Manchester Airports Group Hack Exposes 8.7M Records

Manchester Airports Group (MAG), which operates Manchester, London Stansted and East Midlands airports, confirmed on August 27-28, 2026 that hackers gained unauthorised access to systems holding customer data.
The company said the stolen information includes email addresses, phone numbers, postcodes and vehicle registration numbers connected to airport Wi-Fi sign-ups, car park bookings, airport lounge access and Fast Track service reservations. MAG stated that neither the company nor the affected system held customers' bank or payment card information, and that the breach caused no disruption to flights or airport operations.
Several outlets, including Bitdefender's HotForSecurity and BleepingComputer, reported that around 8.7 million customers were affected, based on details from MAG's disclosure. MAG itself has not published an official precise number, so the figure should be treated as a widely reported estimate rather than a confirmed company statistic.
As a precaution, MAG temporarily suspended its online "Manage My Booking" service, directing affected travelers to its phone line instead. The company said it knows the identity of the group behind the attack but has not named it publicly, and that specialist cybersecurity advisers and relevant authorities have been informed. No ransomware or extortion group had publicly claimed responsibility for the attack at the time of reporting.
MAG is advising customers whose data may have been exposed to stay alert for suspicious emails or text messages and to avoid clicking on links from unsolicited communications, warning that the combination of contact details and travel-related information raises the risk of targeted phishing attempts.
Related
OpenAI Agent Breached Medicare Portal; Australia Told 84 Days Later
996 Zyxel Switches Looted in 48 Countries; Patch Due Sept. 24
Attacks on WordPress RCE Flaw Rose Tenfold After Sept. 22 Fix
Arista VeloCloud Zero-Day at CVSS 10.0; Patch Due Sept. 25
Check Point: VPN Flaw Under Attack Since Sept. 12, Patch by Sept. 25
Malware Lets 4 AI Models Vote on Its Next Attack Move
Microsoft Shuts Down AI Phishing Service That Hit 12,000 Inboxes
F5 Patches Exploited BIG-IP Flaw; CISA Deadline Is Sept. 25
Trending now
- US-China Trade Truce Extended to Jan. 10 as Xi Visits
- Amoeba Breeds at 63°C, Past the 60°C Limit for Complex Life
- 996 Zyxel Switches Looted in 48 Countries; Patch Due Sept. 24
- Oracle Invokes Force Majeure on 2.45GW Stargate Data Center
- Diller Drops $18B MGM Bid; Stock Falls 9.5% to February Levels
- Taylor Swift Adds 4 Songs to ‘Showgirl’ in Sept. 25 Encore
- Attacks on WordPress RCE Flaw Rose Tenfold After Sept. 22 Fix
- Rivian Recalls 98,828 EVs Over Rearview Camera Fault
Comments
No comments yet. Be the first.