
Cyberattack on Manchester Airports Group exposes data of 8.7 million customers
Manchester Airports Group revealed that unauthorized hackers accessed email addresses, phone numbers, and vehicle registrations of 8.7 million travellers across Manchester, Stansted, and East Midlands airports without disrupting flight operations.
Scope of the airport breach
Manchester Airports Group, the largest airport operator in the United Kingdom, announced on Thursday, 27 August 2026, that an unauthorized third party had accessed the personal information of 8.7 million customers. The security breach targeted systems serving three transport hubs: Manchester Airport, London Stansted Airport, and East Midlands Airport in central England. The cyber intrusion occurred over the preceding weekend, but group technical teams only discovered the unauthorized access on Tuesday, 25 August 2026. Company managers stated that they immediately contained the security breach upon discovery, prevented further system penetration, and initiated direct notifications to affected travellers.
- Unauthorized third party penetrates airport customer systems
- MAG discovers the breach, cuts off further access, and informs authorities
- MAG publicly discloses the breach affecting 8.7 million customers
Nature of the exposed records
The company reported that the majority of the compromised data was restricted to customer email addresses collected during passenger registrations for wireless internet in airport terminals. In addition to Wi-Fi records, the attackers obtained data associated with auxiliary passenger bookings across the three locations. These additional records included customer telephone numbers, vehicle license plate numbers, and home postal codes submitted by passengers who had reserved car parking spaces, executive lounge access, or Fast Track security clearance.
The group stated that financial data remained secure throughout the incident, as payment card records and banking details were not stored on the compromised network. Flight schedules, aviation security protocols, and passenger screening procedures remained fully operational, with car parking facilities functioning normally across all three affected airports.
At no point has passenger safety or aviation security been compromised.
Containment and technical response
After discovering the breach on Tuesday, Manchester Airports Group engaged external cybersecurity specialists to isolate compromised components and audit its infrastructure. Company representatives reported that the identity of the perpetrators was known and that details had been shared with relevant law enforcement and national regulatory authorities. The company also issued a formal apology to passengers for the inconvenience and concern caused by the unauthorized access to their personal records.
We immediately contained the risk and have been working with specialist advisers and taking appropriate steps to protect our customers and systems.
To mitigate risks of secondary scams, the airport operator urged all 8.7 million affected customers to remain vigilant regarding incoming communications. Passengers were instructed to look out for suspicious emails, telephone calls, and text messages, and to refrain from opening file attachments or clicking links received from unfamiliar sources.
Context of United Kingdom cyber attacks
The incident at Manchester Airports Group follows a series of cyber attacks that struck multiple high-profile British companies over the course of the previous year. Those intrusions targeted automobile manufacturer Jaguar Land Rover, clothing and food retailer Marks & Spencer, department store Harrods, and supermarket chain Co-op. Technical reviews into the weekend breach across Manchester, Stansted, and East Midlands airports continue under the supervision of specialized cybersecurity advisers and relevant authorities.


