Security & Risk5 minNewsroom

Cyber Attack Exposes Data of 8.7 Million Customers at Three UK Airports

Saguão de embarque de aeroporto vazio à noite com cadeiras desertas e iluminação fria, representando o ataque cibernético ao Manchester Airports Group

Manchester Airports Group confirmed that external attackers exfiltrated data of 8.7 million passengers from Manchester, Stansted, and East Midlands airports. The company refused to pay the ransom demanded by the intruders.

Confirmation and Containment


Manchester Airports Group (MAG) confirmed on August 27, 2026, that unauthorized external attackers exfiltrated data of 8.7 million customers spread across the Manchester, Stansted, and East Midlands airports. The group detected the intrusion on the same day and stated that it contained access before the attackers could advance beyond the CRM and commercial service scheduling systems.


The compromised data includes email addresses, phone numbers, vehicle registration numbers, and postal codes. MAG confirmed that no banking or payment card information was accessed. The information belonged to passengers who used parking services, lounges, Fast Track, or Wi-Fi networks at the three airports.


Ransom Demanded and Refused


Following the exfiltration, the attackers demanded payment in exchange for the return of the data. MAG refused. "We contained the risk quickly and prevented the intruders from gaining additional access," a company spokesperson stated, according to BBC. The identity of the responsible group is known to UK authorities, according to MAG, but has not been publicly disclosed. No criminal organization had claimed responsibility for the attack by the time this article was published.


The Information Commissioner's Office (ICO) and other relevant authorities were notified, according to MAG. The company stated that the operational security of flights was not compromised at any time.


The Overlooked Vector: Passenger Service Systems


MAG operates three of the busiest airports in the UK by passenger volume. Manchester Airport processed 31 million passengers in 2024; Stansted and East Midlands account for an additional 28 million. The breach did not occur in flight control or aviation security systems, but rather in the layers of CRM and commercial service booking platforms, segments that are often audited with less rigor than critical operational infrastructure.


The combination of exposed data (email, phone, registration, and postal code) does not involve financial credentials, but is sufficient to build detailed identity profiles and assemble targeted phishing and smishing campaigns. Security researchers point out that this type of data has high value in underground markets precisely because misuse does not trigger immediate financial fraud alerts, making detection difficult for victims.


Regulatory Impact: From the UK to Continental Europe


In the UK, the ICO can open an investigation under the UK GDPR and impose fines of up to £17.5 million or 4% of global annual revenue, whichever is higher. The regulatory timeline for notification of breaches posing risks to individuals is 72 hours from the discovery. MAG had not confirmed by the time this article was published whether notification to the ICO was completed within that timeframe.


In Continental Europe, the incident resonates directly for airport operators subject to the NIS2 Directive, effective for essential transport entities since October 2024. The rules require initial notification of significant incidents within 24 hours to competent national authorities, with a detailed report due in 72 hours. Operators such as Fraport (Frankfurt Airport), Groupe ADP (Paris airports), and Schiphol Group (Netherlands) operate under this same framework and face increasing scrutiny regarding the adequacy of peripheral CRM and passenger service booking systems in relation to NIS2 obligations.


The difference between the two regimes is relevant for CISOs of consultancies with clients in transportation infrastructure: post-Brexit UK GDPR and EU NIS2, despite common roots, diverge in timelines, notification thresholds, and oversight bodies. Companies operating in both markets need to maintain distinct incident response trails.


What Remains Unknown


The initial vector of compromise has not been disclosed by MAG. The company has also not confirmed the total volume of data transferred out of its systems. The absence of a public claim by the attackers prevents assessment of whether the data will be marketed or kept as leverage for future negotiations. MAG had not announced any remediation or identity monitoring measures for the 8.7 million affected customers by the time this article was published.

The week's analysis, by email

One weekly edition with what matters to people who decide. No ads, no sponsorship.

One-click cancellation, at any time.

Security & Risk