Manchester Airport Group Discloses Data Breach Affecting 8.7 Million Customers

Manchester Airport Group (MAG) has disclosed a cybersecurity incident in which an unauthorised third party obtained data belonging to approximately 8.7 million customers, the company confirmed on 27 August 2026 The Guardian. MAG operates three UK airports: Manchester Airport, London Stansted, and East Midlands Airport.
The accessed data related to car park, lounge, and fast track bookings as well as in-airport wifi sign-ups across all three airports. MAG stated that the majority of the compromised records were customer email addresses gathered through terminal wifi registrations. Phone numbers, vehicle registration numbers, and postcodes were also accessed.
MAG was emphatic that neither the company nor the compromised system held customers' bank or payment details. The group also stated that passenger safety and aviation security were not compromised at any point, and that operations at all three airports remained unaffected.
Upon discovery, MAG said it immediately contained the risk and has been working with specialist advisers and the relevant authorities. Data security incident pages published on MAG airport domains, including East Midlands Airport's site, confirm the scope of the accessed data fields: email addresses, phone numbers, vehicle registrations, and postcodes East Midlands Airport.
The data set, while excluding financial information, is not trivial. Vehicle registration numbers linked to postcodes and phone numbers create a mosaic that could enable targeted phishing (fraudulent messages designed to trick people into revealing sensitive information), identity fraud, or physical-security risks for affected individuals. Email addresses tied to specific travel behaviours — airport lounge usage, fast track preferences, parking bookings — give an attacker contextual hooks for socially engineered campaigns that would carry a higher degree of plausibility than generic scam emails.
The fact that wifi sign-up data constituted the majority of the exposed records points to a familiar weak point in airport infrastructure. Terminal wifi registration pages typically collect email addresses and, in some configurations, phone numbers in exchange for free connectivity. These systems often sit on the operational periphery of an airport's IT estate, managed with less stringent access controls than core aviation systems. The result is a large volume of personally identifiable information flowing through infrastructure that may not receive the same security scrutiny as the operational technology layers that handle baggage, screening, and air traffic control.
MAG's statement that aviation security was not compromised draws a distinction between operational systems — air traffic control, baggage handling, security screening — and the customer-facing commercial platforms that process bookings and wifi registrations. That separation likely prevented the incident from escalating into a safety event. But the volume of records accessed, 8.7 million, places this among the larger UK data breaches involving a single operator in recent years.
The three affected airports serve distinct passenger demographics. Manchester is the largest airport outside London by passenger volume; Stansted handles a heavy concentration of low-cost carrier traffic; East Midlands serves a smaller, more regionally focused catchment. The data sets from each airport were exposed through the same incident, suggesting a shared backend platform or common third-party provider rather than three separate compromises.
The broader context here is one that cybersecurity and data protection professionals have seen repeatedly in large-scale breaches: the perimeter between commercial customer data and operational systems is where containment matters most. MAG's ability to keep the incident within the commercial data layer, without lateral movement into operational technology, appears to have been the decisive factor in avoiding disruption to airport operations. Whether the containment was architectural — built into the system's design — or the result of timely detection and response is not clear from the public disclosures.
The regulatory dimension will turn on timing. UK data protection law requires organisations to notify the Information Commissioner's Office of a notifiable personal data breach within 72 hours of becoming aware of it. MAG's reference to working with "the relevant authorities" suggests engagement is underway, though the company has not publicly detailed the timeline of detection, containment, and notification.
For the 8.7 million affected customers, the practical risk is elevated but bounded. No payment data was exposed, and the absence of financial credentials limits direct monetary fraud. But the combination of contact details, vehicle registrations, and location-specific travel data is sufficient for sophisticated phishing and social engineering operations. Affected individuals would be well advised to treat unsolicited communications referencing airport bookings or parking arrangements with heightened scrutiny.


