Download Privacy Needle App

Type to search

News

Manchester Airport Cyberattack Exposes 8.7M Customer Data

Share
A major cyberattack on Manchester Airport and two other UK airports exposed data linked to 8.7 million customers, raising fresh phishing concerns.

Manchester Airport Cyber Attack Exposes Data of 8.7 Million Customers in Major UK Breach

  1. Manchester Airport Cyberattack: 8.7 Million Customers Caught in Data Breach
  2. 8.7 Million Airport Customers Hit by Major UK Cyberattack
  3. Manchester Airport Hack Exposes Millions of Customer Records
  4. Major Cyberattack Hits UK Airports, Exposing Data of 8.7 Million Customers
  5. Airport Cyberattack Exposes Millions of Emails, Phone Numbers and More

A major cyberattack targeting three of the UK’s busiest airports has exposed personal information belonging to approximately 8.7 million customers, in one of the country’s largest recent data breaches.

Manchester Airports Group (MAG), which operates Manchester Airport, London Stansted Airport and East Midlands Airport, confirmed that attackers accessed customer information connected to airport Wi-Fi registrations, car park bookings, lounge reservations and fast-track services.

The compromised information includes email addresses, phone numbers, vehicle registration numbers and postcodes. However, MAG said that bank account information and payment details were not affected.

What happened at Manchester Airport?

The cyberattack was discovered after suspicious activity was detected on MAG’s systems over the weekend. The company said it identified the incident on Tuesday and moved quickly to contain the threat.

MAG said passenger safety and aviation security were never compromised, and airport operations continued normally despite the attack. The incident affected customer data systems rather than the systems responsible for aircraft operations or airport safety.

The majority of the affected information reportedly came from customers who had registered for Wi-Fi inside airport terminals. Additional information was connected to services such as parking, airport lounges and fast-track bookings.

Which airports were affected?

The breach extends beyond Manchester Airport.

The three airports operated by MAG that were affected are:

  • Manchester Airport
  • London Stansted Airport
  • East Midlands Airport

Together, the airports handled tens of millions of passengers over the past year, making the incident significant both in terms of the amount of data involved and the number of people potentially exposed.

Customers warned about phishing scams

While the stolen information does not reportedly include banking or payment details, cybersecurity experts warn that exposed contact information could still be valuable to criminals.

Attackers could potentially use names, phone numbers, email addresses, postcodes and other details to create convincing phishing messages impersonating an airport, airline, parking provider or travel company.

Affected customers are therefore being urged to be particularly cautious about unexpected emails, text messages or phone calls requesting passwords, payments or financial information.

Customers should avoid clicking suspicious links and should independently visit an airport or airline’s official website rather than using links contained in unexpected messages.

Authorities investigate the breach

MAG has brought in cybersecurity specialists and is working with relevant authorities to investigate the attack and strengthen its systems.

The incident comes amid a growing series of cyberattacks against major UK organizations and critical infrastructure, increasing concerns about the ability of criminals to target organizations holding large amounts of personal information.

For travelers, the attack is another reminder that seemingly routine services such as airport Wi-Fi registrations and parking bookings can create valuable stores of personal data.

With millions of customer records now potentially in the hands of attackers, the consequences of the breach could continue long after airport operations return to normal.

Watch Our Latest Video
Stay ahead with expert insights on privacy, cybersecurity, artificial intelligence, data protection and compliance.
No Leak, No Wahala
Published: August 16, 2026
Daily Privacy News
Cybersecurity Updates
Data Protection Tips
GDPR & NDPA Explained
Tags:
Ikeh James Certified Data Protection Officer (CDPO) | NDPC-Accredited

Ikeh James Ifeanyichukwu is a Certified Data Protection Officer (CDPO) accredited by the Institute of Information Management (IIM) in collaboration with the Nigeria Data Protection Commission (NDPC). With years of experience supporting organizations in data protection compliance, privacy risk management, and NDPA implementation, he is committed to advancing responsible data governance and building digital trust in Africa and beyond. In addition to his privacy and compliance expertise, James is a Certified IT Expert, Data Analyst, and Web Developer, with proven skills in programming, digital marketing, and cybersecurity awareness. He has a background in Statistics (Yabatech) and has earned multiple certifications in Python, PHP, SEO, Digital Marketing, and Information Security from recognized local and international institutions. James has been recognized for his contributions to technology and data protection, including the Best Employee Award at DKIPPI (2021) and the Outstanding Student Award at GIZ/LSETF Skills & Mentorship Training (2019). At Privacy Needle, he leverages his diverse expertise to break down complex data privacy and cybersecurity issues into clear, actionable insights for businesses, professionals, and individuals navigating today’s digital world.

  • 1

You Might also Like

Leave a Reply

Your email address will not be published. Required fields are marked *

  • Rating

This site uses Akismet to reduce spam. Learn how your comment data is processed.