Manchester Airports Group (MAG), which operates Manchester, London Stansted, and East Midlands airports, disclosed that an unauthorized third party obtained customer data from services including car parking, lounges, Fast Track, and airport Wi-Fi. The compromised data includes email addresses, telephone numbers, vehicle registration numbers, and postcodes; reporting indicates up to 8.7 million people may be affected, though most records reportedly contained email addresses only. MAG said payment-card and bank details were not held in the affected system.
MAG contained the incident, restricted access to affected systems, engaged external cybersecurity specialists, notified relevant authorities, and temporarily suspended the online Manage My Booking service. It reported no impact on airport operations, aviation security, passenger safety, or existing bookings, and advised affected customers to remain alert for phishing emails, smishing messages, and fraudulent calls using the stolen contact and travel-related information.

See attribution, scope, and your downstream exposure.
10 events from the most recent confirmed update back to the earliest known activity.
The UK Information Commissioner's Office confirmed that Manchester Airports Group formally notified it of the data-security incident. The regulator said it was assessing the circumstances and the nature and extent of affected information to determine whether further action is warranted.
Have I Been Pwned parsed the purported MAG leak and reported that it contained approximately 8.8 million email addresses and phone numbers. The dataset reportedly also included personal, booking, purchase, vehicle, browser, and residential-IP information.
FulcrumSec posted data for download on its leak site, claiming it had leaked nearly all of roughly 549 GB of uncompressed MAG customer data. The group alleged the material included about 8.7 million customer profiles, marketing and purchase records, plaintext SMS booking data, and nearly 191,000 future bookings; the scale and contents remain unverified.
Data-extortion group FulcrumSec claimed it breached Manchester Airports Group, alleging it stole about 86 GB of data using airport-specific Iterable API credentials exposed in client-side JavaScript. Samples shared with BleepingComputer and partially validated suggested potentially broader exposure of booking, travel, profile, device, and marketing data, though MAG did not address the specific claims and the overall scope remained unverified.
A recipient reported receiving an East Midlands Airport data-breach notification at a work email address not known to have been used for airport or flight bookings. The recipient verified the notice originated from East Midlands Airport, raising the possibility that affected data may extend beyond the stated booking and Wi-Fi records.
MAG contacted affected customers and advised them to remain alert for phishing emails, smishing messages, and fraudulent phone calls. The company stated that airport operations, passenger safety, aviation security, and existing bookings were unaffected.
MAG said it immediately contained the risk, restricted access to affected systems, engaged external cybersecurity specialists, and notified relevant authorities. It also temporarily suspended the online Manage My Booking service as a precaution.
The attackers who accessed Manchester Airports Group customer data demanded a ransom, which MAG refused to pay. MAG also told the BBC it knew the threat actors' identity but did not publicly name them or disclose the ransom amount.
Manchester Airports Group said the cyberattack exposed data relating to approximately 8.7 million customers of Manchester, London Stansted, and East Midlands airports.
Manchester Airports Group (MAG) disclosed that an unauthorized third party obtained customer data associated with car parking, lounge, Fast Track, and in-airport Wi-Fi services at Manchester, London Stansted, and East Midlands airports. The exposed data included email addresses, phone numbers, vehicle registration numbers, and postcodes; MAG said payment and bank details were not held in the affected system.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
31 references tracked. Mallory keeps watching after this page renders.
securityweek.com
Open sourceitpro.com
Open sourceinfosecurity-magazine.com
Open sourcehaveibeenpwned.com
Open sourcetheregister.com
Open sourcemanchesterairport.co.uk
Open sourcemediacentre.magairports.com
Open sourcebbc.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.