CSIDB logo
Incident

Manchester Airport

Incident posture

Attack window
Aug 2026
Location
United Kingdom
Status
Ongoing
CIA posture
Available to members
Updated
2026-08-27 20:33

Linked entities

Victim
Manchester Airport
Threat actors
0 actors
Sources
1 source

Timeline

Occurred
Undetermined
Discovered
Aug 2026
Disclosed
Aug 2026
Resolved
Pending

Summary

Manchester Airports Group confirmed a cyberattack in which an unauthorised third party accessed the personal data of approximately 8.7 million customers. The compromised information related to car park, lounge and Fast Track bookings as well as sign‑ups for the airports’ free Wi‑Fi networks, exposing email addresses, phone numbers, vehicle registration numbers and postcodes; for most affected individuals only an email address obtained via Wi‑Fi sign‑in was involved. No bank details or payment card data were stored on the affected system, and flight operations, security and day‑to‑day activities remained uninterrupted. The group temporarily suspended its online Manage My Booking service while it worked with specialist advisers and relevant authorities to contain the breach and began contacting customers to warn them of possible phishing attempts using the exposed data.

Motives

Detailed motive labels are available to members.

0 motives

TTPs

Detailed technique labels are available to members.

0 techniques

Description

The incident involving Manchester Airports Group (MAG) was reported on 27 August 2026. MAG, which owns Manchester, London Stansted and East Midlands airports, announced that it had become aware of a cyber intrusion on a Tuesday and moved immediately to contain the breach. An unauthorised third party accessed the personal data of approximately 8.7 million customers. The compromised information related to car park, lounge and Fast Track bookings as well as sign‑ups for the airports’ free Wi‑Fi networks, exposing email addresses, phone numbers, vehicle registration numbers and postcodes.

For the majority of those affected, the exposure was limited to an email address obtained through a Wi‑Fi sign‑in. MAG confirmed that no bank details or payment card information were stored on the compromised system and that flights, security and day‑to‑day airport operations remained unaffected. As a precautionary measure, the group temporarily suspended its online Manage My Booking service while the investigation proceeded. MAG stated that it was working with specialist advisers and the relevant authorities to investigate the incident. Customers were contacted directly and advised to watch for follow‑up phishing attempts that might use the stolen data.

Security specialists warned that the exposed details increased the risk of targeted phishing and smishing messages that incorporate genuine travel information to appear credible. MAG reiterated that it would never contact customers unexpectedly to request banking information. The organisation has not disclosed whether it holds a dedicated cyber insurance policy. Under UK GDPR, organisations must report notifiable breaches within 72 hours of awareness; MAG’s timeline—discovery on Tuesday, public confirmation and customer notification by Thursday—indicates an effort to comply with that requirement.

Sources

Sources available to members: 1 source.

CSIDB