8.7 million customers hit as Manchester Airports Group breach exposes airport WiFi sign-ups
WiFi users didn’t have to travel very far to get caught up in this breach.

Photo by Peter Byrne/PA Images via Getty Images
- Hackers stole data linked to 8.7 million customers of Manchester, Stansted, and East Midlands airports.
- The exposed data includes in-airport WiFi registrations, email addresses, phone numbers, parking data and booking details.
- MAG says payment and bank details were not stored on the affected system.
- Experts warn criminals could use the stolen data for convincing phishing scams and fake travel messages.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
Data from 8.7 million customers has been stolen in a cyber attack on three major UK airports, including details collected from passengers signing up for airport WiFi.
Manchester Airports Group (MAG), which operates Manchester, London Stansted and East Midlands airports, said hackers accessed data linked to in-airport WiFi registrations as well as car parking, lounge and Fast Track bookings.
The compromised information includes email addresses, phone numbers, vehicle registrations and postcodes, although MAG has claimed the “vast majority” of those affected had only their email addresses exposed.
No ban or payment details were held on the affected system, according to the airport operator, which issued a statement on Thursday.
MAG has not disclosed how attackers gained access to the data or identified who was behind the breach.
The group became aware of the incident on Tuesday and said it immediately restricted access to affected systems, brought in specialist cyber security experts and notified the relevant authorities.
Under GDPR, UK organisations have to report data breaches to the Information Commissioner's Office (ICO) if they're likely to put people's rights or freedoms at risk – and they have to do it fast: within 72 hours of finding out.
Firms don't need all the technical details at that stage; those can follow later.
“Precise targeting” of parking and WiFi data
The inclusion of WiFi registration data potentially widens the pool of victims beyond customers who made the airport bookings.
Muhammad Yahya Patel, vCISO and cybersecurity advisor for EMEA at Huntress, warned that combining contact and travel-related information could give criminals material for convincing follow on attacks.
“Email addresses, phone numbers and vehicle registrations combined is a precise targeting profile for anyone planning a follow-on fraud or phishing campaign,” Patel said.
Scammers now know you travelled, roughly when, and have two direct contact routes to reach you with a convincing story,Muhammad Yahya Patel, vCISO and cybersecurity advisor for EMEA at Huntress.
Graeme Stewart, head of public sector at Check Point Software, said the absence of disruption at airports should not disguise the potential impact of this attack.
“The data reportedly taken can now be weaponized,” he said “A fake parking refund, a ‘fast track’ issue or message about this very breach suddenly becomes much harder for an ordinary customer to spot,” he warns.
MAG has contacted affected customers and warned them to be wary of unexpected emails, calls and text messages.
The group added that it would never unexpectedly request payment card details, banking information or passwords.
Airport operations, passenger safety and aviation security have not been affected, according to the group, and existing bookings remained valid,
However, MAG added that it was temporarily suspending access to its online Manage My Bookings service, “as a precautionary measure.”
The company said its investigation was continuing and that its data protection team is overseeing the response.
Airport WiFi: How to keep yourself safe
Because all airports are essentially people processing plants, they tend to be a major target for hackers.
The September 2025 Collins Aerospace ransomware attack, saw cybercriminals exfiltrate a 50GB database from the company's servers and disrupted check-in and boarding at Heathrow, Brussels, Berlin, Dublin and Cork.
In February Qilin ransomware claimed against Tulsa International Airport, where attackers allegedly accessed and leaked airport data.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
Meanwhile an alleged cyberattack in early 2026 compromised data from Dubai International Airport, with hackers claiming to have obtained sensitive images including passport and security-scanner material.
Users should avoid public Wi-Fi for sensitive activities such as banking, shopping or entering important passwords, and should verify that the network is legitimate to avoid fake “evil twin” hotspots.
If public Wi-Fi is necessary, Cybernews recommends using a VPN, HTTPS websites, two-factor authentication, updated software, and disabling automatic network connections.