MAG Confirms Customer Data Breach at Three UK Airports
Manchester Airports Group confirmed that an unauthorized third party obtained some customer data. The incident did not affect airport operations or payment information.

MAG data breach affected customer information used for services at Manchester, London Stansted and East Midlands airports. Manchester Airports Group (MAG) confirmed on August 27 that an unauthorized third party obtained some data related to parking, airport lounges, Fast Track reservations and airport Wi-Fi registrations.
The company said the exposed data included email addresses, phone numbers, vehicle registration numbers and postal codes. MAG also claims that neither the compromised system nor the group itself stored customers’ bank or payment information.
The MAG data breach did not affect airport operations
According to the operator’s notice, the incident did not affect airport operational systems, passenger security or aviation safety. The airports and parking services remain operational.
After discovering the incident, MAG restricted access to the affected systems, brought in external cybersecurity experts and notified the relevant authorities. It also temporarily disabled the Manage My Booking online service.
The company says it contacted affected customers directly. In its communications, it warns them about the risk of phishing emails, text messages and phone calls in which attackers may impersonate the airport or reservation service.
What data could be misused
Although MAG does not report a leak of payment information, the combination of contact details, postal code, vehicle registration number and links to specific airport services could help with targeted fraudulent communications. Messages could, for example, refer to parking, Fast Track, a lounge or a reservation, making them appear more credible than typical mass phishing.
Customers should be especially cautious with unexpected requests to change a reservation, pay an additional fee or confirm information. When in doubt, they should avoid opening links in messages and verify their reservation status by directly accessing the airport’s official websites or using a known contact.
The full scope of the incident is not yet public
MAG did not state the number of affected people in its public statement. However, based on the company’s communications with customers, Computer Weekly reported that approximately 8.7 million people were affected. This figure therefore cannot yet be considered publicly confirmed directly by MAG.
The attacker’s identity, the method of intrusion and the timing of the systems’ compromise are also unknown. It has not been publicly confirmed whether the data reached the internet, was offered for sale, or whether the incident involved future reservation dates and additional data fields beyond the categories named by the operator.
Further information may come from confirmation of the scope by MAG or the relevant authorities, possible technical details from the investigation, and the restoration of the Manage My Booking service. It will also be important to see whether subsequent fraud campaigns emerge using the data or themes related to the services of the three airports.
Sources
- Manchester Airport / Manchester Airports Group – Primary confirmation of the incident, the categories of data obtained, the absence of payment information, unaffected operations and the measures taken.
- Computer Weekly – Independently reports approximately 8.7 million affected people and corresponds with the publicly confirmed data categories.
- BleepingComputer – Corroborates MAG’s confirmation that customer data was stolen without an operational outage; notes that the number affected was not publicly confirmed by the company.
Verified and updated: 08/27/2026 20:14



