Thursday, August 27, 2026

Passenger data stolen from major UK airports

Manchester Airports Group (MAG), the parent organisation that runs East Midlands, Manchester, and London Stansted airports, has admitted an unnamed threat actor has stolen a significant quantity of personally identifiable information (PII) on approximately 8.7 million people who parked at or flew through its airports.

The data breach is understood to relate to parking, lounge and Fast Track bookings, and airport Wi-Fi network sign-ins, and while the IT systems breached did not contain bank or payment details, MAG said the stolen dataset includes identifying email addresses, phone numbers, post codes, and vehicle registration plates.

The incident has not led to any operational disruption, and MAG said the affected services are available as normal with upcoming bookings valid and unaffected. Its online Manage My Booking service, however, is currently offline – travellers who need to make urgent changes to any services due before Sunday 30 August should call 0208 163 8001.

“We would like to reassure customers that Manchester Airport Group takes the security of customer information extremely seriously and we apologise for any inconvenience or concern caused.”

Fraud risk to passengers

At the time of writing, there was no indication to suggest that MAG has fallen victim to a cyber extortion or ransomware gang, although this may change during the coming days.

While the breach appears to be largely contained, the greater issue for now will be for those affected, who are at risk of targeted individual cyber attacks depending in whose hands the data ends up. In general, such attacks will manifest as social engineering attempts leading to fraud.

In an email sent to passengers, a copy of which has been passed to Computer Weekly, MAG said there was no further action needed, but urged caution regarding unexpected emails, calls or SMS messages purporting to be from the organisation.

Huntress EMEA virtual chief information security officer (vCISO) and cyber security advisor, Muhammad Yahya Patel, said the combination of email addresses, phone numbers, and car numberplates was a valuable one that enabled a cyber fraudster to build a very precise targeting profile.

“Scammers now know you travelled, roughly when, and have two direct contact routes to reach you with a convincing story. When that data ends up in an unauthorised third party’s hands alongside parking and lounge booking details, it fills in a surprisingly detailed picture of someone’s travel habits,” said Patel, who is among those affected.

“If you’ve received a [breach] notification, as I have, treat any communication referencing your airport booking, parking, or travel details in the coming weeks with serious caution.

“MAG has confirmed they will never contact you to request payment details or passwords. Anything that does should be treated as a scam attempt using data from this breach,” he said.

Comparitech security specialist Brian Higgins added: “As AI makes data aggregation swift and easy consumers are waking up to the fact that criminals can monetise successful breaches in increasingly inventive ways.

“It’s no longer enough for data owning organisations to advise post-attack vigilance and turn to their backups. Victim communities rightly expect better protected networks and systems over and above established norms. As the marketplace grows less fearful and more angry when breaches are made public we may see more emphasis on cyber crime prevention which can only be a good thing,” he said.

More consumer guidance on cyber security for individuals and families is available from the UK’s National Cyber Security Centre (NCSC).

Related Articles

Latest Articles