Personal data stolen from Manchester Airports Group is now circulating beyond the hackers behind the original breach, giving criminals more material for targeted scams against travelers.
The incident affects customers of Manchester, London Stansted, and East Midlands airports. While MAG says payment information and airport operational systems were not compromised, the exposed records contain enough personal and travel-related details to make fraudulent emails, texts, and phone calls more convincing. For UK customers and EMEA organizations with frequent travelers, the longer-term concern is how attackers might reuse that information.
The risk did not end when MAG contained the breach. Publication of the stolen dataset gives more criminals access to information they can combine with familiar travel details to impersonate airport services or other trusted organizations.
Exposed data includes travel history and vehicle details
The BBC reported that criminals published data belonging to about 8.7 million people after the breach. Have I Been Pwned puts the figure slightly higher, saying the exposed data relates to 8.8 million customers.
According to Have I Been Pwned, compromised information includes names, email addresses, phone numbers, IP addresses, geographic locations, browser user-agent details, purchases, and vehicle registration plates. Records also contained parking history, Fast Track purchases, and lounge bookings.
MAG said the affected systems contained information associated with car park, lounge, and Fast Track bookings, along with in-airport Wi-Fi sign-ups. The company said neither MAG nor the affected system held customers’ bank or payment information.
Published records could fuel more convincing travel scams
Travel data can give phishing messages context that generic spam lacks. A criminal who knows a customer’s airport, vehicle registration, parking history, or upcoming travel details could create messages that appear connected to a legitimate booking.
Cybersecurity expert Kevin Beaumont told the BBC that the exposed information includes historical locations and planned future travel. He warned customers to be alert to scammers reusing details such as phone numbers and vehicle registrations.
The BBC also said that the stolen dataset is being offered for free through a website accessible on the open internet rather than being restricted to a dark-web leak site. Easier access increases the number of criminals who could potentially reuse the information.
MAG says payment data and airport systems were unaffected
MAG noted passenger safety, aviation security, and airport operations were not compromised. Upcoming bookings also remain valid.
The company restricted access to affected systems, engaged cybersecurity specialists, and notified relevant authorities. As a precaution, it temporarily suspended its online Manage My Booking service following the incident.
Customers should verify unexpected airport-related messages
MAG advises affected customers to remain alert for suspicious emails, texts, and phone calls. Messages deserve extra scrutiny when they reference real travel details because information that looks familiar is no longer proof that the sender is legitimate.
Customers can lower their risk by:
- Verifying booking or payment requests independently through the airport’s official website or known contact details rather than links in unexpected messages.
- Changing reused passwords and enabling two-factor authentication, particularly on accounts connected to an exposed email address.
- Monitoring financial and online accounts for unusual activity and reporting suspicious communications.
MAG also stresses that it will not contact customers unexpectedly to request payment card details, banking information, or passwords.
UK and EMEA security teams should warn frequent travelers
Security teams do not need to wait for employees to report suspicious messages. Organizations whose staff frequently travel through Manchester, Stansted, or East Midlands can proactively warn them about phishing attempts involving airport parking, lounge access, Fast Track bookings, refunds, or itinerary changes.
The exposed information may remain useful to criminals long after the original breach disappears from the news cycle. For affected travelers and their employers, skepticism toward unusually well-informed travel messages is now an important part of the response.
The MAG breach follows a similar CEVA Logistics incident that exposed customer and order data across Europe, raising phishing concerns.





