Ol' Blighty

Cyberattack Exposes 8.7 Million Airport Customer Records

Manchester Airport Group confirms data breach affecting Manchester, Stansted, and East Midlands airports, but assures no compromise to passenger safety or financial details.

A red 'CONFIDENTIAL' file folder on a dark desk with blurred emergency lights.
Callum Smith
Callum Smith
A cyberattack has compromised the data of approximately 8.7 million customers across Manchester Airport Group's operations.
The breach primarily accessed customer email addresses, specifically those linked to Wi-Fi sign-ups within the terminals at London Stansted Airport, Manchester Airport, and East Midlands Airport.
Phone numbers, vehicle registration numbers, and postcodes were also accessed; these details related to car park, lounge, and fast track bookings, alongside in-airport Wi-Fi sign-ups.
Crucially, no bank or payment details of customers were accessed during the incident. A MAG spokesperson confirmed that neither MAG nor the system accessed holds customers’ bank or payment details.

Neither MAG nor the system accessed holds customers’ bank or payment details.

MAG spokesperson
Airport operations at all three locations remained unaffected by the cyber attack. Customer parking services continued to operate normally, as a MAG spokesperson reiterated that the incident had not resulted in any operational disruption.
MAG has contained the cybersecurity risk and issued an apology. The group works with specialist advisers and authorities to safeguard customer data, with a MAG spokesperson stating that the group immediately contained the risk and has been taking appropriate steps to protect customers and systems.
The group has informed and collaborates with the relevant authorities, ensuring passenger safety or aviation security was not compromised at any point. A MAG spokesperson added that Manchester Airport Group takes the security of customer information extremely seriously and apologizes for any inconvenience or concern caused.
Manchester Airports Group claims the identity of the hackers was known. However, it remains unclear who carried out the attack, and the company has warned customers to be cautious of unexpected emails, calls, or text messages asking for payment or banking information.