Crime5 min read

8.7 Million Travelers' Data Was Just Exposed in a UK Airport Hack — Here's What to Watch For

Hackers stole contact and booking data from Manchester, Stansted, and East Midlands airports. Here's what was taken, what wasn't, and how to stay safe.

8.7 Million Travelers' Data Was Just Exposed in a UK Airport Hack — Here's What to Watch For

Manchester Airports Group (MAG), the UK's largest airport operator, confirmed on August 27, 2026, that hackers gained unauthorized access to customer data connected to three of England's busiest airports — Manchester Airport, London Stansted, and East Midlands Airport. Roughly 8.7 million customers are reportedly affected, based on figures reported by multiple cybersecurity outlets and UK media.

MAG said it identified the intrusion on a Tuesday and moved quickly to contain it, engaging specialist cybersecurity advisors and notifying the relevant authorities. The company has stated that the attackers subsequently demanded a ransom for the stolen data — MAG refused to pay, and has not disclosed the amount demanded.

Official Bulletin: View verified data sheet & incident timeline
Access Briefing →

What data was — and wasn't — taken

According to MAG's own statements and reporting from multiple outlets, the exposed information falls into two main groups:

The bulk of the stolen data consists of email addresses collected through airport WiFi sign-ups at the three airports. A smaller portion includes more detailed personal information — names, phone numbers, postal addresses, postcodes, and vehicle registration numbers — linked to bookings for car parking, airport lounges, and Fast Track security lanes.

Advertisement

MAG has been explicit about what was not compromised: no bank account details or payment-card information were accessed, and passport information was not part of the affected system. The company has also stated that passenger safety, airport operations, and aviation security were not affected at any point during the incident.

Why this matters even without financial data

Losing email addresses, phone numbers, and postcodes might sound less serious than a stolen credit card, but security researchers point to a different risk: the data is detailed enough to make convincing, targeted phishing attempts. Someone who knows you recently booked airport parking or a lounge visit at one of these airports — and has your phone number and postcode — can craft a scam message that looks legitimate.

The UK's National Cyber Security Centre has advised people affected by breaches like this one to be alert specifically to phishing emails, texts, and phone calls that impersonate airports, airlines, or travel services in the weeks following an incident.

Who is affected

Anyone who registered for WiFi at Manchester, Stansted, or East Midlands airports, or who booked parking, a lounge visit, or Fast Track security access at those airports, may be among the 8.7 million affected customers. MAG has said it is in the process of notifying affected customers directly.

What MAG has said about the attackers

MAG has stated that it knows the identity of the group responsible for the attack but has not publicly named them. The company has not disclosed further details about the ransom demand or ongoing negotiations, and it's not yet publicly confirmed whether UK authorities — such as the Information Commissioner's Office or the National Cyber Security Centre — have opened a formal investigation into the incident.

What travelers should do now

If you've used WiFi, parking, lounge, or Fast Track services at Manchester, Stansted, or East Midlands airports, security guidance following breaches like this one generally recommends:

Treat unexpected emails, texts, or calls referencing a recent airport booking with suspicion — especially any that ask you to click a link, confirm personal details, or make a payment. Airports and airlines do not typically ask for payment-card details by text message.

Go directly to the airport's official website or app if you need to check a booking, rather than clicking a link in an unsolicited message.

Watch for messages that reference specific details like your vehicle registration or postcode — attackers may use this real data to make phishing attempts look more credible, not less.

Report suspicious messages to your airline, the airport operator, or the UK's Action Fraud service if you believe you've been targeted.

What happens next

MAG has said it is continuing to work with cybersecurity advisors and relevant authorities as it notifies affected customers. As of this writing, the company has not released a specific timeline for completing customer notifications, and no further public updates on the identity of the attackers or the scale of the breach have been confirmed beyond the initial 8.7 million figure. Readers with bookings or WiFi registrations at any of the three affected airports should watch for official communication directly from MAG rather than assuming any unsolicited message is genuine.

FAQ

Was my bank or credit card information stolen? No. MAG has stated that the affected system did not contain bank account or payment-card details.

Was my passport information exposed? No. MAG has said passport information was not part of the compromised data.

How do I know if I'm one of the affected customers? MAG has said it is notifying affected customers directly. If you registered for WiFi, or booked parking, a lounge, or Fast Track at Manchester, Stansted, or East Midlands airports, you may be affected — but wait for official communication from MAG rather than acting on unsolicited messages claiming to be from the airport.

Did this affect my flight or airport security? No. MAG has stated that passenger safety, airport operations, and aviation security were not affected by the breach.

Who was behind the attack? MAG has said it knows the identity of the group responsible but has not made this public. The incident has been described as a ransomware attack, and MAG says it refused to pay the ransom demanded.

Did you find this story

Share

Get new stories weekly

Advertisement