Three UK Airports Hit by Cyberattack: 8.7m Customers' Data Was Accessed, With Parking, Wi-Fi and Car Details Exposed
Manchester, London Stansted and East Midlands airports were affected as Manchester Airports Group refused a ransom demand and said no payment-card data was accessed

Three UK airports run by Manchester Airports Group (MAG) have been hit by a cyberattack in which data linked to about 8.7 million customers was accessed, including details from airport Wi‑Fi sign‑ups and car parking bookings.
MAG said the vast majority of the information was email addresses and that passenger safety, aviation security and airport operations were not affected.
The breach involved ancillary customer systems covering airport Wi‑Fi, car parking, lounge and Fast Track bookings rather than airside or operational systems. MAG said it had contained the incident and was working with specialist cyber‑security advisers and relevant authorities.
MAG said it discovered the breach on Tuesday 25 August and that the incident involved data accessed over the preceding weekend. The group issued a public statement on Thursday 27 August after notifying affected customers.
The company did not include the 8.7 million figure in its public statement. The figure was provided separately to media as the scope of the affected records became clearer.
What Data Was Accessed?
MAG said the information obtained included email addresses, phone numbers, vehicle registration numbers and postcodes.
It said neither MAG nor the affected system held customers' bank or payment details.
The 8.7 million figure does not represent 8.7 million complete passenger profiles.
Most of the accessed information was understood to be email addresses from airport Wi‑Fi registrations, while a smaller group of parking, lounge and Fast Track customers had additional contact or vehicle information exposed.
MAG has not publicly broken down how many customers fell into each category. It has also not specified which individual fields were linked to each affected service.
Three Airports Were Affected
The affected airports are Manchester, London Stansted and East Midlands, all operated by MAG. The group said customer parking services continued to operate normally and existing bookings remained valid.
Access to the online Manage My Booking service was temporarily suspended as a precaution. Customers could continue to travel and use existing bookings, with customer services available for urgent amendments.
Hackers Demanded a Ransom
MAG said hackers demanded money in return for the data and that the company refused to pay. The amount demanded has not been disclosed.
MAG has not identified the attackers or named a hacking group linked to the incident. The company has also not said how the attackers gained access to the affected systems.
Phishing Risks After Breach
MAG has warned customers to watch for suspicious emails, text messages and phone calls following the breach. In an email to customers, the company said: 'We will never contact you unexpectedly to ask for payment or banking information.'
The group also urged customers to be 'particularly cautious of unexpected emails, calls or text messages claiming to be from us'. Contact and booking information could allow criminals to make fraudulent messages appear more credible by referring to parking, travel or airport services.
Customers should avoid clicking links, opening attachments or providing personal or financial information through unsolicited messages. MAG has contacted customers where it believes their information was affected.
What Remains Unknown
MAG has not publicly said how long the attackers remained in the affected systems or provided a full breakdown of the 8.7 million records. It has also not quantified how many customers had only an email address exposed compared with those whose information included phone numbers, vehicle registrations or postcodes.
The company said it had restricted access to affected systems, brought in cyber‑security specialists and notified relevant authorities. It said airport operations remained unaffected as it worked to assess the incident and the data involved.
© Copyright IBTimes 2026. All rights reserved.

























