Manchester Airport
Incident posture
Linked entities
- Victim
- Manchester Airport
- Threat actors
- 0 actors
- Sources
- 1 source
Timeline
Summary
Manchester Airports Group confirmed a cyberattack in which an unauthorised third party accessed the personal data of approximately 8.7 million customers. The compromised information related to car park, lounge and Fast Track bookings as well as sign‑ups for the airports’ free Wi‑Fi networks, exposing email addresses, phone numbers, vehicle registration numbers and postcodes; for most affected individuals only an email address obtained via Wi‑Fi sign‑in was involved. No bank details or payment card data were stored on the affected system, and flight operations, security and day‑to‑day activities remained uninterrupted. The group temporarily suspended its online Manage My Booking service while it worked with specialist advisers and relevant authorities to contain the breach and began contacting customers to warn them of possible phishing attempts using the exposed data.
Motives
Detailed motive labels are available to members.
TTPs
Detailed technique labels are available to members.
Description
The incident involving Manchester Airports Group (MAG) was reported on 27 August 2026. MAG, which owns Manchester, London Stansted and East Midlands airports, announced that it had become aware of a cyber intrusion on a Tuesday and moved immediately to contain the breach. An unauthorised third party accessed the personal data of approximately 8.7 million customers. The compromised information related to car park, lounge and Fast Track bookings as well as sign‑ups for the airports’ free Wi‑Fi networks, exposing email addresses, phone numbers, vehicle registration numbers and postcodes.
For the majority of those affected, the exposure was limited to an email address obtained through a Wi‑Fi sign‑in. MAG confirmed that no bank details or payment card information were stored on the compromised system and that flights, security and day‑to‑day airport operations remained unaffected. As a precautionary measure, the group temporarily suspended its online Manage My Booking service while the investigation proceeded. MAG stated that it was working with specialist advisers and the relevant authorities to investigate the incident. Customers were contacted directly and advised to watch for follow‑up phishing attempts that might use the stolen data.
Security specialists warned that the exposed details increased the risk of targeted phishing and smishing messages that incorporate genuine travel information to appear credible. MAG reiterated that it would never contact customers unexpectedly to request banking information. The organisation has not disclosed whether it holds a dedicated cyber insurance policy. Under UK GDPR, organisations must report notifiable breaches within 72 hours of awareness; MAG’s timeline—discovery on Tuesday, public confirmation and customer notification by Thursday—indicates an effort to comply with that requirement.
Sources
Sources available to members: 1 source.