On 27 August 2026, Manchester Airports Group (MAG), the operator of Manchester Airport, London Stansted Airport and East Midlands Airport, confirmed that hackers had accessed customer data linked to airport WiFi sign-ups, car parking, airport lounge and Fast Track bookings. MAG became aware of the intrusion on Tuesday, 25 August, and said it immediately restricted access to the affected systems, brought in external cyber security specialists and notified the relevant authorities.
The scale is significant even by the standards of a busy year for breach disclosures: data linked to 8.7 million customers, spanning email addresses, phone numbers, vehicle registration numbers and postcodes. MAG says the vast majority of those affected had only their email address exposed, and that no bank or payment card information was ever stored on the compromised system. The company has not disclosed how the attacker gained access, and no threat actor has publicly claimed responsibility.
What makes the exposure notable is not any single record but the combination. Security researchers pointed out that email address, phone number and vehicle registration together form a precise targeting profile, enough for an attacker to know that a person travelled, roughly when, and to reach them through two direct channels with a plausible story about parking, a Fast Track booking, or the breach itself. MAG has since suspended its online Manage My Bookings service as a precaution and is warning customers to be wary of unexpected calls, emails and texts referencing the incident.
MAG says airport operations, passenger safety and aviation security were unaffected throughout, and that existing bookings remain valid. That containment is real, but it understates the exposure. Under UK GDPR, organisations must notify the Information Commissioner's Office within 72 hours of becoming aware of a breach likely to put people's rights at risk, and MAG's own data protection team is now overseeing an investigation into an incident that has already put contact and travel details on 8.7 million people into unknown hands. The airport sector has had a difficult year: Qilin ransomware claimed a breach at Tulsa International Airport in February, and a ransomware attack on check-in vendor Collins Aerospace disrupted operations at Heathrow, Brussels, Berlin, Dublin and Cork in September 2025.
The defences that failed here were not weak by conventional standards. MAG detected the intrusion, moved quickly to contain it, engaged outside specialists, and disclosed within days rather than months. None of that stopped the underlying export of contact, travel and vehicle data for 8.7 million customer records before anyone outside the attack could confirm whether that export should have happened at all.
A bulk export of contact and travel data covering 8.7 million people is an execution event, not a background system function. Before a query against a WiFi registration, parking or booking database can return records at that scale, a confirmation request should reach the named system owner at MAG on their registered device, requiring a biometric response over a channel separate from whatever access path the attacker used.
MAG still does not know how the attacker got in, which is exactly the scenario GoFirm is built for. It does not matter whether access came through a stolen credential, an exploited vulnerability, or a route not yet identified. None of those routes can produce a biometric confirmation from a named authority on a device the attacker does not hold. The execution boundary holds regardless of how the request arrived.
GoFirm is The Authority Platform. Stop unauthorised action. Every time.
In association with Osinto.ai, the collective intelligence and governance network for Security, Resilience & Defence teams.
References
1. Corvin, A. 2026. 8.7 million customers hit as Manchester Airports Group breach exposes airport WiFi sign-ups. Cybernews, 27 August 2026.
2. RTE. 2026. Customers' data accessed in cyber attack on UK airports. RTE News, 27 August 2026.
Back to Blog
Case Studies·3 min read
Three UK airports let an unidentified attacker walk out with contact and travel data on 8.7 million people.
By GoFirm Team
