Overview
- Manchester Airports Group said an unauthorised third party accessed customer records for Manchester, London Stansted and East Midlands airports and that it informed authorities after being made aware on Tuesday 25 August.
- About 8.7 million records were accessed and mainly came from car-park, lounge and Fast Track bookings plus in-terminal Wi‑Fi sign-ups, with email addresses, phone numbers, vehicle registrations and postcodes among the data taken.
- MAG says the hacked systems did not hold bank or payment details and that passenger safety, aviation security and airport operations were not disrupted.
- The group says it contained the incident, engaged external cyber specialists, contacted affected customers and temporarily suspended its Manage My Booking online service while investigations continue.
- Security experts warn the exposed contact and booking data is valuable for convincing phishing, smishing and social‑engineering attacks and passengers should be wary of unexpected messages claiming to be from the airports.