Manchester Airports Group, which operates three of the UK's busiest airports, says 8.7 million customers were affected by a recent cyberattack in which an extortion group stole customer data. The company, which runs Manchester Airport, Stansted Airport in Essex, and East Midlands Airport in Derbyshire, confirmed the incident on August 27, 2026. MAG said the attack didn't involve ransomware, and emphasized that passenger safety and aviation security were never at risk.
The vast majority of those impacted had only their email addresses taken, according to MAG. Most of these addresses were gathered when customers signed up for public Wi-Fi at the airports, the company told The Register. The next largest group consisted of people who made incomplete bookings — entering their information while considering car parking or Fast Track services but never finishing the purchase. An even smaller portion came from customers who actually completed bookings. The affected system doesn't store bank or payment information, MAG confirmed.
According to MAG, the attackers broke into one of its systems and then extracted files from a database that a third party hosted. Company leadership characterized the incident as "a hack, not a lapse," describing it as a sophisticated intrusion rather than the result of human error like staff accidentally sharing login credentials. The Information Commissioner's Office asked MAG not to disclose the extortion group's name, the ransom note details, or the specific demands, mainly to prevent giving the attackers publicity. However, MAG said the extortion amount requested was notably lower than what the ICO understands this group typically demands. The company hasn't paid the extortionists.
MAG said none of its airports faced operational problems during the attack, though it temporarily disabled its Manage My Booking service as a precaution. Customers needing to change or cancel bookings within 72 hours of the announcement were directed to contact customer service instead. The company, whose airports handled a record 66 million passengers in the most recent financial year, has already notified affected customers and is working with authorities. MAG advised customers to stay alert for phishing attempts but reassured travelers that visiting its airports remains safe. The company apologized for any worry or inconvenience caused, noting it takes customer data security extremely seriously. For travelers already frustrated by parking fees — one customer complained about paying £80 for five days at Stansted — learning their personal information was also compromised added further aggravation. The scale of email address exposure creates a substantial pool of targets that attackers can exploit for future social engineering campaigns, while the company's transparency about third-party database involvement highlights how modern airport operations rely on interconnected systems that expand the potential attack surface.

