Manchester Airports Group, which operates Manchester, London Stansted and East Midlands airports in England, said on August 27, 2026 that it was hit by a cyberattack exposing data belonging to roughly 8.7 million customers, according to the company’s public notice and reporting by The Record and the Yorkshire Post. An unauthorized third party accessed customer data tied to car park, lounge and Fast Track bookings, as well as in-airport Wi-Fi sign-ups.
The compromised information includes email addresses, phone numbers, vehicle registrations and postcodes; the company said neither it nor the affected system stores payment card or banking details, and that no financial data was exposed. MAG said it was alerted to the incident on a Tuesday and believes attackers first accessed the data a few days before discovery. The company has restricted access to the affected systems, engaged outside cybersecurity specialists, notified relevant authorities and temporarily suspended its online Manage My Booking service as a precaution.
MAG said passenger safety and aviation security systems were not affected and that flights, airport operations and parking continue to operate normally; the three airports handled more than 65 million passengers last year. The incident illustrates a distinction increasingly emphasized by airport operators: a breach of customer-facing IT and booking systems does not necessarily indicate any compromise of the physical security, screening or airside operational systems that are typically segmented onto separate networks.

Leave a Reply