Cybercriminals have reportedly stolen the personal data of approximately 8.7 million customers following a cyberattack targeting systems used by Manchester Airports Group (MAG), which operates Manchester Airport, East Midlands Airport, and London Stansted Airport.
The airport operator said the incident involved unauthorized access to customer information, including email addresses, postcodes, and vehicle registration details.
The attackers also demanded a ransom for the stolen information, but MAG said it refused to pay.
According to the company, passenger safety, airport operations, and aviation security were not affected by the incident.
MAG also stated that the compromised systems did not contain customer bank account details or payment-card information.
8.7 Million Customers Potentially Affected
Most of the exposed information reportedly came from passengers who registered for WiFi services at airport terminals.
The stolen information primarily consisted of email addresses associated with WiFi registrations.
Additional customer records were accessed through services connected to airport travel, including:
- Car-park reservations
- Lounge bookings
- Fast-track access
- Airport WiFi registrations
Some of these records may have contained additional information such as vehicle registration numbers and postcodes.
The combination of contact details and travel-related information could provide attackers with valuable data for targeted phishing and social engineering campaigns.
Cyberattack Detected by Manchester Airports Group
MAG said it identified the incident on Tuesday and took immediate steps to prevent further unauthorized access.
The company said it contained the breach, engaged specialist cybersecurity advisors, and began notifying customers whose information may have been affected.
"We immediately contained the risk and have been working with specialist advisors and taking appropriate steps to protect our customers and systems."
MAG also said it had notified the relevant authorities and was cooperating with the investigation.
The company reportedly told the BBC that it knows the identity of the threat actors involved, although it has not publicly identified the hacking group or disclosed the amount of ransom demanded.
UK Data Protection Regulator Investigating
The UK Information Commissioner's Office (ICO) confirmed that it had received a breach notification from Manchester Airports Group.
The regulator is assessing the information provided by MAG and could determine whether the company complied with its data-protection obligations and whether further regulatory action is necessary.
The incident highlights the security risks associated with customer-facing digital services, particularly systems handling large volumes of personal information such as:
- Airport WiFi portals
- Parking platforms
- Online booking systems
- Lounge reservation services
- Fast-track booking systems
Even when financial information is not compromised, seemingly less-sensitive information can still become valuable to cybercriminals.
Stolen Data Could Fuel Phishing Attacks
The exposed information could potentially be used to create highly convincing phishing and social engineering campaigns.
Attackers could use the stolen data to impersonate airport operators or customer-support teams and send messages related to:
- Flight notifications
- Baggage issues
- Parking payments
- Airport services
- Travel refunds
- Compensation claims
- Booking confirmations
Because these messages could contain legitimate-looking travel information, victims may be more likely to trust them.
MAG has urged affected customers to remain cautious about suspicious emails, text messages, and phone calls.
Customers should avoid opening unexpected attachments, clicking links in unsolicited messages, or providing personal information to unverified callers.
Instead, users should independently navigate to official airport websites when checking bookings, payments, or account information.
Enabling multi-factor authentication (MFA) on email accounts, using unique passwords, and closely monitoring inboxes for suspicious messages can also reduce the risk of follow-up attacks.
How LeakWatch Can Help Monitor Exposed Credentials
Data breaches do not always end when the vulnerable system is secured.
Once stolen information reaches underground forums, data-leak sites, or criminal marketplaces, attackers may continue using it for credential stuffing, phishing, account takeover, and social engineering.
This is where LeakWatch can help organizations monitor for exposed credentials and compromised accounts.
LeakWatch, developed by RedSide, is a data-leak monitoring platform designed to help organizations identify whether their domains, usernames, email addresses, or other identifiers appear in known leaked datasets.
Organizations can use leak monitoring to:
- Detect exposed corporate email addresses.
- Identify compromised employee credentials.
- Monitor domains for newly discovered leaks.
- Investigate potential credential exposure.
- Identify accounts that may require password resets.
- Support incident-response and threat-intelligence workflows.
For organizations operating customer-facing platforms, continuous monitoring can provide an additional layer of visibility after a data breach.
A breach notification tells an organization that data was exposed. Continuous leak monitoring can help determine whether that information later appears in datasets accessible to attackers.
Key Takeaway
The Manchester Airports Group incident demonstrates how attackers can potentially extract significant amounts of sensitive information even when payment-card and banking information are not involved.
Email addresses, postcodes, vehicle registration numbers, and travel-related information can provide enough context for attackers to construct convincing phishing and social-engineering attacks.
Organizations handling large volumes of customer data should therefore focus not only on preventing unauthorized access, but also on detecting leaked information, monitoring for credential exposure, and preparing customers for potential follow-up attacks.
Until the investigation is complete, customers associated with Manchester Airport, East Midlands Airport, or London Stansted Airport should remain particularly cautious about unexpected communications referencing their travel, parking, bookings, or airport services.