
Manchester Airports Group (MAG) has disclosed a cybersecurity incident in which an unauthorized third party obtained customer information linked to airport parking, lounge, Fast Track, and Wi-Fi services.
The company says payment information was not exposed and airport operations have not been affected.
The incident affects data associated with Manchester, London Stansted, and East Midlands airports. MAG said the compromised information includes customer email addresses, telephone numbers, vehicle registration numbers, and postcodes.
The airport operator has not disclosed how the attacker gained access, when the intrusion occurred, how long the affected system was accessible, or the number of customers whose information was taken. Some media reports have cited a figure of 8.9 million people potentially affected, but MAG has not officially confirmed that number.
Manchester Airports Group is one of the United Kingdom's largest airport operators and owns and operates Manchester, London Stansted, and East Midlands airports. Its airports collectively handle tens of millions of passengers annually, while MAG also provides ancillary services including parking, airport lounges, Fast Track security bookings, and passenger Wi-Fi.
According to the company's statement, the compromised system did not contain customer bank or payment card details. MAG also stressed that the intrusion did not involve operational airport systems and that neither passenger safety nor aviation security was compromised.
After discovering the incident, MAG restricted access to affected systems, brought in specialist cyber security advisers, and notified the relevant authorities. Its Data Protection team is overseeing the response.
As a precaution, MAG has temporarily disabled its online Manage My Booking service. Existing bookings remain valid, although customers requiring urgent changes to bookings within the next 72 hours are being directed to the company's customer service telephone line.
MAG said it has contacted affected customers directly.
Although financial credentials were reportedly not exposed, the stolen information could still be useful for phishing and social-engineering attacks. Details such as names associated with email addresses or telephone numbers, postcodes, and vehicle registrations can help attackers create convincing messages impersonating an airport, parking provider, travel company, or other service.
Customers should be cautious of unexpected emails, SMS messages, and calls referring to airport bookings or the breach. Links and attachments in unsolicited messages should be avoided, and requests for passwords, banking information, or payment card details should be treated as suspicious.
MAG specifically warns that it will not unexpectedly contact customers asking them to provide payment card details, banking information, or passwords.







Leave a Reply