Cyberattack on Three UK Airports Exposes Data of 8.7 Million Customers

Cyberattack on Three UK Airports Exposes Data of 8.7 Million Customers

A weekend cyberattack on the operator of Manchester, London Stansted and East Midlands airports has exposed personal information belonging to about 8.7 million customers. Image: Amsterdam City Archives/Unsplash

A cyberattack on Manchester Airports Group exposed information belonging to about 8.7 million customers across three UK airports.

Aug 28, 2026

A cyberattack on three of the U.K.’s busiest airports has exposed personal information belonging to about 8.7 million customers, turning routine airport Wi-Fi and booking records into a security concern.

Manchester Airport, London Stansted and East Midlands Airport were targeted in an attack on Manchester Airports Group (MAG), which operates all three facilities.

The compromised information included email addresses, phone numbers, vehicle registration numbers and postcodes. Most of the affected data appears to be email addresses collected when passengers signed up for airport Wi-Fi, according to the BBC.

Other information came from customers using services such as airport parking, lounges and fast-track bookings. MAG said it discovered the intrusion Tuesday after the attackers accessed its systems over the weekend. The company said it identified and closed the point of entry, immediately containing the threat.

The BBC reported that the attackers demanded a ransom for the stolen information, but MAG refused to pay. The amount demanded was not disclosed.

Airports say flights are safe

Despite the scale of the breach, MAG said there was no impact on airport operations or aviation security.

“At no point has passenger safety or aviation security been compromised,” a MAG spokesperson told the BBC.

The company also said the affected system did not contain customers’ bank or payment details. Flight bookings remained valid, and parking services continued operating normally. The incident comes during the busy summer travel period. More than 50 million passengers traveled through the three airports combined last year.

Must-read security coverage

What this means for customers

For affected customers, the immediate concern may be what happens after the breach rather than disruption at the airports themselves.

Advertisement

Stolen email addresses combined with names, phone numbers, postcodes or vehicle details can give criminals useful material for convincing phishing messages. Attackers could potentially pose as an airport, airline or travel service and use genuine-looking details to make fraudulent messages more believable.

Customers who used the affected airports should be especially skeptical of messages that claim to relate to parking, flights, refunds or payments.

MAG has said customers do not need to take specific action following the breach, but vigilance is important. Unexpected requests for passwords, payment information or other personal details should not be trusted simply because they appear to reference a recent airport trip.

The attack also shows why companies operating critical infrastructure must treat customer-facing services as part of their wider security perimeter. Even when an intrusion leaves planes flying normally, the personal data associated with those operations can still be a valuable target.

Other Security News: Australia Post’s password notebooks have reignited debate over whether writing credentials on paper can be safer than storing them on devices targeted by infostealer malware. 

Aminu Abdullahi

Aminu Abdullahi is a B2C and B2B technology and finance writer with more than six years of experience covering enterprise IT, cybersecurity, cloud computing, artificial intelligence, fintech, business software, and emerging technologies. He has written for a wide range of technical and business audiences, from IT professionals and cybersecurity leaders to small business owners, executives, and technology buyers. His work has appeared in publications including: TechRepublic eWEEK Channel Insider Geekflare Enterprise Networking Planet eSecurity Planet CIO Insight Webopedia With a background in computer science, Aminu specializes in translating complex technical subjects into clear, practical, and accessible content. His writing helps readers understand emerging technologies, evaluate business software, strengthen cybersecurity strategies, and make more informed decisions about technology investments. Across his work, Aminu focuses on the real-world impact of technology, connecting technical innovation with business value, operational efficiency, security, and long-term digital transformation.