Manchester Airports Group has confirmed a cyberattack that compromised personal information of up to 8.7 million customers across its airports including Manchester, London Stansted, and East Midlands. The breach involved data linked to car park bookings, lounge access, Fast Track services, and in-airport WiFi registrations.

  • 8.7 million customer records exposed including contact and vehicle data
  • No financial data was compromised but risk of phishing is elevated
  • MAG is working with authorities and urging vigilance among customers

What happened

Manchester Airports Group (MAG), operator of several major UK airports including Manchester, London Stansted, and East Midlands, suffered a cyberattack that resulted in the theft of personal data belonging to approximately 8.7 million customers. The breached information was primarily collected through various services such as parking bookings, lounge and Fast Track services, and airport WiFi user registrations.

The stolen data includes email addresses, phone numbers, vehicle registrations, and postcodes. MAG confirmed that though this data was taken, sensitive banking and financial information was not affected. The group acted quickly to contain the breach and is collaborating with cybersecurity experts and relevant authorities to manage the situation.

Why it matters

This breach exposes a vast number of airport customers to potential targeted scams and phishing attacks. With detailed personal and travel-related data stolen, cybercriminals can craft highly convincing fraudulent communications referencing flights, parking details, or airport services, which makes deception easier and more dangerous for victims.

The incident highlights the increasing targeting of the aviation sector by cybercriminals, raising concerns about the resilience of critical infrastructure within travel and transport. Even though airport operations have not been disrupted, the breach represents a significant threat due to the weaponization potential of the compromised data and the possibility of sustained cyber campaigns ahead.

What to watch next

MAG advises all affected customers to remain cautious and wary of unsolicited calls, emails, or texts relating to airport services or the breach itself. Customers should avoid clicking on links or sharing personal information through suspicious contacts and verify any communications through official airport channels.

Moving forward, the aviation industry must reinforce its cybersecurity defenses and monitor for further cyber threats carefully. The event serves as a critical reminder that even without operational disruptions at terminals, the sector faces serious digital risks that require proactive, continuous protection measures and rapid incident response capabilities.

Source assisted: This briefing began from a discovered source item from TechRadar. Open the original source.
How SignalDesk reports: feeds and outside sources are used for discovery. Public briefings are edited to add context, buyer relevance and attribution before they are published. Read the standards

Related briefings