UK Airport Cyber-Attack Exposes 8.7 Million Customers

Hackers accessed data from 8.7 million customers of Manchester, Stansted and East Midlands airports. Here's what was taken and how to protect yourself.

Aug 28, 2026 - 17:38
 0
UK Airport Cyber-Attack Exposes 8.7 Million Customers

A breach on a national scale

 

One of the largest cyber-attacks to hit UK transport infrastructure this year has exposed personal data belonging to approximately 8.7 million customers across three of England's busiest airports. Manchester Airports Group (MAG), which operates Manchester, London Stansted and East Midlands airports, confirmed this week that hackers had accessed systems tied to a range of customer-facing services, though it stressed that flight operations and passenger safety were never compromised.

 

MAG said it discovered the breach on Tuesday 25 August, though the intrusion is understood to have taken place over the preceding weekend, with a public statement following two days later on Thursday 27 August. The company has since notified affected customers directly and reported the incident to the relevant authorities, including the UK's data protection regulator.

 

What was actually taken

 

The scale of the number — 8.7 million — has understandably alarmed passengers, but MAG has been keen to clarify exactly what it represents. The figure does not equate to 8.7 million complete passenger profiles; the vast majority of the exposed records are simply email addresses gathered when customers signed up for in-airport WiFi.

 

A smaller subset of the data is more detailed. Beyond the WiFi sign-up information, the breach also touched systems handling car park, lounge and fast-track bookings, with attackers obtaining email addresses, phone numbers, vehicle registration numbers and postcodes. Crucially, the airport group has repeatedly emphasised that no banking or payment card details were held on the affected systems, meaning financial information should not have been directly exposed.

 

A ransom demanded — and refused

 

Perhaps the most striking detail to emerge is that this was not simply a data-exposure incident but an attempted extortion. Hackers subsequently demanded a ransom for the return of the stolen data, but MAG confirmed it had refused to pay. No hacking group has publicly claimed responsibility, and investigators have not yet linked the attack to a specific known actor, though the incident fits a wider pattern of ransomware campaigns targeting critical infrastructure operators.

 

That wider pattern is becoming harder to ignore. The MAG breach follows other recent attacks on British infrastructure, including an incident earlier in August in which Iran-linked hackers reportedly knocked a British power plant offline for several days — one of several signs that UK critical infrastructure is facing an increasingly hostile cyber environment.

 

The human cost of a data breach

 

For ordinary travellers, the immediate risk is not financial theft but something more insidious: highly convincing scam attempts. Cybersecurity specialists have warned that stolen contact details, when combined with knowledge of a genuine airport booking, can be used to craft messages that look entirely legitimate — a fake parking refund notice, a bogus fast-track booking issue, or even a scam message referencing the breach itself.

 

One affected customer, a 71-year-old man from Cheshire, told BBC Radio Manchester that he and his wife had both received breach notifications after using East Midlands Airport and booking Manchester Airport parking earlier in the year, and said he remained unconvinced that MAG's reassurances were sufficient given that hackers now held his name and postcode.

 

What passengers should do now

 

MAG has taken its online Manage My Booking service offline as a precautionary measure while its investigation continues, working alongside external cybersecurity specialists. The company has reiterated that it will never contact customers unexpectedly to request payment details, banking information or passwords — advice security experts say is worth remembering, since scammers frequently impersonate breached companies in the weeks following an incident.

 

The Information Commissioner's Office has confirmed it has received notification of the breach and is examining the circumstances, a process that could take months and may ultimately determine whether MAG faces regulatory penalties over how the data was secured.

 

For now, the advice to the millions of people affected is straightforward: be sceptical of unexpected emails, texts or calls referencing airport bookings, parking or WiFi accounts, and verify anything unusual directly through official airport channels rather than clicking links in messages.

 

What's Your Reaction?

Like Like 0
Dislike Dislike 0
Love Love 0
Funny Funny 0
Angry Angry 0
Sad Sad 0
Wow Wow 0