Manchester, Stansted and East Midlands airports were affected by a cyber incident in which customer contact and service-related information was accessed.

UK Airports Cyber Breach Exposes Data of 8.7 Million Customers

The420.in Staff
7 Min Read

The UK’s Manchester Airports Group (MAG), which operates Manchester Airport, London Stansted Airport and East Midlands Airport, has confirmed a cybersecurity incident in which personal information linked to approximately 8.7 million customers was accessed by an unauthorised third party.

MAG confirmed the incident on August 27 and said the affected information related to customers who had used services including airport car parks, lounges, Fast Track bookings and in-airport Wi-Fi.

The compromised information includes email addresses, phone numbers, vehicle registration numbers and postcodes. MAG said the affected system did not contain customers’ bank or payment information.

The airport operator also said the incident did not affect aviation security, passenger safety or airport operations.

What Data Was Exposed?

According to MAG, the information accessed was primarily customer contact and service-related data.

Many affected records contained email addresses, while some also included phone numbers, vehicle registration details and postcodes. The information held in individual records varied depending on the airport service used.

MAG has said that neither the company nor the system accessed during the incident contained customers’ bank or payment details.

There has also been no indication that passport information or aviation-security data was accessed.

The incident therefore appears to involve the exposure of customer information rather than a compromise of systems responsible for flight operations or airport security.

Which UK Airports Are Affected?

The affected airports are all operated by Manchester Airports Group:

  • Manchester Airport
  • London Stansted Airport
  • East Midlands Airport

The exposed information relates to customers who used selected digital and airport services at these facilities.

MAG has not said that every customer using the three airports was affected. The company has been contacting customers whose information may have been involved.

Algoritha Security Launches ‘Make in India’ Cyber Lab for Educational Institutions

Did the Cyberattack Disrupt Flights?

MAG said the incident did not affect airport operations, aviation security or passenger safety.

There has been no indication from the airport operator that flights, check-in systems, passenger screening or other operational services were disrupted as a result of this incident.

This distinguishes the incident from cyberattacks in which attackers directly disrupt airport technology or critical operational systems.

MAG Says the Incident Was Contained

MAG said it acted immediately after identifying the incident and took steps to contain the risk.

The airport operator has brought in specialist cybersecurity advisers and is working with relevant authorities to investigate what happened and protect affected customers.

Customers who may have been affected are being contacted by the company.

The investigation is expected to establish how the unauthorised party gained access, what information was obtained and whether any further systems or data were affected.

Why Exposed Airport Data Can Be Used for Phishing

Even when bank details and passwords are not exposed, customer information such as email addresses, phone numbers, postcodes and vehicle registration numbers can have value to cybercriminals.

Attackers may use such information to make subsequent phishing or impersonation attempts appear more convincing. For example, a fraudulent message could claim to relate to an airport booking, parking payment, lounge reservation or recent journey.

Customers should therefore be cautious about unexpected messages that appear to come from airports, airlines, parking operators or travel companies.

They should avoid clicking suspicious links or providing passwords, payment details, verification codes or other sensitive information in response to unsolicited communications.

UK Airports Face Growing Cybersecurity Risks

The incident comes amid wider concerns about cyberattacks targeting major organisations and critical infrastructure in the UK.

Airports can be attractive targets because they operate large digital ecosystems connecting passenger services, bookings, parking, Wi-Fi, retail and other systems.

The latest incident follows a major cyber incident affecting Collins Aerospace in September 2025, which disrupted check-in and boarding services at several European airports, including airports in the UK. The UK’s National Cyber Security Centre subsequently worked with Collins Aerospace, affected airports and law-enforcement agencies to assess the impact.

The MAG incident is different in that the airport operator has said there was no disruption to aviation operations or passenger safety.

FCRF Launches Flagship Certified Cyber Security Auditor (CCSA) Program for Next-Generation Cyber Auditors

What Should Affected Customers Do?

Customers who receive an unexpected message referring to an airport booking or service should independently verify the communication before taking any action.

People should particularly be cautious if a message:

  • asks them to click an unfamiliar link;
  • requests payment or banking information;
  • asks for a password or one-time verification code;
  • claims that a parking, lounge or travel booking requires urgent action; or
  • directs them to install an application or provide additional personal information.

If a customer is unsure whether a communication is genuine, they should contact the relevant airport or service provider through its official website or verified contact channel.

Investigation Into the Breach Continues

Investigations into the cybersecurity incident are continuing. MAG has not publicly confirmed how the attackers obtained access or identified the unauthorised third party responsible.

The scale of the incident, involving information connected to approximately 8.7 million customers, highlights the importance of protecting personal data even when systems containing payment and operational information are not compromised.

Further details are expected to emerge as MAG and the relevant authorities continue examining the incident, the method of access and the information affected.

About the author — Ananya Aradhya writes on cybercrime, fraud, scams, cybersecurity, digital safety, and emerging threats. Her work also covers major criminal cases, financial frauds, consumer scams, and stories that highlight risks affecting people in the real and digital world.

Stay Connected