Manchester, Stansted and East Midlands airports say hackers took data on 8.7 million customers — from the car park bookings and the terminal wi-fi
Manchester Airports Group says no payment details were held on the breached system and that flights were never affected. What the attackers did get is a list of email addresses, phone numbers, postcodes and vehicle registration plates belonging to a sixth of the United Kingdom — the raw material for a very convincing scam.

The reassuring half of Thursday's disclosure is the half that will be quoted. Manchester Airports Group, which runs Manchester, London Stansted and East Midlands airports, said that a cyber-attack by an unauthorised third party had been contained, that no bank or payment card details were held on the affected system, and that "at no point has passenger safety or aviation security been compromised." No flight was delayed. The car parks kept working.
The other half is the number. Data belonging to roughly 8.7 million customers was accessed — email addresses in the main, along with phone numbers, postcodes and vehicle registration numbers, drawn from car park, lounge and fast-track bookings and from sign-ups to the wi-fi in the three airports' terminals.
The three airports involved
MAG is the largest UK airport operator outside Heathrow, and the scale of the group explains how a customer database reaches 8.7 million records. Manchester handles more than 32 million passengers a year. Stansted, London's fourth airport and the base of Europe's largest low-cost carrier, handles more than 30 million. East Midlands adds around 4 million passengers and is one of the country's busiest dedicated air freight hubs.
Between them that is a substantial fraction of everyone who flies from Britain, and the breached systems are exactly the ones that touch the widest slice of them. You do not have to have flown from Manchester to be in this dataset. You only have to have parked there, or bought a fast-track pass, or connected a phone to the terminal wi-fi and typed an email address into the captive portal to get online.
Why "no payment details" is not the end of the story
The absence of card data genuinely does matter. It rules out the most direct form of loss, and it is why MAG has been able to tell customers there is no immediate action to take with their banks. But the security value of a breach is not measured only by whether the stolen records can be spent.
Consider what this particular combination gives an attacker. An email address establishes contact. A phone number establishes a second channel and enables SIM-swap and smishing attempts. A postcode narrows identity to a street. And a vehicle registration number — the field that makes this breach unusual — ties a named individual to a specific car that was parked at a specific airport on specific dates.
That last item is the one worth dwelling on. A parking record is a travel record. It says the vehicle's owner was away from home, from roughly this date to roughly that one. Aggregated across 8.7 million entries and cross-referenced with a postcode, it is a dataset with obvious secondary uses that have nothing to do with fraud at all.
The scam that writes itself
The immediate risk is phishing, and MAG's own warning is unusually specific about it. In an email to customers, Stansted urged people to be "particularly cautious of unexpected emails, calls or text messages" claiming to come from the airport, adding: "We will never contact you unexpectedly to ask for payment or banking information."
We would urge you to be particularly cautious of unexpected emails, calls or text messages claiming to be from us.
That warning is worth taking seriously because of how well this data supports a convincing approach. Airport parking is one of the few consumer transactions where an unexpected message about a charge is entirely plausible — overstays, tariff differences, penalty notices and number-plate recognition disputes are all normal. A message that quotes your actual registration plate, your actual postcode, and the actual terminal you used does not read like a scam. It reads like admin.
The window for that is now. Phishing kits built on a fresh breach are typically deployed within days, while the incident is in the news and a message about it is least surprising. Anyone in the affected group should assume any parking-related message received over the next several weeks is hostile until proven otherwise, and should reach the airport through its own website rather than through a link.
The regulatory clock
MAG said it had "informed and are working with the relevant authorities" and had engaged specialist advisers. Under UK data protection law, an organisation must notify the Information Commissioner's Office within 72 hours of becoming aware of a personal data breach that poses a risk to individuals, and must tell affected individuals directly where the risk is high. The customer emails that went out on Thursday indicate MAG has concluded it falls in that category.
British precedent on penalties is instructive but not predictive. The ICO fined British Airways £20 million over the 2018 attack on its website and app, having initially proposed a figure nine times larger, and the reduction was driven partly by the pandemic's effect on aviation and partly by the airline's remediation. easyJet disclosed in 2020 that around nine million customers' details had been accessed, including the card details of some 2,200 of them, and was not fined at all.
The variable that separates those outcomes is not the record count. It is whether the regulator concludes the organisation's security was inadequate before the incident and whether the response afterwards was fast and candid. On the second test, MAG's Thursday disclosure — same-day customer notification, an explicit statement of which data categories were involved, and a named warning about the phishing risk — is close to the model answer.
Aviation has become a preferred target
This is the second serious cyber incident to hit European aviation inside a year, and the two are instructive precisely because they are so different. In September 2025, ransomware against Collins Aerospace's MUSE platform — the shared check-in and boarding software used at more than 170 airports worldwide — forced Heathrow, Brussels and Berlin Brandenburg to revert to manual processing. More than a hundred flights were delayed or cancelled and passengers queued for hours. A 40-year-old man was arrested in Britain days later.
That attack hit operations and left the data alone. This one hit the data and left operations alone. Between them they map the two distinct attack surfaces an airport presents: the operational technology stack that moves aircraft and people, which is regulated, segmented and audited to aviation standards, and the commercial customer stack — parking, lounges, wi-fi, loyalty, retail — which is regulated as ordinary e-commerce and generally built to that standard.
MAG's insistence that aviation security was never compromised is, in that light, both true and slightly beside the point. The commercial estate was never the part anyone was worried about protecting from a safety perspective, which is exactly why it holds 8.7 million records with comparatively little scrutiny attached to them.
There is a commercial logic to the imbalance, and it is not a flattering one. Airports have spent fifteen years rebuilding themselves as retail businesses with runways attached, because aeronautical charges are capped and regulated while parking, lounges, duty free and food are not. Every one of those non-aeronautical revenue lines runs on customer data, and each new one is bolted onto an estate that was never designed as a data business. The breach did not happen in the part of the airport that flies planes because that is not where the customer records are.
The wi-fi sign-up problem
The single most avoidable element of this breach is the terminal wi-fi database. Captive portals collect an email address because marketing wants one, not because the network needs one — the connection works identically if the field is discarded after authentication. Retaining those addresses converts a transient technical interaction into a permanent marketing asset, and a permanent marketing asset into a permanent liability.
Data minimisation is not an abstract compliance principle here; it is the difference between a breach of a few hundred thousand paying parking customers and a breach of nearly nine million people, most of whom did nothing more than want to check their email before a flight. Every organisation that runs a guest network is currently sitting on the same pile.
MAG has apologised for the inconvenience and concern caused and says the risk was contained immediately. Both things can be true and the exposure still runs for years, because email addresses, phone numbers, postcodes and number plates do not expire and cannot be reissued. Unlike a card, you cannot cancel your registration plate and have a new one posted out.
The practical advice for the 8.7 million is therefore short and unglamorous. Treat every message about airport parking, a lounge booking or a fast-track pass as suspect for the rest of the year, whatever plate or postcode it quotes back at you. Do not click a payment link in one; go to the airport's site directly. If an email address used at Stansted or Manchester is also a login somewhere else, change that password and turn on two-factor authentication, because credential-stuffing lists are assembled from exactly this kind of dump. None of that undoes the breach. It just makes the list less profitable for whoever is holding it.
This report is based on statements issued by Manchester Airports Group and London Stansted Airport on Thursday, August 27, 2026, and on contemporaneous reporting by the Guardian and PA Media. Passenger volumes are annual figures for the three airports. MAG has not said when the intrusion began, how it was carried out, or whether a ransom was demanded.
