World

What Happened in the Manchester Airport Data Breach

Elena MarquezPublished 3w ago4 min readBased on 3 sources
Reading level
What Happened in the Manchester Airport Data Breach
Photo by Brett Sayles on Pexels

Manchester Airport Group (MAG) has revealed that someone outside the company got hold of data belonging to about 8.7 million customers. The company confirmed this on 27 August 2026 The Guardian. MAG runs three UK airports: Manchester Airport, London Stansted, and East Midlands Airport.

The data that was taken came from car park bookings, lounge and fast track bookings, and wifi sign-ups at all three airports. MAG said most of the stolen records were email addresses that people entered when signing up for free wifi in the terminals. Phone numbers, vehicle registration numbers, and postcodes were also taken.

MAG stressed that it never held customers' bank or payment card details, so those were not exposed. The company also said that airport safety and security were not affected, and that all three airports kept running normally.

MAG said it acted quickly to contain the problem once it was discovered and has been working with security experts and the relevant authorities. Pages on the airports' own websites, including East Midlands Airport's site, confirm what types of data were accessed: email addresses, phone numbers, vehicle registrations, and postcodes East Midlands Airport.

Even without bank details, the stolen information is still useful to criminals. When someone's vehicle registration is combined with their postcode and phone number, it creates a detailed picture that could be used for scams or identity fraud. Email addresses linked to specific travel habits — like booking airport parking or using a lounge — make it easier for scammers to send convincing fake messages that reference real details about a person's trip.

The fact that wifi sign-ups made up most of the stolen data points to a common weakness. Airport wifi pages ask for an email address, and sometimes a phone number, before letting people connect for free. These systems are often less carefully protected than the core technology that runs airport operations, like baggage handling or air traffic control. That means a lot of personal information flows through systems that may not get the same level of security attention.

MAG's statement that aviation security was not affected draws a line between the systems that keep planes and passengers safe and the commercial platforms that handle bookings and wifi. That separation likely stopped the incident from becoming a safety issue. But 8.7 million records is a large number, placing this among the bigger UK data breaches involving a single company in recent years.

The three airports serve different types of travellers. Manchester is the largest airport outside London; Stansted handles a lot of low-cost flights; East Midlands serves a smaller regional area. The data from all three was exposed in the same incident, which suggests they shared a common system rather than being hacked separately.

The wider picture here is about how organisations separate different types of data. Keeping customer booking data away from the systems that run airport operations appears to have been what prevented this from disrupting flights. It is not clear from public statements whether that separation was built into the system's design or was the result of catching the breach quickly.

UK law requires organisations to report a significant data breach to the Information Commissioner's Office within 72 hours of finding out about it. MAG has said it is working with the relevant authorities, but has not shared specific details about when it detected the breach, when it contained it, or when it reported it.

For the 8.7 million people affected, the practical risk is real but limited. No bank details were exposed, which reduces the chance of direct financial theft. But the combination of contact details, vehicle registrations, and travel data could be used for convincing scam emails and phone calls. Anyone who used these airports should be cautious about unexpected messages that mention airport bookings or parking, even if they seem to know specific details.