Data from 8.7 million customers has been stolen in a cyber attack on three major UK airports, including details collected from passengers signing up for airport WiFi.
Manchester Airports Group (MAG), which operates Manchester, London Stansted and East Midlands airports, said hackers accessed data linked to in-airport WiFi registrations as well as car parking, lounge and Fast Track bookings.
The compromised information includes email addresses, phone numbers, vehicle registrations and postcodes, although MAG has claimed the “vast majority” of those affected had only their email addresses exposed.
No ban or payment details were held on the affected system, according to the airport operator, which issued a statement on Thursday.
MAG has not disclosed how attackers gained access to the data or identified who was behind the breach.
The group became aware of the incident on Tuesday and said it immediately restricted access to affected systems, brought in specialist cyber security experts and notified the relevant authorities.
Under GDPR, UK organisations have to report data breaches to the Information Commissioner's Office (ICO) if they're likely to put people's rights or freedoms at risk – and they have to do it fast: within 72 hours of finding out.
Firms don't need all the technical details at that stage; those can follow later.
The inclusion of WiFi registration data potentially widens the pool of victims beyond customers who made the airport bookings.
Muhammad Yahya Patel, vCISO and cybersecurity advisor for EMEA at Huntress, warned that combining and travel-related information could give criminals material for convincing follow on attacks.
“Email addresses, phone numbers and vehicle registrations combined is a precise targeting profile for anyone planning a follow-on fraud or phishing campaign,” Patel said.
Graeme Stewart, head of public sector at Check Point Software, said the absence of disruption at airports should not disguise the potential impact of this attack.
“The data reportedly taken can now be weaponized,” he said “A fake parking refund, a ‘fast track’ issue or message this very breach suddenly becomes much harder for an ordinary customer to spot,” he warns.
MAG has contacted affected customers and warned them to be wary of unexpected emails, calls and text messages.
The group added that it would never unexpectedly request payment card details, banking information or passwords.
Airport operations, passenger safety and aviation security have not been affected, according to the group, and existing bookings remained valid,
However, MAG added that it was temporarily suspending access to its online Manage My Bookings service, “as a precautionary measure.”
The company said its investigation was continuing and that its data protection team is overseeing the response.
Because all airports are essentially people processing plants, they tend to be a major target for hackers.
The September 2025 Collins Aerospace ransomware attack, saw cybercriminals exfiltrate a 50GB database from the company's servers and disrupted check-in and boarding at Heathrow, Brussels, Berlin, Dublin and Cork.
In February Qilin ransomware claimed against Tulsa International Airport , where attackers allegedly accessed and leaked airport data.
Meanwhile an alleged cyberattack in early 2026 compromised data from Dubai International Airport, with hackers claiming to have obtained sensitive images including passport and security-scanner material.
Users should avoid public Wi-Fi for sensitive activities such as banking, shopping or entering important passwords, and should verify that the network is legitimate to avoid fake “ evil twin” hotspots.
If public Wi-Fi is necessary, Cybernews recommends using a VPN, HTTPS websites, two-factor authentication, updated software, and disabling automatic network connections.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
