted scams, although MAG stressed that bank and payment details were not accessed.

What Information Was Stolen?

MAG said the compromised information includes customers' email addresses, telephone numbers, vehicle registrations and postcodes.

The company said neither MAG nor the affected system holds customers' bank or payment information, meaning financial details were not exposed. Passport information was also not identified among the compromised data.

The affected information was collected through airport services including parking, lounges, Fast Track bookings and Wi-Fi registrations.

MAG said it restricted access to affected systems after discovering the incident and brought in specialist cyber security advisers. It has also notified relevant authorities and is taking steps to protect customers and its systems.

Will Flights and Bookings Be Affected?

Passengers should not expect disruption to flights or airport operations.

MAG said the incident did not compromise aviation security or passenger safety, while airport operations and customer parking services remain unaffected. Existing bookings also remain valid.

However, access to the online Manage My Booking service has been temporarily suspended. Customers with bookings within the next 72 hours who need urgent changes have been advised to contact customer services directly.

The incident therefore represents primarily a data security and privacy risk, rather than an immediate threat to passengers travelling through the airports.

Why Passengers Should Watch for Scams

The biggest concern may now be what criminals do with the stolen information.

A combination of an email address, phone number, postcode and vehicle registration could allow scammers to make fraudulent messages appear convincing. Criminals could potentially use airport booking information to create convincing phishing emails or text messages.

The National Cyber Security Centre advises people affected by data breaches to be particularly alert to suspicious messages and contact organisations through official websites rather than links supplied in unexpected communications.

Passengers should avoid clicking unfamiliar links, opening unexpected attachments or providing passwords, banking information or payment details in response to unsolicited messages.

MAG has also warned that it will never unexpectedly request payment card details, banking information or passwords from customers.

What Passengers Should Do Now

Customers who use Manchester, Stansted or East Midlands airports should remain vigilant even if their travel plans are unaffected.

MAG said affected customers are being contacted directly. Passengers should verify that communications genuinely come from the airport group and avoid responding to unexpected requests for sensitive information.

The scale of the breach highlights the growing cyber security risks facing major transport infrastructure.

For passengers, the immediate message is clear: your flight may be unaffected, but your personal information could now be used to make scams look more convincing. Staying alert to suspicious calls, emails and texts is therefore one of the most important steps customers can take following the breach.