Independent Reviews
Abstract glass data vault fractured by a security breach
Data Breach Published 28 Aug 2026 5 min read2 sources

Manchester Airports Group Says Data on 8.7 Million Customers Was Accessed

Manchester Airports Group says hackers accessed data linked to about 8.7 million customers of Manchester, London Stansted and East Midlands airports. MAG says the affected system held no bank or payment data and airport operations were not affected.

By VPN Rocks Editorial Team

The short version

What you need to know

  • Manchester Airports Group told the BBC that attackers accessed data relating to about 8.7 million customers of Manchester, London Stansted and East Midlands airports.
  • Most of the affected records were email addresses collected through airport Wi-Fi sign-ups. Some booking records also included names, phone numbers, postcodes and vehicle registrations; MAG says the compromised system did not hold bank or payment details.
  • Be cautious of messages that use real airport, parking or travel details to appear convincing. A VPN cannot remove stolen records or stop criminals from using them in targeted phishing.

What happened?

Manchester Airports Group, which operates Manchester, London Stansted and East Midlands airports, says hackers accessed customer information in a cyber-attack. The group told the BBC that data relating to about 8.7 million customers was accessed and that it refused a ransom demand.

MAG says most of the affected data was limited to email addresses supplied when travellers signed up for Wi-Fi in airport terminals. Records connected to car-park, lounge and fast-track bookings could also include names, phone numbers, postcodes and vehicle registration numbers. The company says the affected system did not contain bank or payment-card details.

What the incident did not affect

The airport operator says passenger safety and aviation security were not compromised. Airport operations and parking services continued normally, so this should not be described as a disruption to flights or airport control systems.

MAG told the BBC it became aware of the intrusion on 25 August, contained the access and notified affected customers. The Information Commissioner's Office confirmed to the BBC that it had received a breach report and was assessing the information provided.

Why follow-up scams could look convincing

An email address alone can support broad phishing. A combination of contact details, postcode, vehicle registration and knowledge of an airport service can make a message look much more personal. A criminal could impersonate an airport, parking operator or travel company and refer to a refund, booking problem, unpaid fee or security check.

Do not treat accurate travel details as proof that a message is genuine. Open the airport or booking provider's official site independently, use a saved app or type a known address yourself. Do not call a number, open an attachment or enter payment details through an unexpected message.

What affected customers can do now

Read the notification from MAG carefully to understand which details it says were involved. Passwords were not among the affected fields reported by MAG, but anyone who reused an airport-account password elsewhere should still replace that reuse with unique passwords and enable multi-factor authentication where it is available.

Watch email, text and phone channels for messages tied to airport Wi-Fi, parking, lounge or fast-track use. If a message asks for payment or banking information, verify it through a separately obtained official channel. Keep evidence and contact your bank immediately if you entered card details on a suspicious page.

Where a VPN helps — and where it does not

A reputable full-tunnel VPN can encrypt traffic between a supported device and the VPN provider while using public Wi-Fi. That reduces exposure to local-network snooping and can be useful when travelling.

This incident concerns information held in an airport operator's systems. A consumer VPN cannot protect data after a company has collected it, remove records accessed by attackers, identify a convincing phishing message or reverse account and payment fraud. Independent message verification, unique passwords and rapid reporting remain the relevant controls.

VPN Rocks view

Airport Wi-Fi sign-up data can feel low risk, but the scale of this incident shows how a simple email collection can become a large breach. When richer booking details are involved, one plausible follow-up risk is impersonation that reflects a real journey or vehicle.

Companies should minimise retention, separate low-sensitivity sign-up records from richer booking data and make breach notices precise about which fields were affected. Travellers should verify any unexpected request for payment or banking information through an independently obtained official channel.

Primary reading

Sources and further reading

We add plain-English context and practical advice. These links let you inspect the underlying reporting, research and official guidance directly.

Useful next steps