Manchester Airport Breach: What 8.7M Customers Should Do

Manchester Airports Group customer data is now public. Here’s what was exposed, why it raises scam risks, and what affected travelers should do next.

Written By
KJ
Kezia Jungco
Sep 3, 2026
3 minute read
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

Personal data stolen from Manchester Airports Group is now circulating beyond the hackers behind the original breach, giving criminals more material for targeted scams against travelers.

The incident affects customers of Manchester, London Stansted, and East Midlands airports. While MAG says payment information and airport operational systems were not compromised, the exposed records contain enough personal and travel-related details to make fraudulent emails, texts, and phone calls more convincing. For UK customers and EMEA organizations with frequent travelers, the longer-term concern is how attackers might reuse that information.

The risk did not end when MAG contained the breach. Publication of the stolen dataset gives more criminals access to information they can combine with familiar travel details to impersonate airport services or other trusted organizations.

Exposed data includes travel history and vehicle details

The BBC reported that criminals published data belonging to about 8.7 million people after the breach. Have I Been Pwned puts the figure slightly higher, saying the exposed data relates to 8.8 million customers.

According to Have I Been Pwned, compromised information includes names, email addresses, phone numbers, IP addresses, geographic locations, browser user-agent details, purchases, and vehicle registration plates. Records also contained parking history, Fast Track purchases, and lounge bookings.

MAG said the affected systems contained information associated with car park, lounge, and Fast Track bookings, along with in-airport Wi-Fi sign-ups. The company said neither MAG nor the affected system held customers’ bank or payment information.

Published records could fuel more convincing travel scams

Travel data can give phishing messages context that generic spam lacks. A criminal who knows a customer’s airport, vehicle registration, parking history, or upcoming travel details could create messages that appear connected to a legitimate booking.

Cybersecurity expert Kevin Beaumont told the BBC that the exposed information includes historical locations and planned future travel. He warned customers to be alert to scammers reusing details such as phone numbers and vehicle registrations.

Advertisement

The BBC also said that the stolen dataset is being offered for free through a website accessible on the open internet rather than being restricted to a dark-web leak site. Easier access increases the number of criminals who could potentially reuse the information.

MAG says payment data and airport systems were unaffected

MAG noted passenger safety, aviation security, and airport operations were not compromised. Upcoming bookings also remain valid.

The company restricted access to affected systems, engaged cybersecurity specialists, and notified relevant authorities. As a precaution, it temporarily suspended its online Manage My Booking service following the incident.

Customers should verify unexpected airport-related messages

MAG advises affected customers to remain alert for suspicious emails, texts, and phone calls. Messages deserve extra scrutiny when they reference real travel details because information that looks familiar is no longer proof that the sender is legitimate.

Customers can lower their risk by:

  • Verifying booking or payment requests independently through the airport’s official website or known contact details rather than links in unexpected messages.
  • Changing reused passwords and enabling two-factor authentication, particularly on accounts connected to an exposed email address.
  • Monitoring financial and online accounts for unusual activity and reporting suspicious communications.

MAG also stresses that it will not contact customers unexpectedly to request payment card details, banking information, or passwords.

UK and EMEA security teams should warn frequent travelers

Security teams do not need to wait for employees to report suspicious messages. Organizations whose staff frequently travel through Manchester, Stansted, or East Midlands can proactively warn them about phishing attempts involving airport parking, lounge access, Fast Track bookings, refunds, or itinerary changes.

The exposed information may remain useful to criminals long after the original breach disappears from the news cycle. For affected travelers and their employers, skepticism toward unusually well-informed travel messages is now an important part of the response.

The MAG breach follows a similar CEVA Logistics incident that exposed customer and order data across Europe, raising phishing concerns.

KJ

Kezia Jungco is a technology writer and researcher specializing in artificial intelligence, data analytics, CRM software, cloud infrastructure, cybersecurity, and emerging business technologies. With more than five years of experience evaluating software platforms and technology solutions, she helps business leaders understand the tools and trends shaping the future of work. Kezia has extensive hands-on experience testing and analyzing generative AI platforms, chatbots, natural language processing (NLP) tools, CRM systems, and business software. Her work focuses on translating complex technologies into practical insights that help organizations make informed decisions about technology adoption, operational efficiency, and digital transformation. As a staff writer for TechnologyAdvice, Kezia covers AI innovation, business applications of machine learning, data-driven technologies, cloud computing, cybersecurity, and sales technology. Her background in journalism, research, and education enables her to combine rigorous analysis with clear, accessible reporting for both enterprise and consumer audiences. Kezia holds a bachelor's degree in Development Communication with a major in Development Journalism from the University of the Philippines Los Baños. She has also completed professional training in artificial intelligence, data privacy, and information security. Her work has been featured in TechnologyAdvice, TechRepublic, eWeek, Datamation, and Selling Signals, where she helps readers navigate a rapidly evolving technology landscape with practical, research-driven guidance.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2026 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.