What went wrong
Eight‑point‑seven million customers had their personal details accessed when Manchester Airports Group (MAG) was hit by a cyberattack. The breach covered data from car‑park, lounge, Fast Track bookings and in‑airport Wi‑Fi sign‑ups at Manchester, London Stansted and East Midlands airports.
MAG discovered the intrusion on a Tuesday and immediately locked down the affected systems. It brought in external cybersecurity specialists and informed the relevant authorities.
Technical snapshot
The attackers did not obtain any bank or payment‑card information – MAG stores none of those details. The compromised fields were limited to email addresses, phone numbers, vehicle registrations and postcodes. In the vast majority of cases only an email address was accessed.
MAG has not disclosed how the intruders gained entry or what tools they used. The organization simply stated that passenger safety and aviation security were untouched; flights, airport operations and parking services kept running as normal.
Who’s affected
The three airports together handled more than 65 million passengers in the previous year, so the impact stretches far beyond the 8.7 million directly listed. Anyone who ever booked a car‑park slot, used a lounge, signed up for Wi‑Fi or bought a Fast Track pass at those sites could be on the list.
What MAG is doing
- Temporarily suspended the online “Manage My Booking” portal.
- Restricted access to the compromised systems while the investigation continues.
- Sent warning emails to affected customers, explicitly stating it will never request payment‑card details, banking information or passwords unexpectedly.
- Set up a dedicated phone line for customers who need to amend a reservation within the next 72 hours.
Steps you can take now
- Treat any unsolicited email referencing MAG bookings as suspicious. Verify the sender before clicking any links.
- If you received a MAG warning, do not reply with personal or financial details.
- Consider changing passwords on any accounts that reuse the same credentials as your airport booking portal.
- Enable two‑factor authentication wherever possible, especially on email accounts.
- Monitor your email inbox for phishing attempts that reference the breach and report them to MAG’s helpline.
While the breach did not expose financial data, the volume of personal identifiers makes phishing a real risk. Staying vigilant is the best defence.
