Airport Breach Exposes 8.7 Million
Coverage from McAfee, Shieldworkz, and others

Manchester Airports Group reported unauthorized access to customer records connected to parking, lounge, Fast Track and Wi-Fi services at Manchester, London Stansted and East Midlands airports.
Approximately 8.7 million customers may be affected, with exposed information including email addresses, phone numbers, vehicle registrations and postcodes, while payment and banking details were reportedly not stored in the accessed system. MAG restricted affected access, engaged external specialists, notified UK authorities and warned customers about phishing and impersonation risks; airport operations and passenger safety were not disrupted.
If you read one thing
It provides the broadest overview of the exposed records, affected airports, operational containment and remaining uncertainty.
Best explainer
It explains why non-financial travel and contact data can still create substantial phishing and impersonation risks.
The evidence
It adds security-focused evidence on how exposed airport, contact and vehicle data could enable targeted phishing.
Broad exposure of travel-linked personal data
The incident potentially affects approximately 8.7 million records across three UK airports, primarily involving email addresses and, for some customers, phone numbers, postcodes and vehicle registrations linked to parking, lounge, Fast Track and Wi-Fi services. Although payment and banking data were reportedly absent, the combination of verified contact and travel-related details creates sustained phishing, impersonation and parking-fraud risks.
Customer-data compromise contained without reported aviation disruption
MAG restricted access to affected systems, took online booking-management functions offline, engaged external incident-response specialists and notified UK authorities. Reporting indicates that airport operations, passenger safety, payment processing and safety-critical aviation systems continued unaffected, while the investigation and service restrictions remain ongoing.
Material uncertainty over incident scope and characterization
The approximately 8.7 million affected-record figure is widely reported but remains partly qualified, with the exposed fields varying by service and customer group. Key investigative details—including the initial access route, attacker identity, dwell time and precise data-transfer volume—remain unknown, while the supplied coverage does not establish a confirmed ransomware characterization.
8.7 million customers
customers reportedly affected
“Manchester Airports Group (MAG), which operates Manchester, London Stansted and East Midlands airports, confirmed on 27 August 2026 that an unauthorized third party had obtained a quantity of customer data. About 8.7 million customers were reportedly affected.”
8.7 million passengers
passengers reportedly affected by the breach
“The Telegraph reported that approximately 8.7 million passengers were affected and that more than 90% of the stolen records were email addresses, largely because travelers provide an email address when registering for free airport Wi-Fi.”
more than 90% percent
stolen records that were email addresses
“The Telegraph reported that approximately 8.7 million passengers were affected and that more than 90% of the stolen records were email addresses, largely because travelers provide an email address when registering for free airport Wi-Fi.”
8.7 million customers
customers with personal data linked to the accessed records
“Manchester Airports Group (MAG) confirmed on August 27 that an unauthorized third party accessed personal data linked to around 8.7 million customers across Manchester Airport, London Stansted, and East Midlands Airport.”
approximately 8.7 million individuals
individuals associated with affected records
“Manchester Airports Group (MAG), operator of Manchester, London Stansted and East Midlands airports, disclosed a cybersecurity incident on 27 August 2026 involving a customer-facing backend system shared across the three airports. The incident reportedly affected records associated with approximately 8.7 million individuals.”
There was no material change: no new topic members were supplied beyond the existing account of unauthorized access to Manchester Airports Group customer records.
Previously
Manchester Airports Group reported unauthorized access to customer records connected to parking, lounge, Fast Track and Wi-Fi services at Manchester, London Stansted and East Midlands airports. Approximately 8.7 million customers may be affected, with exposed information including email addresses, phone numbers, vehicle registrations and postcodes, while payment and banking details were reportedly not stored in the accessed system. MAG restricted affected access, engaged external specialists, notified UK authorities and warned customers about phishing and impersonation risks; airport operations and passenger safety were not disrupted.
