HackMyIP
← Back to News
2026-08-27 The Record

Manchester Airports Group Data Breach Exposes 8.7 Million Customers

Data BreachPhishingIncident Response

Manchester Airports Group (MAG), the public-private operator of Manchester, London Stansted, and East Midlands airports, confirmed Thursday that a cyberattack compromised personal data belonging to approximately 8.7 million customers. The breach exposed information tied to car park reservations, lounge and Fast Track bookings, and in-airport Wi-Fi sign-ups. MAG said an unauthorized third party gained access to a relevant system but did not disclose the initial attack vector, how long the intruder remained inside, or whether any lateral movement occurred beyond the affected database. Detection came on Tuesday, with the attackers believed to have first accessed customer data only "a few days" earlier.

The compromised dataset includes email addresses, phone numbers, vehicle registration plates, and postal codes. MAG stressed that neither the company nor the affected system stores customers' bank account or payment card details, and no financial data was exposed. In the "vast majority" of cases, only an email address was accessed, according to a spokesperson speaking to The Yorkshire Post, though a smaller subset of records contained the additional identifiers. The three airports handled more than 65 million passengers last year, though not all travelers would have interacted with the impacted services. MAG has temporarily suspended its online Manage My Booking portal while it works with external cybersecurity specialists and has notified the relevant UK authorities. Flights, ground operations, and parking services continue to run normally, and aviation security remains unaffected.

MAG is majority-owned by ten Greater Manchester local authorities, with Australian fund IFM Investors holding a minority stake. Affected customers have been notified by email and warned to remain alert to phishing attempts, with the company emphasizing it will never cold-call customers to request payment card details, banking information, or passwords. Travelers with bookings requiring changes within the next 72 hours are being directed to a dedicated customer service phone line, and all existing reservations remain valid. Users who registered for any of the impacted services can verify whether their email appears in known leaks using our email breach checker, audit their broader exposure with the privacy checkup, and confirm account credentials remain strong via the password checker before reusing any login tied to the compromised MAG services.

Source: The Record →

Related Tools

Check whether this kind of story affects you — free, no signup:

Email Breach Check →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is a data breach? →Credential stuffing attacks →How to check for an email breach →