Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-08-28 ยท updated: 2026-08-28 ยท tags: [cyber, incident] ยท confidence: high ยท severity: high ยท affected_sectors: [transport] ยท au_impact: false

Manchester Airports Group Says Cyberattack Exposed Data of ~8.7 Million Travellers

Summary

Manchester Airports Group (MAG), the United Kingdom's largest airport operator โ€” managing Manchester, London Stansted and East Midlands airports with around 65 million passengers a year โ€” disclosed a cyber attack affecting customer data. Around 8.7 million travellers' data was affected, relating to car-park, lounge and Fast Track bookings and in-airport Wi-Fi sign-ups.

Technical detail

The exposed information includes email addresses, phone numbers, vehicle registrations and postcodes. MAG stated that no financial data was stored in the affected system and temporarily suspended its Manage My Booking service as a precaution. The company said it was alerted to the incident on the relevant day (Tuesday), believes the attackers gained access a few days earlier, and has restricted access and engaged external specialists. The breach type is confirmed breach.

Significance

As one of the largest airport operators in Europe, MAG illustrates the growing attack surface across transport and travel services. Even without credit-card data, the combination of email addresses, phone numbers, vehicle registration plates and home postcodes is enough to fuel targeted phishing, credential-stuffing and physical-resecurity threats such as vehicles being tracked. The precautionary suspension of booking services underscores the operational disruption that can follow a data-related breach.

AU/NZ relevance

The Manchester incident has limited direct AU/NZ application given it concerns a UK operator. However, it is a live cautionary example for Australian and New Zealand aviation and transport operators, whose loyalty, parking and lounge booking datasets have similar characteristics; it reinforces the need to treat low-trust ancillary booking systems (car park, lounge, Wi-Fi sign-up) as first-class security assets.