Manchester Airports Group says hackers have stolen travellers’ data

Manchester Airports Group says hackers have stolen travellers’ data

Manchester Airports Group says hackers have stolen travellers' data

Manchester Airports Group (MAG) has revealed that hackers have breached its systems and stolen customer data, including WiFi logins from Manchester, Stansted and East Midlands airports.

The intruder did not have access to customers’ payment data and the attack had no impact on airport operations, the company said.

The company said in a statement today that the exfiltrated data also “relates to parking, lounge and fast track bookings.” The list of compromised data includes customers’ email addresses, phone numbers, vehicle registration numbers and zip codes.

Picture

“The incident did not cause any operational disruption,” the organization assured, adding that “airport operations remain unaffected and customer parking services continue to function normally.”

Out of an abundance of caution, MAG has temporarily suspended its online Manage My Booking service and is directing travelers to use its telephone line instead.

MAG is the UK’s largest airport operator, owning Manchester, London Stansted and East Midlands airports, which together handle over 66 million passengers annually.

The company employs 40,000 people and generates Annual turnover of £1.5 billion.

After discovering the breach, MAG said it acted quickly to contain it, restricting access to the affected systems, bringing in outside experts and notifying law enforcement.

Potentially exposed customers are advised to pay attention to suspicious communications and avoid clicking on links received via email or SMS.

MAG emphasizes that customers are never asked for payment card information, banking details or passwords. Customers should reject and report any attempts to obtain personal, financial or other sensitive information to authorities.

People are also encouraged to follow NCSC recommendations following a breach to stay safe.

The company said it contacted affected customers directly, but did not provide information on the number of people affected.

Local media reported that data from up to 8.9 million travelers may have been exposed citing private MAG statements; However, BleepingComputer was unable to confirm the number.

At the time of writing, no ransomware or data extortion groups have publicly claimed the attack.


Item image

Overall prevention scores can hide what happens after the first access. Once attackers use valid credentials, prevention drops sharply.

The 2026 Blue Report measures defense technology for technology in 338 million simulations conducted in customer production environments.

Get the report

Leave a Reply

Your email address will not be published. Required fields are marked *