Manchester Airports Group (MAG), operator of Manchester, London Stansted and East Midlands airports, has reported a “cyber security incident” that exposed millions of customer records.
The airport operator on Thursday (27 August) said “an unauthorised third party” accessed customer data linked to car park, lounge and Fast Track bookings, as well as in-airport wifi sign-ups at all three airports. The data includes email addresses, phone numbers, vehicle registrations and postcodes.
Nearly 8.7 million customers have been affected by the breach, according to the BBC.
MAG said "at no point has passenger safety or aviation security been compromised" and the system hacked did not hold customers' bank or payment details. Airport operations and customer parking services also remain unaffected.
In a statement MAG said: “We immediately contained the risk and have been working with specialist advisors and taking appropriate steps to protect our customers and systems. We have informed and are working with the relevant authorities. At no point has passenger safety or aviation security been compromised.
"We would like to reassure customers that Manchester Airport Group takes the security of customer information extremely seriously and we apologise for any inconvenience or concern caused.”
The incident is the latest in a series of cyber attacks targeting travel suppliers and airports. Last November, a third-party vendor for Spain-based Iberia Airlines exposed customer data, while in September several major European airports experienced disruptions after a cyber attack against a provider of check-in and boarding systems. This followed a June breach at Qantas that compromised approximately 6 million records, including contact details and frequent flyer numbers.
Read more in BTN’s Travel Risk Outlook 2026: Cyber crime is on the rise