In short: On 27 August 2026, Manchester Airports Group (MAG) confirmed a major cyberattack: an unauthorised third party accessed personal data belonging to 8.7 million customers of Manchester Airport, London Stansted Airport, and East Midlands Airport. Payment details were not compromised. However, email addresses, phone numbers, postal codes, and vehicle registration numbers were stolen. The attackers demanded a ransom — MAG refused. Here is what happened and what it means if you have used any of these airports.
What happened: the timeline
On 25 August 2026, MAG's computer systems detected anomalous activity. The company immediately isolated the affected systems, engaged specialist cybersecurity advisors, and notified regulators. On 27 August, MAG officially confirmed that an "unauthorised third party" had accessed customer data. According to BleepingComputer, the attackers demanded a ransom payment, which MAG refused. MAG's "Manage My Booking" online service was temporarily suspended while the affected infrastructure was secured. For practical tips on protecting your data when travelling, see the LiMP VPN blog.
What data was exposed
According to Help Net Security and BleepingComputer, the breach covered data associated with the following MAG customer services:
- Car park bookings. Date, time, booking type, and vehicle registration number — data that directly identifies a specific vehicle and its owner.
- Airport lounge access. Name, email, phone number, date, and associated flight.
- Fast Track security lanes. Personal details of the purchaser.
- Airport Wi-Fi registration. Email address, device identifier, connection date and time.
MAG confirmed that no payment card data or financial information was stored in the compromised systems. However, email addresses, phone numbers, postal codes, and vehicle registration numbers are more than sufficient for targeted follow-on attacks against affected customers.
Why "no card data" is not a reason to relax
The absence of payment data from the leak is welcome news. But the combination of email address, phone number, postal code, and vehicle registration number creates a genuinely dangerous profile:
- Targeted phishing. An attacker knows that you flew from Manchester during a specific period. An email from "Manchester Airport" asking you to confirm your booking or update payment details looks extremely convincing — especially if it references your flight date or car park.
- Vishing (phone fraud). A "MAG support agent" calls and correctly names your vehicle and the car park you used. This social-engineering scenario is exactly what stolen databases are used for — combined data is far more dangerous than a simple email list.
- Cross-breach correlation. A vehicle registration linked to specific travel dates is a valuable puzzle piece. Criminals aggregate data from multiple breach sources to build increasingly complete victim profiles.
- Wi-Fi surveillance. Connection data captures device, time, and location — useful for tracking movement patterns and identifying high-value targets in transit environments.
Scale: the largest UK transport breach of 2026
Manchester Airports Group operates three airports with combined annual passenger volumes in the tens of millions. 8.7 million compromised records make this one of the largest data breaches in British transport infrastructure in recent years. For comparison: the 2018–2019 British Airways breach affected approximately 400,000 customers — the MAG incident exceeds that by more than 20 times.
MAG has notified the UK's Information Commissioner's Office (ICO). Under GDPR, the regulator may impose fines of up to 4% of global annual turnover if a personal data breach is confirmed. MAG's decision to refuse the ransom demand is widely regarded by security experts as correct — payment provides no guarantee that stolen data will not be resold or published.
Steps to take if you have used MAG airports
If you have ever booked a car park, lounge, or Fast Track pass, or connected to Wi-Fi at Manchester, Stansted, or East Midlands Airport:
- Be alert to phishing emails from "MAG" or "Manchester Airport." Do not click links in emails — navigate to airport websites directly by typing the URL into your browser.
- Expect a direct notification from MAG — the company is legally required to inform affected customers. But do not trust notifications from unfamiliar sender addresses.
- Check your email at HaveIBeenPwned — free, no registration. If your address appears, change passwords on all connected accounts.
- Use a VPN on airport and hotel Wi-Fi. The MAG breach partially involved data from airport Wi-Fi users. Open airport networks are one of the highest-risk interception vectors — attackers can deploy "Evil Twin" hotspots that mimic the official network. LiMP VPN encrypts your traffic and hides your data from eavesdroppers. Plans from ₽69/month.
