Manchester Airport Group Cyberattack Exposes Traveler Data
Manchester Airport Group (MAG) has confirmed that hackers breached its systems and stole customer information, including data associated with Wi-Fi registrations at Manchester, London Stansted, and East Midlands airports.
MAG said the attackers did not access customer payment information, and the cyberattack has not affected airport operations.
In a statement released today, the company said the compromised data may also relate to parking, airport lounge, and Fast Track bookings. Exposed information could include customer email addresses, telephone numbers, vehicle registration numbers, and postal codes.
“The incident has not disrupted operations,” MAG said, adding that airport services and customer parking remain available as normal.
As a precaution, MAG has temporarily suspended its online Manage My Booking service. Travelers who need assistance have been instructed to contact the company by telephone instead.
MAG is the United Kingdom’s largest airport operator. The company owns Manchester, London Stansted, and East Midlands airports, which collectively serve more than 66 million passengers each year.
MAG employs approximately 40,000 people and reported annual revenue of £1.5 billion.
After detecting the intrusion, MAG said it moved quickly to contain the breach by restricting access to affected systems, working with external cybersecurity experts, and notifying law enforcement agencies.
Customers who may have been affected should remain alert for suspicious emails, text messages, and phone calls. Travelers should avoid clicking links or opening attachments in unexpected communications.
MAG said it will never ask customers to provide payment card details, bank account information, or passwords. Customers should reject and report any attempt to obtain personal, financial, or other sensitive information.
Customers can also review the NCSC post-breach recommendations for additional guidance on protecting their accounts and personal information.
The company said it has contacted customers who may be affected, but it has not disclosed how many people were impacted by the Manchester Airport Group data breach.
Local media reported that as many as 8.9 million travelers may be affected, reportedly based on non-public statements from MAG. However, BleepingComputer has not independently verified that figure.
At the time of publication, no ransomware or data extortion group had publicly claimed responsibility for the attack.
Prevention scores do not always show what happens after an attacker gains initial access. When threat actors use valid credentials, an organization’s defenses can weaken significantly.
Blue Report 2026 evaluates defensive techniques across technologies using 338 million simulations conducted in customer production environments.
Source: www.bleepingcomputer.com




