Customer information connected to bookings and Wi-Fi registrations at Manchester, Stansted and East Midlands airports has been obtained by an unauthorised third party.
Manchester Airports Group (MAG) has confirmed a cybersecurity incident in which an unauthorised third party obtained customer data relating to three UK airports.
The affected information relates to car park, lounge and Fast Track bookings and in-airport Wi-Fi registrations at Manchester Airport, Stansted Airport and East Midlands Airport.
MAG has said data relating to 8.7 million customers was affected by the incident.
According to MAG, the information accessed includes email addresses, telephone numbers, vehicle registration numbers and postcodes.
The airport operator stressed that neither MAG nor the system that was accessed holds customers’ bank or payment details.
In a statement, MAG said: “We immediately contained the risk and have been working with specialist advisors and taking appropriate steps to protect our customers and systems. We have informed and are working with the relevant authorities. At no point has passenger safety or aviation security been compromised.”
MAG said the incident has caused no operational disruption and does not involve operational airport systems. Passengers have been advised to continue travelling as normal, while existing bookings remain valid.
Following discovery of the incident, MAG restricted access to affected systems, brought in specialist cybersecurity experts and notified the relevant authorities. Its Data Protection team is overseeing the response.
As a precaution, access to the company’s online Manage My Booking service has been temporarily suspended.
MAG said it has contacted affected customers directly and advised them to remain alert for suspicious emails, text messages and telephone calls following the incident.
Customers have also been warned against clicking links or opening attachments in unexpected communications.
MAG said it will never unexpectedly contact customers asking for payment card information, banking details or passwords.
Industry experts have responded to the news
Muhammad Yahya Patel, vCISO and Cybersecurity Advisor for EMEA at Huntress, said: “Email addresses, phone numbers, and vehicle registrations combined is a precise targeting profile for anyone planning a follow-on fraud or phishing campaign. Scammers now know you travelled, roughly when, and have two direct contact routes to reach you with a convincing story. When that data ends up in an unauthorised third party’s hands alongside parking and lounge booking details, it fills in a surprisingly detailed picture of someone’s travel habits. If you’ve received a notification, treat any communication referencing your airport booking, parking, or travel details in the coming weeks with serious caution. MAG has confirmed they will never contact you to request payment details or passwords. Anything that does should be treated as a scam attempt using data from this breach.”
Daniel Wilcock, Threat Intelligence Analyst at Talion Cyber Security, said: “This is a very significant breach that has impacted millions of people.
“Fortunately, however, the attack doesn’t appear to have had an operational impact on flights or the running of the airports.
“Airports are widely regarded as critical national infrastructure and they are a prime target for threat actors and state-sponsored criminals. In this case, it appears that data was compromised, however, things could have been a lot worse particularly if planes themselves were involved.
“Any people impacted by the attack must be on guard for phishing emails, SMS scams, voice phishing plus postal scams.
“Given that everyone impacted by the incident will have the attack in common, scammers will likely use the event to launch attacks.
“This could be fake updates around the breach where customers are encouraged to click on links or divulge further information.
“Anyone impacted must be on guard for these types of attacks.”
Jamie Akhtar, CEO and Co-Founder of CyberSmart, said: “The cyberincident affecting The Manchester Airport Group is a reminder that organisations holding large volumes of customer data remain attractive targets for cybercriminals. Reports suggest data linked to car park, lounge and Fast Track bookings, as well as airport Wi-Fi registrations, was accessed across Manchester, London Stansted and East Midlands airports. While it is reassuring that airport operations, passenger safety and payment information were not compromised, details such as email addresses, phone numbers, postcodes and vehicle registrations can still be valuable to criminals looking to make scams and phishing attempts more convincing.
“Customers affected should be cautious of unexpected emails, texts or calls claiming to be from the airport or associated travel providers. Avoid clicking links or sharing personal information in unsolicited messages and, where possible, verify communications independently through an organisation’s official website or app. It is also good practice to use unique passwords for every account, enable multi-factor authentication and be alert to messages that use personal details to create a false sense of legitimacy or urgency. In the aftermath of a breach, vigilance against social engineering is just as important as securing the systems themselves.”

