Manchester Airports Group says hackers stole travelers’ data

Manchester Airports Group Fesses Up to Data Heist, Travelers’ Wi-Fi Sign-Ups and Booking Details Compromised

In a disturbing revelation that’s left thousands of travelers on high alert, Manchester Airports Group (MAG) has confirmed that hackers have breached its systems, making off with sensitive customer data. The affected airports – Manchester, Stansted, and East Midlands – are among the UK’s busiest, serving over 66 million passengers annually.

According to MAG, the cyber attackers made off with a treasure trove of personal details, including email addresses, phone numbers, vehicle registration numbers, postcodes, and even booking information for car parks, lounges, and Fast Track services. Crucially, however, the hackers did not access customers’ payment card details or compromise airport operations in any way.

The breach was discovered by MAG’s security teams, who quickly sprang into action to contain the damage. External experts were brought in to assist with the response, and law enforcement has been notified. As a precautionary measure, the online “Manage My Booking” service has been temporarily suspended, and customers are being directed to use phone lines instead.

The incident highlights the importance of robust cybersecurity measures in protecting sensitive customer data. With an estimated 8.9 million travelers potentially affected, MAG is urging customers to remain vigilant for suspicious communications and avoid clicking on links or providing sensitive information via email or SMS.

In a statement, MAG assured customers that they will never ask for payment card information, banking details, or passwords. The company has also taken steps to notify impacted customers directly, although the exact number of affected individuals remains unclear.

The breach is a stark reminder that even the most seemingly secure systems can be vulnerable to attack. As cybersecurity expert Bill Toulas noted in related research, “Once attackers have valid credentials, only 37% of their actions are blocked.” This highlights the need for continuous monitoring and improvement of security defenses, particularly when it comes to protecting sensitive customer data.

For travelers affected by this breach, the key takeaway is to remain alert and cautious. Follow NCSC’s post-breach recommendations to stay safe online, and be wary of any suspicious communications or requests for sensitive information. By taking these simple precautions, you can help minimize the risk of falling victim to phishing scams or other cyber threats.

As the investigation into this breach continues, one thing is clear: cybersecurity is a top priority for both businesses and individuals. By staying informed and taking proactive steps to protect your personal data, you can reduce your risk of being affected by similar incidents in the future.


Source: Bleeping Computer — 2026-08-27