Criminal hackers have stolen the personal data of about 8.7 million customers following a cyberattack on systems used by Manchester Airports Group (MAG), which operates Manchester Airport, East Midlands Airport and London Stansted Airport.
The airport operator said the incident involved unauthorized access to customer information, including email addresses, postcodes and vehicle registration details. The attackers also demanded a ransom for the stolen data, but MAG said it refused to pay.
MAG stated that passenger safety, airport operations and aviation security were not affected by the breach. The compromised system did not contain customer bank account details or payment-card information, according to the group.
Most of the exposed data reportedly came from passengers who registered for WiFi services in airport terminals. The stolen information primarily included email addresses associated with WiFi sign-ups.
Hackers Steal Data From Three UK Airports
Additional customer records were accessed through services linked to airport travel, including car-park reservations, lounge bookings and fast-track access. These records may have contained more detailed information, such as vehicle registration numbers and postcodes.
The airport operator said it identified the incident on Tuesday and acted quickly to stop further unauthorized access. MAG said it contained the breach, engaged specialist cybersecurity advisors and began notifying customers whose data may have been affected.
“We immediately contained the risk and have been working with specialist advisors and taking appropriate steps to protect our customers and systems,” MAG said in a statement.
The company said it had informed the relevant authorities and was cooperating with them, while MAG told the BBC that it knows the identity of the threat actors involved but did not publicly name the hacking group or disclose the ransom amount demanded.
The UK Information Commissioner’s Office confirmed that it had received a breach notification from Manchester Airports Group and was assessing the information supplied by the company.
The regulator may determine whether MAG met its data-protection obligations and whether further action is required. The incident highlights the risks associated with customer-facing digital services, especially WiFi portals, parking platforms, and online booking systems.
While the compromised records did not include payment data, attackers can use email addresses, names, postcodes, and vehicle information to build convincing phishing and social engineering campaigns.
Affected customers may receive fake airport notifications, fraudulent baggage or flight alerts, malicious parking-payment messages, or scam calls claiming to offer compensation.
The combination of travel-related information and contact details can make such attacks appear legitimate. MAG has urged customers to remain alert for suspicious emails, text messages and phone calls.
Users should avoid opening unexpected attachments, clicking links in unsolicited messages or sharing personal information with unverified callers. Customers should independently visit official airport websites rather than following links in breach-related messages.
They should also enable multi-factor authentication on email accounts, use unique passwords, and monitor inboxes for phishing attempts that impersonate Manchester Airport, East Midlands Airport, London Stansted Airport, or customer-support teams.
Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC

