- 8.7m customers had personal data exposed in the cyber attack
- The breach affected Manchester, London Stansted and East Midlands airports
- Data accessed included email addresses, phone numbers, vehicle registrations and postcodes
- No banking or payment details were held on the compromised system
- MAG refused to pay the ransom demand and is working with authorities
Manchester Airports Group has confirmed a major cyber attack that exposed the personal data of approximately 8.7m customers. The breach targeted systems holding information from three major English hubs: Manchester Airport, London Stansted Airport and East Midlands Airport.
The compromised database held information tied to car park bookings, airport lounge access, fast-track security lanes and terminal Wi-Fi registrations. Cybercriminals accessed customer email addresses, phone numbers, vehicle registration plates and postcodes. MAG noted that the vast majority of the breached records were restricted to email addresses gathered during Wi-Fi log-ins. Hackers demanded a ransom payment for the return of the data, which MAG refused to pay.
MAG confirmed that no banking details, credit card information or financial data were stored on the compromised system. Flights, security check-ins and airport terminal activities remained completely unaffected. Passenger and aviation safety were never compromised. The breach occurred over the weekend before MAG detected the unauthorised activity on Tuesday, 25 August 2026. The group immediately contained the system, restricted access and launched an investigation alongside cyber security specialists, the National Cyber Security Centre and the Information Commissioner’s Office.
MAG representative shared the vast majority of the breached records were restricted to email addresses gathered during Wi-Fi log-ins. MAG spokesperson shared passenger and aviation safety were never compromised and airport operations continue normally.



