Last Update: 09/22/2026 at 11:34 PM EST

Airport Breach Exposes 8.7 Million

Coverage from McAfee, Shieldworkz, and others

Airport Breach Exposes 8.7 Million topic image

Manchester Airports Group reported unauthorized access to customer records connected to parking, lounge, Fast Track and Wi-Fi services at Manchester, London Stansted and East Midlands airports.

Approximately 8.7 million customers may be affected, with exposed information including email addresses, phone numbers, vehicle registrations and postcodes, while payment and banking details were reportedly not stored in the accessed system. MAG restricted affected access, engaged external specialists, notified UK authorities and warned customers about phishing and impersonation risks; airport operations and passenger safety were not disrupted.

Key Articles3 of 10 articles

If you read one thing

It provides the broadest overview of the exposed records, affected airports, operational containment and remaining uncertainty.

Shieldworkz

Best explainer

It explains why non-financial travel and contact data can still create substantial phishing and impersonation risks.

Cyber Management Alliance

The evidence

It adds security-focused evidence on how exposed airport, contact and vehicle data could enable targeted phishing.

McAfee / Brooke Seipel
Key Issues

Broad exposure of travel-linked personal data

The incident potentially affects approximately 8.7 million records across three UK airports, primarily involving email addresses and, for some customers, phone numbers, postcodes and vehicle registrations linked to parking, lounge, Fast Track and Wi-Fi services. Although payment and banking data were reportedly absent, the combination of verified contact and travel-related details creates sustained phishing, impersonation and parking-fraud risks.

Drawn from 5 articles

Customer-data compromise contained without reported aviation disruption

MAG restricted access to affected systems, took online booking-management functions offline, engaged external incident-response specialists and notified UK authorities. Reporting indicates that airport operations, passenger safety, payment processing and safety-critical aviation systems continued unaffected, while the investigation and service restrictions remain ongoing.

Drawn from 3 articles

Material uncertainty over incident scope and characterization

The approximately 8.7 million affected-record figure is widely reported but remains partly qualified, with the exposed fields varying by service and customer group. Key investigative details—including the initial access route, attacker identity, dwell time and precise data-transfer volume—remain unknown, while the supplied coverage does not establish a confirmed ransomware characterization.

Drawn from 4 articles

Key Numbers

8.7 million customers

customers reportedly affected

across Manchester, London Stansted and East Midlands airports · 27 August 2026

Manchester Airports Group (MAG), which operates Manchester, London Stansted and East Midlands airports, confirmed on 27 August 2026 that an unauthorized third party had obtained a quantity of customer data. About 8.7 million customers were reportedly affected.

Cyber Management Alliance

8.7 million passengers

passengers reportedly affected by the breach

approximately

The Telegraph reported that approximately 8.7 million passengers were affected and that more than 90% of the stolen records were email addresses, largely because travelers provide an email address when registering for free airport Wi-Fi.

McAfee

more than 90% percent

stolen records that were email addresses

of the stolen records

The Telegraph reported that approximately 8.7 million passengers were affected and that more than 90% of the stolen records were email addresses, largely because travelers provide an email address when registering for free airport Wi-Fi.

McAfee

8.7 million customers

customers with personal data linked to the accessed records

across Manchester Airport, London Stansted, and East Midlands Airport

Manchester Airports Group (MAG) confirmed on August 27 that an unauthorized third party accessed personal data linked to around 8.7 million customers across Manchester Airport, London Stansted, and East Midlands Airport.

BetaNews

approximately 8.7 million individuals

individuals associated with affected records

records across Manchester, London Stansted and East Midlands airports

Manchester Airports Group (MAG), operator of Manchester, London Stansted and East Midlands airports, disclosed a cybersecurity incident on 27 August 2026 involving a customer-facing backend system shared across the three airports. The incident reportedly affected records associated with approximately 8.7 million individuals.

Shieldworkz

Looking Back
2 Day Timeline
Aug 27Aug 28
The Story So Far
No material change

There was no material change: no new topic members were supplied beyond the existing account of unauthorized access to Manchester Airports Group customer records.

Previously

Manchester Airports Group reported unauthorized access to customer records connected to parking, lounge, Fast Track and Wi-Fi services at Manchester, London Stansted and East Midlands airports. Approximately 8.7 million customers may be affected, with exposed information including email addresses, phone numbers, vehicle registrations and postcodes, while payment and banking details were reportedly not stored in the accessed system. MAG restricted affected access, engaged external specialists, notified UK authorities and warned customers about phishing and impersonation risks; airport operations and passenger safety were not disrupted.

All Articles10 articles
Interesting10 articles · CI Score 45–59
McAfee / Brooke Seipel
Manchester Airports Group reported in the United Kingdom that an unauthorized third party accessed information from approximately 8.7 million airport customers across Manchester, London Stansted, and East Midlands airports.
8/28/2026 • Data Breaches & Exposure Events • General
Shieldworkz
Manchester Airports Group disclosed on 27 August 2026 that unauthorized access to a shared customer-service backend exposed records associated with approximately 8.7 million people across three UK airports.
8/28/2026 • Data Breaches & Exposure Events • General
BetaNews / Camila Nogueira
Manchester Airports Group confirmed on August 27 that an unauthorized third party accessed personal data linked to about 8.7 million customers at three UK airports.
8/28/2026 • Data Breaches & Exposure Events • General
Safestate
Manchester Airports Group notified roughly 8.7 million customers on 27 August after attackers stole contact, vehicle and postcode records from systems serving three UK airports.
8/28/2026 • Data Breaches & Exposure Events • General
Cyber Management Alliance
Manchester Airports Group confirmed on 27 August 2026 that unauthorized access to customer-service systems at three UK airports affected approximately 8.7 million customers.
8/27/2026 • Data Breaches & Exposure Events • General
Aviation Business News / Greg Whitaker
Manchester Airports Group confirmed that an unauthorised third party accessed customer booking and Wi-Fi records at Manchester, Stansted, and East Midlands airports.
8/27/2026 • Data Breaches & Exposure Events • General
Cybersecurity Insiders / Naveen Goud
Manchester Airports Group reported in the United Kingdom that a ransomware incident may have exposed more than 8.7 million airport customer information records.
8/27/2026 • Data Breaches & Exposure Events • General
Help Net Security / Sinisa Markovic
Manchester Airports Group reported that an unauthorised third party accessed customer booking and WiFi signup data at Manchester, Stansted, and East Midlands airports in the United Kingdom.
8/28/2026 • Data Breaches & Exposure Events • General
The Record / Alexander Martin
Manchester Airports Group disclosed on Tuesday that an unauthorized third party accessed data for about 8.7 million customers across Manchester, Stansted and East Midlands airports.
8/27/2026 • Data Breaches & Exposure Events • General
BleepingComputer / Bill Toulas
Manchester Airports Group disclosed after discovering an intrusion that hackers stole customer contact and vehicle information from systems serving three UK airports.
8/27/2026 • Data Breaches & Exposure Events • General