Manchester Airports Group Data Breach
27th August 2026

If you have recently used Manchester Airport, London Stansted or East Midlands Airport, you may have received an email from Manchester Airports Group (MAG) regarding a recent cyber security incident.

A spokesperson at MAG told The Register that it's believed that up to 8.7 million customers may be affected. The data involved relates to services including airport parking, lounges, Fast Track bookings and on-airport Wi-Fi.

MAG has confirmed that the information identified as having been accessed includes email addresses, phone numbers, vehicle registration numbers and postcodes.

Importantly, MAG has stated that the affected system did not contain customers' bank or payment details, and there has been no reported impact on passenger safety, aviation security or airport operations. MAG says it took immediate steps to secure the affected system, engaged external cyber security specialists and notified the relevant authorities. While the absence of financial information is reassuring, the incident remains significant given the volume and nature of the customer data involved.

It can be easy to underestimate the value of information such as an email address, phone number or postcode. However, cyber criminals rarely need a complete profile of an individual from a single source. Instead, information obtained through a breach can be combined with data from other sources to build a more convincing picture of a target. An email address and phone number, combined with a vehicle registration, postcode or knowledge of previous airport bookings, could provide enough context to support a targeted phishing or social-engineering attack.

MAG has warned affected customers to be particularly cautious of unexpected emails, calls and text messages claiming to be from the organisation. This is particularly important following a high-profile breach, as criminals can use the incident itself as the basis for convincing scams.

For example, a customer could receive a message claiming to be from MAG asking them to confirm personal details, verify a booking, make a payment, click a link or contact a customer support team. If the attacker has access to genuine information about the customer, the message may appear considerably more credible than a typical phishing attempt. The fact that the recipient already knows about the breach can make the deception even more effective.

If you have received a genuine notification from MAG, there is no need to panic, but it is sensible to remain particularly vigilant. If an email, text or phone call asks you to click a link, log in, provide additional information or make a payment, stop and verify the request independently. Rather than following links or using contact details provided in an unexpected message, visit the organisation's official website directly and use its published contact information.

Be especially cautious of messages designed to create urgency, such as claims that a booking will be cancelled, a payment is overdue or an account will be restricted unless you act immediately. Phishing is also not limited to email. If your phone number was included in the affected information, unexpected calls and text messages should be treated with the same level of caution.

For organisations, the MAG incident highlights that a cyber incident does not necessarily end when the compromised system has been secured. Once customer information has been accessed, there can be a second wave of attacks targeting customers, employees and partners.

Organisations therefore need to consider not only how they prevent and contain a breach, but also what happens afterwards. This includes how customers will be notified, how criminals could impersonate the organisation, what customers need to know to protect themselves, how customer-facing teams will respond to suspicious enquiries and how genuine communications can be made easy to distinguish from fraudulent ones.

Find MAG's statement on the incident here: https://mediacentre.magairports.com/mag-statement-on-cyber-security-incident/